Connections and current research
Connect workspace tools with explicit permissions and use current public information with saved sources.
Last updated 2026-10-02
What you'll achieve
- Configure and revoke a workspace MCP connection.
- Understand private provider sign-in and tool permissions.
- Use Azure Foundry research and reopen its saved sources.
Connect Idam to your workspace tools and use current public information while building. Connection permissions control which tools Idam can use; saved research includes its sources and retrieval dates.
Workspace connections
The Connections screen is available at /dashboard/idam/connections when Idam is
accessible. Owners and admins manage connections; developers inspect the granted
tools and health. Staff membership does not bypass workspace membership.
Use the normal authenticated session and CSRF flow with X-Organization-Id:
| Operation | Endpoint | Required fields |
|---|---|---|
| List | GET /api/idam/connections/ |
Optional before cursor |
| Discover choices | POST /api/idam/connections/discover/ |
endpoint, auth_type; token for new bearer authentication; optional existing connection_id and revision together |
| Create | POST /api/idam/connections/ |
client_request_id, name, endpoint, auth_type, permissions, expires_at; token for bearer authentication |
| Update | PUT /api/idam/connections/UUID/ |
Current revision and the complete configuration |
| Check | POST /api/idam/connections/UUID/check/ |
Empty object |
| Revoke | DELETE /api/idam/connections/UUID/ |
None |
permissions maps exact tool names to read or write. expires_at is a future
timezone-aware ISO timestamp or null. Reuse the creation UUID after an uncertain
save; changed intent needs a new UUID. Updates compare the saved revision. A blank
replacement token preserves the existing token only for the same server. Tokens
are never returned. Revocation erases the credential and invalidates pending
discovery, including while new connections are disabled.
Guided setup lists tool names and descriptions before saving. New tools default to no access; the customer explicitly chooses Read or Write for 1–30 tools. Tools with unsupported schemas are visible but cannot be selected. Manual name entry remains available. Changing the endpoint or authentication clears the previous selection. Server descriptions are displayed as untrusted plain text. Rediscovery names previously selected tools that disappeared or became unsupported and explains that saving removes their access; discovery itself changes no grant.
Setup discovery is ephemeral: it creates no connection or grant, stores no new
token and never calls a tool. Omitting a token reuses a saved credential only with
the current connection revision, identical endpoint and authentication type, and
an active original grant. Every protocol request and final result recheck manager
and account authority. Sensitive reflected metadata is rejected. Discovery is
limited to 10 requests per minute per user and the bounded protocol deadline.
CLI setup and connection mutations require organizations:write; task execution
scope alone cannot administer connections. Listing requires ai:read for CLI
sessions. Workspace membership remains required; workload identities cannot use
personal Idam endpoints.
Responses include credential_stored, a boolean indicating encrypted credential
presence without decrypting it. This does not prove that the credential is valid.
Revoked connections report false; the interface shows the credential as removed.
recent_actions contains at most ten administrative events. tool_activity
contains at most ten invocations from the current user's tasks in the same
workspace, newest first. Managing a connection does not reveal other members'
private task activity. Removed task content is excluded. Activity exposes only
the invocation ID, tool name, access class, lifecycle/outcome, timestamps and
reserved/charged credit units. Prompts, arguments, results, service charges and
task links are omitted. The database selects the result's error flag without
loading the response body.
A returned result is distinct from a tool-reported error, a verified customer outcome and credit settlement. An unknown external outcome remains unknown with its credit hold intact; the interface does not offer automatic retry. Revocation stops new use but does not retroactively cancel an already-sent external action.
Supported servers use MCP Streamable HTTP with protocol 2025-11-25 or
2025-06-18, JSON or bounded SSE responses, over public HTTPS. Authentication is
bearer or none. Configured providers can obtain a bearer token through the private
sign-in flow below. Legacy HTTP/SSE and private-network tunnels are not supported.
A successful check performs initialize and tool discovery; it does
not run a customer tool or install credentials in a deployed application.
Private provider sign-in
Private sign-in appears only for configured providers. For other supported MCP servers, use the reviewed bearer-token or unauthenticated connection flow. Arbitrary website login and automatic token renewal are not supported.
For a configured provider, choose Sign-in method, enter the exact tool names and access levels, and select Sign in privately. Continue to secure sign-in opens the provider in a separate tab. Return to Connections and select Finish connecting to save the reviewed permissions. Signing in alone does not create a grant. A task is not automatically resumed by connecting a provider.
Open Options → Connect a service from a conversation to keep a return link. After sign-in, the connection page retains that link across reloads and interrupted responses. Check the connection, return to the saved conversation, and send your next request. The existing task keeps its original tool contracts, permissions, credit holds and execution receipts. Connecting never replays a pending action. Removed conversations or loss of project access remove the return link.
The provider owns the password entry screen. It is outside Idam's shared browser, screenshots, model context and analytics. Only the requesting workspace manager can finish the connection. Refresh status after an interrupted response; the interface does not automatically repeat a code exchange or a connection mutation. If the provider tab is lost before completing sign-in, cancel and start again.
| Operation | Endpoint | Body |
|---|---|---|
| Providers and own sessions | GET /api/idam/connections/sign-in/ |
Optional task_id query to verify a conversation return target |
| Begin | POST /api/idam/connections/sign-in/ |
provider, configuration, connection_id and revision (both null for new connections), optional task_id |
| Finish | POST /api/idam/connections/sign-in/UUID/ |
Empty object |
| Cancel | DELETE /api/idam/connections/sign-in/UUID/ |
None |
configuration contains name, endpoint, auth_type: "bearer", exact
permissions, and expires_at. Sessions last ten minutes, with at most three
active sessions per requester and workspace. Status reads allow 60 requests per
minute; mutations allow ten, independently. The normal session, CSRF, CLI scope
and workspace authority requirements above apply. Status never returns tokens,
authorization codes or the original authorization link.
Conversation targets contain only the task and project IDs, checked against the
current requester and workspace. They are navigation hints, never tool authority.
Completed sign-ins with a conversation target remain visible for up to one day
so a lost finish response does not lose the return path.
Provider endpoints and configuration are bound to each attempt. Changing them, revoking access, or changing membership invalidates the attempt. Temporary verifiers and tokens are encrypted and bound to the requester, workspace and session; completion and expiry remove them. Access-token expiry caps the grant's expiry. Refresh tokens and ID tokens are discarded. Expired access needs a fresh sign-in. Cleanup runs with the existing Idam attachment-expiry maintenance task.
Tool schemas use bounded JSON Schema 2020-12 objects. Remote/recursive references, regex patterns, formats, unique-item and contains evaluation are rejected. Tool results currently support bounded text and structured JSON; embedded resource, image and audio content is not fetched. Server annotations and instructions cannot expand a grant. A changed definition requires fresh discovery before execution.
There are at most 30 active connections per workspace and 30 granted tools per connection. Discovery has one 25-second deadline across all requests, at most 100 tools and four catalogue pages. Health becomes stale after five minutes. Every protocol request and the publication of discovery results recheck authority. Removing and restoring an account or membership does not revive an old grant.
The task coordinator automatically refreshes relevant stale or unchecked connections before offering their tools. It ranks the full 30-connection quota, refreshes at most eight connections within a shared 25-second deadline, then returns before billable model/tool execution. Developers can use this existing grant without gaining connection-management permissions. Every request rechecks the task lease, task and account authority, connection revision, and grant. Database transactions end before network requests. Recent failed checks are cached; abandoned check leases can be recovered after 60 seconds.
If discovery expires while a model response is arriving, the coordinator retains that response and refreshes in a later job. It does not repeat inference. Pinned tool definitions cannot silently change, and uncertain external actions never become retryable through refresh. Missing external-tool pricing omits those tools before the initial model round; ordinary model tasks can still proceed. Actual invocations continue to require fresh discovery, separate credit holds, per-request authority checks, and the durable send fence.
Research boundary
Azure Foundry's built-in Responses search is the selected production provider. It uses Bing underneath; no separate Brave account or Bing resource is required. Automatic queries come from reviewed public topics. Arbitrary queries require explicit public search input; raw chat, private source and account facts are never sent as search queries.
Public page retrieval retains bounded public HTML/text and preserves the title, URL, retrieval time and content digest. Restored evidence is labelled fresh or stale. Page text is untrusted evidence and cannot authorize an action.
The coordinator offers native web.search through protocol 2, including
project-free questions. The Brave provider additionally offers web.fetch.
Foundry returns an intact grounded answer with its original references. Those
links are not inputs to automatic page retrieval or crawling. Search selects a
public query ID. Brave page retrieval
selects a settled search invocation and result rank from the same task; a model
cannot supply an arbitrary destination. An explicit request in the form
“Search the web for …” can add a screened public query. Other prompts use the
public topic catalogue; private conversation, source and account context never
become search queries. If pricing or provider configuration is missing, these
tools are omitted without preventing ordinary assistance.
The customer tariff contains
rate_version, review_digest, search_units and fetch_units. Queries and rates
are pinned for each task, together with the provider, endpoint, deployment and
identity, and checked again before execution. Each native read has
its own durable invocation, credit reservation and send fence. Only successful
validated results charge customer credits; failed or uncertain reads release
them. A lost response never causes the same invocation to be resent. Customer
credit release does not establish a zero upstream cost.
Saved native research is returned as live_research in task detail and conversation
turns. It includes validated source URLs, titles, original retrieval timestamps,
stored/freshness labels and whether the answer cited each source. Task detail
includes bounded excerpts or the intact Foundry answer and original references.
The conversation list omits source content, including Foundry grounding, to avoid
separating its references from the answer. Reopening these
records performs no network search and consumes no credits. Reviewed snapshots
remain separate in research_sources. Content removal clears saved query/source
content while retaining financial records. Reading sources requires current
task/conversation access.
Native citations are bound to settled research results and model history before they can enter an answer. Saved proposals validate their final outcome and source history again when preparing source changes or workflow handoff, independently of whether live research is currently configured. Current write access, source revision and customer authority still apply.
References: MCP transport specification, Azure Foundry web search, Bing terms, Microsoft Privacy Statement.
Help improve this page
Sign in to send page-specific feedback. For account-specific help, email support@blinkhost.me.