Skip to content
Everruns Cloud is open in early access. Run agents without operating the platform.
IDuser_mcp
CategoryIntegrations
FeaturesNone
DependenciesNone
RiskMedium

Adds the user MCP servers of the person who sent the current message to the agent’s MCP servers for that turn. Each server signs in as that person. With use alone the capability adds no tools of its own; the tools come from the person’s servers. With manage on, the agent can also change the person’s list in chat.

  • A personal assistant such as Platform Chat, where each person brings their own Linear, Notion or internal servers.
  • Any agent people talk to directly and should be able to extend for themselves without editing the agent.

Leave it off for agents that run unattended or in shared channels: they get nothing from it.

SettingDefaultEffect
usetrueAdd the person’s enabled servers to each turn.
managefalseGive the agent the tools below to change the person’s list.
allow_custom_urlsfalseWith manage, let the agent add a server by URL, not only from the organization’s MCP catalog.
{ "ref": "user_mcp", "config": { "use": true, "manage": true } }

Added only when manage is on. They act on the list of the person who sent the message, the same list as Settings > My MCP servers, and never on the organization catalog.

ToolWhat it doesAsks the person first
list_user_mcp_serversLists the person’s servers: enabled, signed in, and whether this agent skips one because its own server has the same nameNo
add_user_mcp_serverAdds a catalog server ({"catalog": "linear"}), or a server by URL when allow_custom_urls is onYes
remove_user_mcp_serverRemoves a serverNo
enable_user_mcp_serverTurns a server onYes
disable_user_mcp_serverTurns a server off without removing itNo
connect_mcp_serverShows the person a Connect card for a server that needs a sign-inNo

add_user_mcp_server and enable_user_mcp_server wait for the person to approve them in chat (the card shows the call, such as the catalog name or URL), whether or not the agent has Tool Approval on. remove and disable only take tools away and run without asking.

A server added or enabled in a turn is usable from the person’s next message. connect_mcp_server never sees a credential: the person signs in in their own browser, as with any Connect card. Servers added in chat cannot carry API keys or headers; the person adds those in Settings.

  • Only the person who sent the message counts, never the session owner or the agent’s own account. Unattended runs get no servers.
  • Sessions with more than one person get no servers.
  • An agent or capability server with the same name wins; the person’s server is skipped. list_user_mcp_servers and the agent’s MCP servers sheet report it.
  • The manage tools refuse to run without a person (unattended runs) and in sessions with more than one person, with a message saying so.
  • A server that fails validation is skipped on its own; the rest still load.

Medium. The agent can call any tool on servers the person chose, with the person’s login. Tool approval and the agent’s other guardrails apply to these tools as to any MCP tool.

With manage, adding a server is how a prompt injection would try to send the person’s data somewhere new. That is why adding and enabling always wait for the person’s approval, custom URLs are off by default, and every URL goes through the same address checks as the API.