Skip to main content

Register BYO MCP servers in the console

Bring Your Own (BYO) Model Context Protocol servers allow an Orbit AI agent to discover and invoke tool catalogs hosted on external infrastructure. This guide covers how to register, test, inspect, and remove external MCP servers using the Orbit dashboard console or the REST API.

Prerequisites

Before registering an external MCP server, ensure you have:
  • An Owner, Admin, or Developer role in your Orbit organization.
  • A running MCP server accessible over public HTTPS.
  • Authentication credentials for the server (either a static Bearer token or OAuth2 client credentials).

Step 1: Open the agent’s MCP servers tab

  1. Navigate to Agents in the Orbit dashboard.
  2. Select the agent you want to configure.
  3. Open the Tools tab on the agent detail page, or navigate directly to /agents/<agent-id>?tab=tools.
  4. In the tools view, locate the MCP Servers section.

Step 2: Register a new MCP server

Click Register server to open the registration dialog:
  1. Server name: Enter a unique identifier for the server (for example, customer-crm-tools). Names must be unique per agent.
  2. Server URL: Enter the public HTTPS endpoint of your MCP server (for example, https://mcp.example.com/sse).
  3. Authentication: Choose between:
    • None: If your server is open or network-gated.
    • Bearer token: Provide a static API token or bearer secret.
    • OAuth2: Select the grant type (client_credentials or refresh_token), then provide the Token URL, Client ID, Client Secret, and optional Scopes.
  4. Test connection: Click Test connection before saving. Orbit issues an ephemeral probe against the endpoint to verify protocol compatibility and authentication without saving bad configurations.
  5. Click Register server to save.

Step 3: Manage and delete registered servers

Once registered, your servers appear in the agent’s server list:
  • Health and status: Orbit checks server reachability and displays status badges indicating active health or connection errors.
  • Toggle state: You can temporarily disable an MCP server using the switch toggle without deleting its configuration or credentials.
  • Delete a server: Click the trash icon next to any server to remove it. Orbit will prompt for confirmation. Once removed, tools from that server will no longer be available during subsequent agent runs.

Write-time SSRF guards and common rejections

Orbit enforces strict server-side request forgery (SSRF) guards at registration time. If your registration is rejected, the API returns a 422 or 409 status code:
  • 422 INVALID_MCP_SERVER_URL: The server URL failed the security guard (e.g., non-HTTPS protocol, private IP address, or internal DNS resolution).
  • 422 INVALID_MCP_OAUTH_TOKEN_URL: The OAuth2 token exchange URL failed the SSRF guard.
  • 409 MCP_SERVER_NAME_CONFLICT: An MCP server with the same name already exists on this agent.
For detailed steps on resolving these errors, see Troubleshooting: MCP server registration rejected.

Register via the REST API

You can also automate server registration against POST /api/v1/agents/:agentId/mcp-servers using the Orbit REST API.

Add an MCP server with a Bearer token

cURL

Add an MCP server with OAuth2 Client Credentials

cURL

Response example

201

See also