How ToPreviewFor developerFor agency

Connections and current research

Connect workspace tools with explicit permissions and use current public information with saved sources.

Last updated 2026-10-02

What you'll achieve

  • Configure and revoke a workspace MCP connection.
  • Understand private provider sign-in and tool permissions.
  • Use Azure Foundry research and reopen its saved sources.

Connect Idam to your workspace tools and use current public information while building. Connection permissions control which tools Idam can use; saved research includes its sources and retrieval dates.

Workspace connections

The Connections screen is available at /dashboard/idam/connections when Idam is accessible. Owners and admins manage connections; developers inspect the granted tools and health. Staff membership does not bypass workspace membership.

Use the normal authenticated session and CSRF flow with X-Organization-Id:

Operation Endpoint Required fields
List GET /api/idam/connections/ Optional before cursor
Discover choices POST /api/idam/connections/discover/ endpoint, auth_type; token for new bearer authentication; optional existing connection_id and revision together
Create POST /api/idam/connections/ client_request_id, name, endpoint, auth_type, permissions, expires_at; token for bearer authentication
Update PUT /api/idam/connections/UUID/ Current revision and the complete configuration
Check POST /api/idam/connections/UUID/check/ Empty object
Revoke DELETE /api/idam/connections/UUID/ None

permissions maps exact tool names to read or write. expires_at is a future timezone-aware ISO timestamp or null. Reuse the creation UUID after an uncertain save; changed intent needs a new UUID. Updates compare the saved revision. A blank replacement token preserves the existing token only for the same server. Tokens are never returned. Revocation erases the credential and invalidates pending discovery, including while new connections are disabled.

Guided setup lists tool names and descriptions before saving. New tools default to no access; the customer explicitly chooses Read or Write for 1–30 tools. Tools with unsupported schemas are visible but cannot be selected. Manual name entry remains available. Changing the endpoint or authentication clears the previous selection. Server descriptions are displayed as untrusted plain text. Rediscovery names previously selected tools that disappeared or became unsupported and explains that saving removes their access; discovery itself changes no grant.

Setup discovery is ephemeral: it creates no connection or grant, stores no new token and never calls a tool. Omitting a token reuses a saved credential only with the current connection revision, identical endpoint and authentication type, and an active original grant. Every protocol request and final result recheck manager and account authority. Sensitive reflected metadata is rejected. Discovery is limited to 10 requests per minute per user and the bounded protocol deadline. CLI setup and connection mutations require organizations:write; task execution scope alone cannot administer connections. Listing requires ai:read for CLI sessions. Workspace membership remains required; workload identities cannot use personal Idam endpoints.

Responses include credential_stored, a boolean indicating encrypted credential presence without decrypting it. This does not prove that the credential is valid. Revoked connections report false; the interface shows the credential as removed.

recent_actions contains at most ten administrative events. tool_activity contains at most ten invocations from the current user's tasks in the same workspace, newest first. Managing a connection does not reveal other members' private task activity. Removed task content is excluded. Activity exposes only the invocation ID, tool name, access class, lifecycle/outcome, timestamps and reserved/charged credit units. Prompts, arguments, results, service charges and task links are omitted. The database selects the result's error flag without loading the response body.

A returned result is distinct from a tool-reported error, a verified customer outcome and credit settlement. An unknown external outcome remains unknown with its credit hold intact; the interface does not offer automatic retry. Revocation stops new use but does not retroactively cancel an already-sent external action.

Supported servers use MCP Streamable HTTP with protocol 2025-11-25 or 2025-06-18, JSON or bounded SSE responses, over public HTTPS. Authentication is bearer or none. Configured providers can obtain a bearer token through the private sign-in flow below. Legacy HTTP/SSE and private-network tunnels are not supported. A successful check performs initialize and tool discovery; it does not run a customer tool or install credentials in a deployed application.

Private provider sign-in

Private sign-in appears only for configured providers. For other supported MCP servers, use the reviewed bearer-token or unauthenticated connection flow. Arbitrary website login and automatic token renewal are not supported.

For a configured provider, choose Sign-in method, enter the exact tool names and access levels, and select Sign in privately. Continue to secure sign-in opens the provider in a separate tab. Return to Connections and select Finish connecting to save the reviewed permissions. Signing in alone does not create a grant. A task is not automatically resumed by connecting a provider.

Open Options → Connect a service from a conversation to keep a return link. After sign-in, the connection page retains that link across reloads and interrupted responses. Check the connection, return to the saved conversation, and send your next request. The existing task keeps its original tool contracts, permissions, credit holds and execution receipts. Connecting never replays a pending action. Removed conversations or loss of project access remove the return link.

The provider owns the password entry screen. It is outside Idam's shared browser, screenshots, model context and analytics. Only the requesting workspace manager can finish the connection. Refresh status after an interrupted response; the interface does not automatically repeat a code exchange or a connection mutation. If the provider tab is lost before completing sign-in, cancel and start again.

Operation Endpoint Body
Providers and own sessions GET /api/idam/connections/sign-in/ Optional task_id query to verify a conversation return target
Begin POST /api/idam/connections/sign-in/ provider, configuration, connection_id and revision (both null for new connections), optional task_id
Finish POST /api/idam/connections/sign-in/UUID/ Empty object
Cancel DELETE /api/idam/connections/sign-in/UUID/ None

configuration contains name, endpoint, auth_type: "bearer", exact permissions, and expires_at. Sessions last ten minutes, with at most three active sessions per requester and workspace. Status reads allow 60 requests per minute; mutations allow ten, independently. The normal session, CSRF, CLI scope and workspace authority requirements above apply. Status never returns tokens, authorization codes or the original authorization link. Conversation targets contain only the task and project IDs, checked against the current requester and workspace. They are navigation hints, never tool authority. Completed sign-ins with a conversation target remain visible for up to one day so a lost finish response does not lose the return path.

Provider endpoints and configuration are bound to each attempt. Changing them, revoking access, or changing membership invalidates the attempt. Temporary verifiers and tokens are encrypted and bound to the requester, workspace and session; completion and expiry remove them. Access-token expiry caps the grant's expiry. Refresh tokens and ID tokens are discarded. Expired access needs a fresh sign-in. Cleanup runs with the existing Idam attachment-expiry maintenance task.

Tool schemas use bounded JSON Schema 2020-12 objects. Remote/recursive references, regex patterns, formats, unique-item and contains evaluation are rejected. Tool results currently support bounded text and structured JSON; embedded resource, image and audio content is not fetched. Server annotations and instructions cannot expand a grant. A changed definition requires fresh discovery before execution.

There are at most 30 active connections per workspace and 30 granted tools per connection. Discovery has one 25-second deadline across all requests, at most 100 tools and four catalogue pages. Health becomes stale after five minutes. Every protocol request and the publication of discovery results recheck authority. Removing and restoring an account or membership does not revive an old grant.

The task coordinator automatically refreshes relevant stale or unchecked connections before offering their tools. It ranks the full 30-connection quota, refreshes at most eight connections within a shared 25-second deadline, then returns before billable model/tool execution. Developers can use this existing grant without gaining connection-management permissions. Every request rechecks the task lease, task and account authority, connection revision, and grant. Database transactions end before network requests. Recent failed checks are cached; abandoned check leases can be recovered after 60 seconds.

If discovery expires while a model response is arriving, the coordinator retains that response and refreshes in a later job. It does not repeat inference. Pinned tool definitions cannot silently change, and uncertain external actions never become retryable through refresh. Missing external-tool pricing omits those tools before the initial model round; ordinary model tasks can still proceed. Actual invocations continue to require fresh discovery, separate credit holds, per-request authority checks, and the durable send fence.

Research boundary

Azure Foundry's built-in Responses search is the selected production provider. It uses Bing underneath; no separate Brave account or Bing resource is required. Automatic queries come from reviewed public topics. Arbitrary queries require explicit public search input; raw chat, private source and account facts are never sent as search queries.

Public page retrieval retains bounded public HTML/text and preserves the title, URL, retrieval time and content digest. Restored evidence is labelled fresh or stale. Page text is untrusted evidence and cannot authorize an action.

The coordinator offers native web.search through protocol 2, including project-free questions. The Brave provider additionally offers web.fetch. Foundry returns an intact grounded answer with its original references. Those links are not inputs to automatic page retrieval or crawling. Search selects a public query ID. Brave page retrieval selects a settled search invocation and result rank from the same task; a model cannot supply an arbitrary destination. An explicit request in the form “Search the web for …” can add a screened public query. Other prompts use the public topic catalogue; private conversation, source and account context never become search queries. If pricing or provider configuration is missing, these tools are omitted without preventing ordinary assistance.

The customer tariff contains rate_version, review_digest, search_units and fetch_units. Queries and rates are pinned for each task, together with the provider, endpoint, deployment and identity, and checked again before execution. Each native read has its own durable invocation, credit reservation and send fence. Only successful validated results charge customer credits; failed or uncertain reads release them. A lost response never causes the same invocation to be resent. Customer credit release does not establish a zero upstream cost.

Saved native research is returned as live_research in task detail and conversation turns. It includes validated source URLs, titles, original retrieval timestamps, stored/freshness labels and whether the answer cited each source. Task detail includes bounded excerpts or the intact Foundry answer and original references. The conversation list omits source content, including Foundry grounding, to avoid separating its references from the answer. Reopening these records performs no network search and consumes no credits. Reviewed snapshots remain separate in research_sources. Content removal clears saved query/source content while retaining financial records. Reading sources requires current task/conversation access.

Native citations are bound to settled research results and model history before they can enter an answer. Saved proposals validate their final outcome and source history again when preparing source changes or workflow handoff, independently of whether live research is currently configured. Current write access, source revision and customer authority still apply.

References: MCP transport specification, Azure Foundry web search, Bing terms, Microsoft Privacy Statement.

Help improve this page

Sign in to send page-specific feedback. For account-specific help, email support@blinkhost.me.