Set up an MCP server integration
Connect an MCP server to Creatio AI Studio to make its tools available to your agents. Once connected, Creatio AI Studio discovers all tools the server exposes — you do not need to define them one by one. You also configure which access modes agents can use when calling the server.
Before you start, make sure you have the MCP server URL and credentials if the server requires authentication.
Add the MCP server
-
Go to the Integrations section in the navigation panel.
-
Click New to open the integration wizard.
-
Select MCP Server and continue to the setup form.
-
Enter the integration name in the Name field.
The name appears in the integration catalog and in the agent's Integrations tab. Use a descriptive name that identifies the server and its environment, for example, "Bee MCP – Production."
-
Enter the description in the Description field (optional).
-
Turn on the Requires authentication toggle if the server requires credentials to connect.
When the toggle is on, the server requires credentials to connect. When the toggle is off, Creatio AI Studio connects using the URL only — no credentials are needed. Most MCP servers require authentication.
-
Configure the connection scope using the Same connection for all environments toggle, which is on by default.
When the toggle is on, all environments — Sandbox, Stage, Production — use the same MCP server URL and credentials. When the toggle is off, you can specify a separate URL and credentials for each environment.
-
Enter the MCP Server URL.
-
Select the Integration credentials. Click Select to open the "Select credentials" dialog and pick existing credentials, or click Create new credentials and fill in the "Create credentials" form:
- Enter the credential name in the Name field.
- Select the credential type in the Type field: "OAuth" or "Bearer."
- For OAuth: enter the Base URL, the Token endpoint path (optional), the Client ID, and the Secret. Enter the scope in the Scope (optional) field, if the server requires one. Further settings sit under Advanced options.
- Click Create to save the credentials.
-
Enable the access methods the integration allows. All three start off, and at least one is required when Requires authentication is on. The choice you make here is what agent creators can later pick from.
- Integration credentials — the MCP server authenticates using the credentials stored on the integration. All agents whose creators select this mode use the same credentials and appear identical to the server.
- Agent-owned credentials — each agent authenticates with its own credentials. The server can identify which agent is calling and apply agent-specific permissions.
- Delegated access — the end user authenticates directly with the MCP server at the start of a session. All tool calls run on behalf of that user, using their role-based access controls. The method reads "Not verified" until you click Check support, and Creatio AI Studio asks you to confirm before turning it on. Once it is on, a Redirect URL appears: copy it and add it to the OAuth app in your external system. On a Creatio integration, when Creatio stops accepting the access a user granted, the agent asks the user to authorize again and gives a link that opens the Creatio environment the conversation runs in.
-
Click Connect MCP server.
As a result, Creatio AI Studio connects to the MCP server, discovers its tools, and reports "MCP Server '…' created." The integration appears in the catalog with an "MCP Server" label. If the connection fails, the integration is saved but flagged in Needs attention — open it to correct the URL or credentials. Check the number of discovered tools on the integration's Tools tab before you rely on it.
Check the tools in each environment
When Same connection for all environments is off, a tool can be available in one environment and not in another. The Tools tab shows the state of each tool in every environment.
-
Go to the Integrations section in the navigation panel and open the MCP integration.
-
Go to the Tools tab. Each environment has its own column. A toggle shows whether the tool is turned on in that environment. A dash (—) means the tool is not available there.
-
Point to a dash to see why the tool is not available. The tooltip reads one of the following:
- "Not reachable in this environment" — the environment has no URL or connection.
- "Not yet discovered — run Discover Tools for this environment"
- "Not offered in this environment" — the server does not offer the tool there.
-
Click Discover Tools after you add or fix an environment's URL on the Configuration tab. Discovery runs for every connected environment.
As a result, the Tools tab shows which tools are available in each environment. Environments that have no URL yet are not reported as discovery errors, and their tools show "Not reachable in this environment."
Change the access methods
-
Go to the Integrations section in the navigation panel.
-
Open the integration you want to configure.
-
Go to the Configuration tab and find Access methods in the Connection panel.
-
Turn the methods on or off, as described in step 10 above.
-
Click Save to apply the configuration. Cancel and Save appear once something has changed.
Limit who can use the integration
The Access tab decides who can use an integration and enable its tools for agents. It works the same way for every integration type, including HTTP API integrations. An integration you create is restricted: only you and users with the Manage security permission can use it until you grant access to others. An integration created before access control was available stays open to everyone in the organization until you restrict it, and an integration provisioned by the platform is always available to the whole organization.
To restrict an integration, you need the Edit integrations permission. To grant access, you need the Manage security permission.
-
Go to the Integrations section in the navigation panel.
-
Open the integration you want to restrict.
-
Go to the Access tab.
-
Turn on the Restrict access switch in the Who can use this integration block, if it is off. If nobody holds a grant yet, confirm the "Restrict without granting anyone?" dialog with Restrict.
-
Click Grant access in the Who has access block. This opens the "Grant access" dialog.
-
Select who gets access on the User, Role, or Group tab. For a group, enter its slug in the Group slug field. The slug must match the group in your identity provider.
-
Select the access methods in the Limit to access modes field, if needed. The field appears when the integration allows more than one access method. Leave it empty to allow every access method enabled on the integration.
-
Click Grant access.
As a result, Creatio AI Studio reports "Access granted." and lists the new grant under Who has access. The users, roles, and groups listed there can use the integration and enable its tools. To take access away, click the delete icon in the grant's row, then click Revoke in the "Revoke access?" dialog.
Runs that start without a signed-in user, such as channel and triggered runs, cannot use a restricted integration through a grant. To let an agent call the integration's tools in a channel or from a trigger, turn off Restrict access so that the integration is open to the organization.
Assign the integration to an agent
-
Go to the Agents section in the navigation panel.
-
Open the agent you want to configure. If the agent is published, click Create draft to start a new draft.
-
Go to the Integrations tab on the Build tab group.
-
Find the integration in the list. A restricted integration is listed only when you have access to it.
-
Select the access mode the agent will use under Access mode. Only the methods enabled on the integration can be selected; the rest are greyed out. If your grant on a restricted integration is limited to specific access methods, use one of those.
For Agent-owned credentials: assign credentials for each environment in the table that appears below. To generate credentials automatically for Creatio-hosted MCP servers, click Autogenerate credentials.
-
Enable the tools the agent should use by checking the Enabled checkbox for each tool in the tools table.
-
Publish and deploy the agent. The agent editor saves your changes to the draft automatically. Click Publish, then click Deploy and select the environment.
As a result, the agent can call the selected tools from the MCP server using the chosen access mode.