MCP connectors let agents use tools from external services. Connections are installed in a vault in the Distill app and are available to every agent in that vault.
Distill discovers the server’s tools. Your agents can then use them when you ask for work involving the connected service. Every agent in the vault shares the permissions granted to that connection, including any ability to change data.
Connections use Streamable HTTP. Local subprocess servers, private-network URLs, and older standalone SSE endpoints are not supported.
Access token: Enter a bearer token issued by the service. It is stored in your device’s secure credential store. Use Update token to replace it.
OAuth: Sign in through your system browser. Distill uses PKCE and refreshes tokens when needed. Servers must advertise an issuer and support S256. If the provider requires a registered application, enter its public native client ID and register distill://connectors/oauth as the callback URL. You can cancel a pending sign-in in the app.
No authentication: Use this for public servers that do not require credentials.
Disabling or removing a connection blocks queued work. An action already sent to the provider may still finish. When an interrupted call has an unknown outcome, Distill stops the run rather than automatically repeating it. Check the connected service before trying again.
Requests go directly from your device to the external service. Credentials stay in the device’s secure credential store, and connections do not sync. Set up each device separately. Tool results become part of the agent conversation and may be sent to the agent’s configured AI provider.
If you previously connected services through the web dashboard, upgrade the app and reconnect them in the vault. The backend no longer stores or runs connectors.
Check the server URL, authentication, and Streamable HTTP support if discovery fails. A supported public HTTPS URL must not contain credentials, query parameters, or a fragment. Use Refresh tools after the server changes. If OAuth registration fails, use a registered native client ID accepted by that provider or a bearer token if the service supports it.