Register BYO MCP servers in the console
Bring Your Own (BYO) Model Context Protocol servers allow an Orbit AI agent to discover and invoke tool catalogs hosted on external infrastructure. This guide covers how to register, test, inspect, and remove external MCP servers using the Orbit dashboard console or the REST API.Prerequisites
Before registering an external MCP server, ensure you have:- An Owner, Admin, or Developer role in your Orbit organization.
- A running MCP server accessible over public HTTPS.
- Authentication credentials for the server (either a static Bearer token or OAuth2 client credentials).
Step 1: Open the agent’s MCP servers tab
- Navigate to Agents in the Orbit dashboard.
- Select the agent you want to configure.
- Open the Tools tab on the agent detail page, or navigate directly to
/agents/<agent-id>?tab=tools. - In the tools view, locate the MCP Servers section.
Step 2: Register a new MCP server
Click Register server to open the registration dialog:- Server name: Enter a unique identifier for the server (for example,
customer-crm-tools). Names must be unique per agent. - Server URL: Enter the public HTTPS endpoint of your MCP server (for example,
https://mcp.example.com/sse). - Authentication: Choose between:
- None: If your server is open or network-gated.
- Bearer token: Provide a static API token or bearer secret.
- OAuth2: Select the grant type (
client_credentialsorrefresh_token), then provide the Token URL, Client ID, Client Secret, and optional Scopes.
- Test connection: Click Test connection before saving. Orbit issues an ephemeral probe against the endpoint to verify protocol compatibility and authentication without saving bad configurations.
- Click Register server to save.
Step 3: Manage and delete registered servers
Once registered, your servers appear in the agent’s server list:- Health and status: Orbit checks server reachability and displays status badges indicating active health or connection errors.
- Toggle state: You can temporarily disable an MCP server using the switch toggle without deleting its configuration or credentials.
- Delete a server: Click the trash icon next to any server to remove it. Orbit will prompt for confirmation. Once removed, tools from that server will no longer be available during subsequent agent runs.
Write-time SSRF guards and common rejections
Orbit enforces strict server-side request forgery (SSRF) guards at registration time. If your registration is rejected, the API returns a422 or 409 status code:
422 INVALID_MCP_SERVER_URL: The server URL failed the security guard (e.g., non-HTTPS protocol, private IP address, or internal DNS resolution).422 INVALID_MCP_OAUTH_TOKEN_URL: The OAuth2 token exchange URL failed the SSRF guard.409 MCP_SERVER_NAME_CONFLICT: An MCP server with the same name already exists on this agent.
Register via the REST API
You can also automate server registration againstPOST /api/v1/agents/:agentId/mcp-servers using the Orbit REST API.
Add an MCP server with a Bearer token
cURL
Add an MCP server with OAuth2 Client Credentials
cURL
Response example
201
See also
- BYO MCP servers for AI agents — architecture, runtime discovery, and scope models.
- Hosted MCP server — exposing Orbit capabilities to external MCP clients.
- Orbit-as-MCP hosted server handshake — protocol details for inbound MCP.
- Troubleshooting: MCP server registration rejected — resolving SSRF guard rejections and naming conflicts.
- Build tenant custom tools for AI agents — single-endpoint HTTPS webhook tools.