Skip to main content
Cedros

Connecting an external AI tool through MCP

Connect your AI client to Cedros, choose access, confirm the connection, and manage or revoke its key.

Connect an external AI tool to Cedros through MCP (Model Context Protocol) so it can work with your site's tools and information. You choose the client, create an access key in Cedros, and configure the connection on the machine where the client runs.

Start with a read-only request, then review the available access before asking the tool to make changes.

Before you connect

You need a client that supports a remote MCP connection and a Cedros account with permission to manage settings. Open Settings → Assistant → MCP to find MCP access and Set up MCP.

Set up the connection for the site you intend to use. Each site's instructions contain its own address and credential variable; do not reuse another site's values.

An MCP access key can grant access to private site information and, depending on its permissions, actions that change the site. Keep the key out of chat messages, screenshots, shared documents, and committed configuration files. Use a separate, clearly named key for each machine or client so you can revoke it independently.

Choose your client and create a key

  1. Select Set up MCP.
  2. Under MCP client, choose the tool you use. Choose Other MCP if you need the connection values for another compatible client.
  3. Choose Access. Use Site tools to let the client work with the site tools allowed by your account. Assistant conversations is a narrower option for messaging your personal Cedros assistant; it requires site administrator access and blocks site changes.
  4. Under Which machine or client is this for?, enter a recognizable label, such as “Work laptop.”
  5. Select Create key, then copy the key while it is visible. Cedros shows the full value only once.

Keys created through this setup expire after 90 days. The confirmation that the key is accepted by Cedros verifies the credential; you still need to configure your external client.

If Cedros says the key was created but its connection check failed, save the key before closing the dialog. Read the error and check the key list before trying again.

Configure the client where it runs

Follow the instructions shown for your selected client. Depending on the client, setup either provides a terminal command that securely asks for the key or shows separate steps to supply the key and add the configuration.

  1. Provide the key through the private prompt or credential mechanism shown in the setup. Do this on the machine where the client runs.
  2. Add the displayed connection configuration to the indicated file or the client's MCP settings. Preserve any other connections already configured there.
  3. Make sure the client can read the credential when it starts. A value set in one terminal may not reach an app opened another way, or a client running on another machine.
  4. Restart or reconnect the client so it loads the configuration and credential.

Use the site's displayed MCP URL rather than its admin-page address. For Other MCP, the connection values include the server name, URL, and Authorization header. Supply the key securely as instructed; the explanatory placeholder is not a working credential.

The expandable Let the client configure itself section provides a setup prompt. It contains connection instructions, not your key. If you use it, keep the key in the separate credential step.

Confirm access with a read-only check

In your external client, check that the Cedros connection is enabled and its tools are available. Then make a small read-only request. For a Site tools key, you could ask:

List the titles of up to five published documentation articles on this Cedros site. Do not create, edit, publish, or delete anything.

Check that the result belongs to the correct site. If you chose Assistant conversations, site content tools are outside that key's access; use the client's connection status or read your personal conversation instead.

Return to Settings → Assistant → MCP. A recorded last used time shows that a client authenticated with the key. If the setup dialog is still open, it can show MCP access confirmed. This confirms a connection, not that every tool or requested action is permitted.

The Coding sessions list is separate: it shows agents that register a coding session. An empty list does not by itself mean your MCP connection failed.

Your external AI tool may charge for processing a request. Calling Cedros assistant or generation tools can also use the site's configured AI services. Listing tools or checking key status does not require an assistant generation request.

Keep changes deliberate

A Site tools key uses permissions granted when it is issued; it is not automatically read-only. Your client may be able to save, send, or publish through the tools available to it. Check the access you are granting before sharing the key with a client.

Describe the intended result and when you want to review it. For example, ask for a draft first and inspect it in Cedros before requesting publication. Review the actual page or record after a change. See Writing useful requests for the assistant and Understanding drafts, previews, and publishing.

Available tools depend on the key's access, your site's enabled features and extensions, and the client's configuration. A connected tool cannot make an unavailable feature available. If your account access changes, reconnect with a newly issued key when required; do not keep retrying an old credential with outdated access.

Replace or revoke a key

The MCP access list shows each key's label, creation date, last use, and expiry. Review keys you no longer recognize or use. Expired and revoked keys contains inactive entries.

To replace a key before it expires:

  1. Use Set up MCP to create a replacement with a clear label and the intended access.
  2. Update the credential in the client that uses it, then restart or reconnect that client.
  3. Confirm the replacement works and its last used time updates.
  4. Open the old key's actions menu, choose Revoke key, review the named key, and confirm Revoke key.

Creating a new key does not automatically revoke your existing connections. Revoking a key stops every client using that key from authenticating to the site. It cannot be undone; restoring access requires a new key. It does not undo changes the client already made.

If a key has been exposed, revoke it promptly rather than waiting for a routine replacement check. Remove it from the affected client and configure a new one securely.

Resolve common connection problems

  • Set up MCP is disabled: ask your administrator to check your settings access. See Why can't I see or edit a feature?.
  • The client cannot authenticate: check the site URL, the credential variable named in setup, and whether the key has expired or been revoked. Restart the client after updating its environment.
  • The key still says never used: confirm that setup was completed on the machine running the client, that the connection is enabled, and that the client made a request. Creating a key alone does not count as client use.
  • The connection works but a tool is missing or denied: check the selected access type, account permissions, feature availability, and the client's enabled-tool settings. Reconnect to refresh its tool list after a relevant change.
  • The key value disappeared: Cedros cannot display it again. Create a replacement and revoke the unused key you could not save.
  • The key list shows a loading error: use Try again. If older rows remain visible, wait for a successful refresh before relying on their status.

When asking for help, include the client name, site address, key label, error message, and whether the key shows recent use. Do not include the key itself.