Docs · MCP servers

Tools: MCP servers and webhook tools

Updated September 25, 2026 · by , founder of Agent Studio

Two ways to give an agent tools. Connect an MCP server, fetch its tools and tick the ones the agent may call; or add a Webhook tool, which needs no server: describe when to use it, set a URL and parameters, and the orchestrator calls it with a signed JSON request. Every call, with input and result, lands in the trace. Plans cap the total tools per agent.

Setting one up

  • Add an MCP server from the palette and connect it to the orchestrator.
  • Enter the server URL and choose HTTP (default) or SSE. Add an Authorization value if the server needs one.
  • Press Fetch tools. Tick the tools the orchestrator may use; the counter shows how many your plan allows.
  • Test in the playground. Tool calls appear in the trace as MCP tool entries with input and result.

Webhook tools (no server needed)

Add a Webhook tool from the palette and connect it to the orchestrator. Fill in: a description of when the agent should call it, the method and URL, an optional Authorization value, and the parameters the model must supply (name, type, description, required). Choose whether to wait for the response; if you do, the response body is handed back to the model so it can use the result.

Your endpoint receives JSON:

POST https://hooks.example.com/agent
Content-Type: application/json
X-Agent-Studio-Timestamp: 1790000000000
X-Agent-Studio-Signature: <hex HMAC-SHA256(secret, "<timestamp>.<raw body>")>

{ "tool": "Create ticket", "agent": "Support Copilot", "args": { "email": "a@b.co", "summary": "Login fails on iOS" }, "sentAt": "2026-09-28T10:00:00.000Z" }

For GET, the parameters are sent as query string values and the signature covers the timestamp only. Verify the signature with the shared secret from your account settings if you need to trust the caller; the header alone tells you the request came through Agent Studio. Responses are truncated to 4,000 characters; a non-2xx status is returned to the model as an error it can explain.

Each webhook tool counts as one tool against the plan limit below, alongside enabled MCP tools.

Limits by plan

PlanTools per agent (MCP + webhook)
Free trial1
Starter1
Pro2
Growth10
Agency60

The limit counts enabled MCP tools plus webhook tools connected to one agent. Saving, deploying, the playground and the public API all enforce it; after a downgrade, deployments over the new limit pause until redeployed. See pricing.

Security

  • Server URLs are checked before every connection: only public http(s) hosts; loopback, private ranges, link-local and cloud metadata addresses are refused, and redirects are not followed.
  • Credentials belong in the Authorization field, never in the URL.
  • The orchestrator only sees the tools you enabled, under a name prefixed with the server, so tools from different servers cannot collide.
  • A server that is down does not fail the run: the trace records the connection error and the agent answers without those tools.

What the trace shows

{ "stage": "tool", "server": "CRM", "tool": "find_customer", "input": "{"email":"a@b.co"}", "result": "{"id":"c_123","plan":"pro"}", "ok": true, "ms": 412 }

Frequently asked questions

I don't have an MCP server. Can the agent still call my system?+

Yes. Add a Webhook tool instead: name it, describe when the agent should use it, set the URL and a few parameters. The orchestrator fills the parameters and Agent Studio sends a signed JSON request to your URL. Point it at a Flows trigger, a Zapier or Make webhook, or your own API.

What is an MCP server?+

A service that speaks the Model Context Protocol and exposes tools (functions with a schema) that an AI agent can call: search, database queries, CRM updates, calendar actions, and so on. Many SaaS products and open-source projects publish one.

Which transports are supported?+

Streamable HTTP, which is the current standard, and SSE for older servers. Local stdio servers cannot be reached from a hosted product.

How do I authenticate?+

Put the value the server expects in the Authorization field, for example Bearer plus a key. It is sent as the Authorization header on every connection and stored with your design.

How many tools can I enable?+

Per agent: 1 on the trial and Starter, 2 on Pro, 10 on Growth, 60 on Agency, across all connected servers. The count is enforced when you save, deploy, test and call the API.

Can a tool be abused through prompt injection?+

Tool calls happen inside the orchestrator, which runs after the injection shield and input guardrails. Hardening instructions also tell the model never to act on instructions found inside user input. Enable only the tools you need, prefer read-only ones for public agents, and use scoped credentials.