# Direct connections

> Connect an MCP server or HTTP API you run to your agents with its endpoint and headers. Every call asks for approval unless you always allow it.

A **direct connection** links your agents to a server you run: a remote MCP server or an HTTP API. You give endue its endpoint and the headers it needs, and the agents you attach it to can call it.

## When to use it

Use a direct connection for a service with no connector in the catalog: an internal API, your own MCP server, a tool your team built. If the service is in [Available connectors](/docs/connect/available-connectors/), use that connector instead. Its operations are already classified, so only sending and deleting ask you first.

## MCP server or HTTP server

| | MCP server | HTTP server |
| --- | --- | --- |
| **Endpoint** | The server's MCP endpoint, using the Streamable HTTP transport | A base URL |
| **What the agent gets** | Each tool the server lists, with the server's names and descriptions | One request tool that sends GET, POST, PUT, PATCH, or DELETE to paths under the base URL |
| **Description** | Optional. Helps you recognize the server in the list. | Required. The agent reads it to know which paths and methods to use. |

## Add a direct connection

<Steps>

1. **Open Resources › Connectors** from the left sidebar, select the **Direct** tab, then **Add direct connection**.

2. **Choose the type**: **MCP server** or **HTTP server**. It cannot be changed after you save.

3. **Fill in the fields.**

   - **Name**: shown in lists and in the conversation.
   - **Endpoint URL**: an `https://` address on the public internet. For an HTTP server this is the base URL, and the agent can reach only paths under it.
   - **Headers**: one row per header the server needs, such as `Authorization` with `Bearer …`.
   - **Description**: for an HTTP server, write what the agent needs to know: the paths, the methods, and an example. For instance: *GET items?q=term finds items. POST items with `{"title": "…"}` creates one.*

4. **Select Check connection.** Nothing is saved yet.

   - For an MCP server, you see the server's name, the MCP protocol version, the tools it offers, and any tools the agent cannot use, with the reason.
   - For an HTTP server, endue sends one GET request to the base URL, or to **Path to check** under it if you fill that in, and shows the status code and the start of the response.

5. **Select Save.** For an MCP server the tool list is fetched as part of saving. If the server cannot be reached, nothing is saved.

6. **Attach it to an agent.** In that agent's [Agent Builder](/docs/build/agent-builder/), open **Resources › Connectors** and pick it like any other connection. It shows a **Direct** badge and its host.

</Steps>

## Headers

Header values, such as tokens, are stored encrypted. Once saved they are not shown again, not even to you, and they never reach the agent or the conversation: endue adds them to each request itself, and the agent cannot add headers of its own.

When you edit a connection, leave a value empty to keep it or type a new one to replace it. Because saved values are not sent back to your browser, **Check connection** on an existing connection needs every header value typed again.

`Host`, `Content-Length`, `Connection`, and headers starting with `Proxy-`, `CF-`, `X-Forwarded-`, or `Mcp-` are managed by the connection and cannot be set.

## Approvals

Every call to a direct connection **asks for your [approval](/docs/work/approvals/)** by default. endue does not know what a tool on your server does, and it does not take the server's own description of a tool as a reason to skip the question.

To let calls go ahead without asking, select **Edit** on the connection in the **Direct** tab and turn on **Always allow**:

- **MCP server**: per tool.
- **HTTP server**: per method, for example GET.

Runs that nobody is watching, such as [routines](/docs/automate/routines/) and [channels](/docs/automate/channels/), can use only what you set to Always allow. Other calls in those runs are refused.

<Aside type="caution" title="Always allow is your decision alone">
  Turn it on only for calls you are happy to have run with no one checking, such as
  read-only lookups. A tool that changes data on your server should keep asking.
</Aside>

## Network rules

endue calls your server from its own infrastructure, not from your computer. The server has to be reachable from the internet:

- `https://` only, on port 443 or 8443.
- A public domain name. IP addresses, `localhost`, names that resolve to private addresses, and endue's own addresses are rejected. So is a URL with a username or password in it; put credentials in a header.
- Redirects are followed only to the same host.
- Each call has 30 seconds. An HTTP response larger than 256 KB is cut off at 256 KB. An MCP response larger than 256 KB fails. A request body over 256 KB is not sent.

Requests come from Cloudflare's network. If your server has a firewall or an allowlist, allow Cloudflare's IP ranges.

## Managing a connection

The **Direct** tab lists each connection with its type, host, number of tools, status, and the agents using it.

- **Fetch again** re-reads an MCP server's tool list. Do this after you change the tools on the server. The list is also fetched again when you change the endpoint or headers.
- **Error** means endue could not reach the server the last time it tried. Open the connection to see the reason.
- **Delete** erases the saved header values and removes the connection from every agent that uses it. It cannot be undone.

## Limits

- Up to 20 direct connections per account.
- MCP servers must use the Streamable HTTP transport. Servers that use the older HTTP with SSE transport, or that require an OAuth sign-in, are not supported.
- An HTTP server gives the agent one request tool and your description. endue does not read an OpenAPI document. The agent handles JSON and text responses, not file uploads or streamed responses.
- Servers on a private network cannot be reached. The server needs a public HTTPS address.
- Tools whose input format the agent cannot use are left out and listed as unusable, with the reason.
- A direct connection belongs to your account. It does not appear in the catalog.

## Related

<CardGrid>
  <LinkCard
    title="Connectors overview"
    href="/docs/connect/overview/"
    description="Connections, binding, and catalog connectors."
  />
  <LinkCard
    title="Approvals"
    href="/docs/work/approvals/"
    description="What you see when a call asks first."
  />
  <LinkCard
    title="Security and permissions"
    href="/docs/account/security/"
    description="What an agent can reach, and how credentials are held."
  />
</CardGrid>
