# Model Context Protocol (MCP)

Connect your own tools with Model Context Protocol

Model Context Protocol (MCP) servers extend Droid's capabilities with extra tools and context. You can manage them two ways: an interactive manager inside the TUI for browsing and setup, or `droid mcp` CLI commands for scripting and automation. Droid supports three transports: **stdio** (local processes), **http** (Streamable HTTP, the current MCP standard, which streams responses over SSE internally), and **sse** (the legacy standalone HTTP+SSE transport, for older servers).

<Note>
  For a supported cloud app with Factory-managed setup and guided authentication, use [Connectors](/harness/connectors). Use MCP when you need a custom tool, a self-hosted service, or direct control over the server and transport.
</Note>

## Quick start: add from the registry

The fastest way to start is the built-in server registry.

<Steps>
  <Step title="Open the manager">
    Type `/mcp` inside Droid and select **Add from Registry**.
  </Step>
  <Step title="Pick a server">
    Browse the registry and choose one, such as `linear`, `sentry`, or `playwright`.
  </Step>
  <Step title="Authenticate">
    For remote servers that need OAuth, follow the browser prompt. The server is then ready to use.
  </Step>
</Steps>

Representative registry servers include:

| Server | Description |
| :----- | :---------- |
| linear | Issue tracking and project management |
| sentry | Error tracking and performance monitoring |
| notion | Notes, docs, and project management |
| figma | Generate code with Figma context |
| stripe | Payment processing APIs |
| supabase | Create and manage Supabase projects |
| vercel | Manage projects and deployments |
| playwright | End-to-end browser testing |

The registry includes many more servers than shown here.

<Tip>
  The registry is the quickest path for popular servers. For custom servers or automation, use the CLI commands below.
</Tip>

## Manage servers interactively (`/mcp`)

Type `/mcp` inside Droid to open the interactive manager. From there you can:

{/* sweep-allow: term-bullets */}

- **Browse servers** and see their connection status.
- **View tools** that each connected server provides.
- **Enable or disable** servers without removing them.
- **Authenticate** OAuth-enabled servers via the browser.
- **Clear auth** to remove stored credentials for a server.
- **Add from registry** for one-click setup of popular servers.
- **Remove** user-configured servers.

Run `/mcp off` to disable every configurable server for the current session. Organization-managed servers are unaffected.

## Add servers from the CLI

For scripting and automation, use `droid mcp add`. The transport flag determines how the rest of the arguments are parsed.

```bash
droid mcp add <name> <urlOrCommand...> --type <stdio|http|sse>
```

- `name` is a unique server identifier.
- `--type` defaults to `stdio` when omitted.
- `--env KEY=VALUE` sets environment variables (stdio only, repeatable).
- `--header "KEY: VALUE"` sets HTTP headers (http/sse only, repeatable).
- `--no-oauth` disables OAuth for a header- or API-key-authenticated remote server (stores `oauth: false`).

<Tabs>
  <Tab title="HTTP">
    HTTP servers are remote MCP endpoints, the recommended way to connect to cloud services.

    ```bash
    droid mcp add linear https://mcp.linear.app/mcp --type http
    ```

    Pass authentication headers with `--header`, repeating the flag as needed:

    ```bash
    droid mcp add twelvelabs https://mcp.twelvelabs.io --type http \
      --header "x-api-key: YOUR_API_KEY"
    ```

    Use `--no-oauth` when a server authenticates by header or API key and you do not want Droid to attempt an OAuth flow:

    ```bash
    droid mcp add internal https://mcp.internal.example.com/mcp --type http \
      --header "Authorization: Bearer YOUR_TOKEN" --no-oauth
    ```
  </Tab>
  <Tab title="SSE">
    `sse` is the legacy HTTP+SSE transport. Prefer `http` (which already streams over SSE internally) and reach for `sse` only when a server offers just the older standalone SSE endpoint. Arguments mirror HTTP; only `--type` changes.

    ```bash
    droid mcp add example-sse https://mcp.example.com/sse --type sse \
      --header "Authorization: Bearer YOUR_TOKEN"
    ```
  </Tab>
  <Tab title="stdio">
    Stdio servers run as local processes, ideal for tools that need direct system access. Quote the command if it contains spaces, and pass environment variables with `--env`.

    ```bash
    droid mcp add airtable "npx -y airtable-mcp-server" \
      --env AIRTABLE_API_KEY=your_key
    ```
  </Tab>
</Tabs>

<Tip>
  `npx` examples install the latest published version of a package. For security-sensitive setups, pin an explicit version (for example `airtable-mcp-server@1.4.0`) so updates are deliberate and auditable.
</Tip>

<Tip>
  Many remote servers require OAuth. After adding one, run `/mcp` to complete the browser authentication flow.
</Tip>

## Manage servers from the CLI

List every configured server with its connection and authentication status:

```bash
droid mcp list
```

Each server reports its current status: **connected**, **connecting**, **needs authentication**, or **failed**. Servers that require OAuth show **needs authentication** until you finish the sign-in flow with `/mcp`.

Remove a user-configured server:

```bash
droid mcp remove <name>
```

### Persistent tool permissions

When you approve an MCP tool, Droid can remember that approval so it persists across sessions. Each approval is bound to a stable fingerprint of the server's transport configuration (its stdio command and arguments, or its http/sse URL). If a previously trusted server name is later re-pointed at a different command or URL, the stored approval no longer applies and the tool must be approved again.

Manage these approvals with `droid mcp permissions`:

```bash
droid mcp permissions list
droid mcp permissions revoke <server> [tool]
droid mcp permissions clear --confirm
```

- `list` shows all persistent permissions.
- `revoke <server>` removes a server's approval, including all of its per-tool approvals. Add a `tool` argument to revoke a single tool.
- `clear --confirm` removes every persistent permission.

<LabeledDivider label='Files and schema' />

## Configuration file

MCP server configurations are stored in `mcp.json` files at three levels:

| Level | Location | Purpose |
| :---- | :------- | :------ |
| **User** | `~/.factory/mcp.json` | Your personal servers, available in every project. |
| **Folder** | `.factory/mcp.json` in an ancestor directory of the project | Servers shared across nested projects under a common parent. |
| **Project** | `.factory/mcp.json` in the project root | Shared team servers, committed to the repo. |

Organizations can also provide servers centrally and restrict which ones are allowed through managed settings (see [Enterprise: MCP policy](#enterprise-mcp-policy)).

**Behaviors to know:**

- Servers you add with `droid mcp add` or the registry always go to your **user** config.
- **Project servers cannot be removed** with `droid mcp remove` or the `/mcp` manager. To remove them, edit `.factory/mcp.json` directly.
- When you **enable or disable** a project-defined server, Droid writes a copy to your user config with the new state and leaves the project file untouched, so your teammates are unaffected.
- When the same server name is defined at more than one level, Droid loads one definition for it. Organization-managed servers and the [MCP policy](#enterprise-mcp-policy) always take precedence. The `/mcp` manager shows which file each server comes from.

OAuth tokens are stored globally in your system keyring (or a fallback file), not per project, so authenticating with a server in one project authenticates it everywhere that server is configured. Use the `/mcp` manager's **Clear Auth** action to remove stored credentials.

<Warning>
  Project-level `.factory/mcp.json` is committed to the repo. Never put secrets there: header auth tokens (such as `Authorization`), `oauth.clientSecret`, or API keys. Keep them in your user-level config (`~/.factory/mcp.json`), supply them through environment variables, and rely on Droid's keyring for OAuth tokens.
</Warning>

Droid reloads automatically when an `mcp.json` file changes, so new servers are available immediately.

<CodeGroup>

```json HTTP
{
  "mcpServers": {
    "linear": {
      "type": "http",
      "url": "https://mcp.linear.app/mcp",
      "disabled": false
    }
  }
}
```

```json SSE
{
  "mcpServers": {
    "example-sse": {
      "type": "sse",
      "url": "https://mcp.example.com/sse",
      "headers": {
        "Authorization": "Bearer YOUR_TOKEN"
      },
      "disabled": false
    }
  }
}
```

```json stdio
{
  "mcpServers": {
    "playwright": {
      "command": "npx",
      "args": ["-y", "@playwright/mcp@latest"],
      "disabled": false
    }
  }
}
```

</CodeGroup>

## Schema reference

Each server entry accepts these common fields:

| Field | Type | Description |
| :---- | :--- | :---------- |
| `type` | `"stdio" \| "http" \| "sse"` | Transport. May be omitted for stdio servers, which default to `stdio`. |
| `disabled` | `boolean` | Temporarily disable the server (default: `false`). |
| `disabledTools` | `string[]` | Tool names to exclude from this server. Excluded tools are never loaded into context. |
| `timeout` | `number` | Tool call timeout in milliseconds. Bounds each tool invocation, not the initial connection. Falls back to the built-in default when omitted. |
| `connectTimeout` | `number` | Connection timeout in milliseconds for the initial server handshake. Falls back to the transport default when omitted: 10 seconds (10000ms) for `http`/`sse`, 30 seconds (30000ms) for `stdio`. |

Transport-specific fields:

- **stdio** servers use `command` (the executable), `args` (an array of arguments), and `env` (an object of environment variables).
- **http** and **sse** servers use `url` (the endpoint), `headers` (an object of HTTP headers), and `oauth` (OAuth overrides, or `false` to disable OAuth entirely).

### Tool filtering

A server can expose many tools, and you may not want all of them in every session. Use `disabledTools` to exclude specific tools persistently in `mcp.json`. Every tool the server reports is loaded except the listed names, and excluded tools are never registered with the model, so they do not consume context tokens.

```json title="mcp.json"
{
  "mcpServers": {
    "my-server": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@some/mcp-server"],
      "disabledTools": ["tool_i_dont_need", "another_unused_tool"]
    }
  }
}
```

<Tip>
  Run `/mcp` to see the exact tool names a server exposes, then copy them into `disabledTools`.
</Tip>

<LabeledDivider label='Credentials' />

## Secrets and variable expansion

Droid expands `${NAME}` references in `mcp.json` against your current shell environment when it connects to a server. This keeps secrets out of the file itself so you can source them from a secret manager, a `.env` loader, or your shell profile. Only the `${NAME}` form is supported; there is no default-value syntax.

Expansion applies to credential-bearing fields only:

- `env` values for **stdio** servers.
- `headers` values for **http** and **sse** servers.
- `oauth.clientId` and `oauth.clientSecret` for **http** and **sse** servers.

It does **not** apply to `command`, `args`, or `url`.

```json title="mcp.json"
{
  "mcpServers": {
    "context7": {
      "type": "http",
      "url": "https://mcp.context7.com/mcp",
      "headers": {
        "CONTEXT7_API_KEY": "${CONTEXT7_API_KEY}"
      },
      "disabled": false
    },
    "airtable": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "airtable-mcp-server"],
      "env": {
        "AIRTABLE_API_KEY": "${AIRTABLE_API_KEY}"
      }
    }
  }
}
```

If a referenced variable is unset, the connection to that server fails with an error naming the missing variable. The raw `mcp.json` file is never rewritten with expanded values; expansion happens in memory at connection time, so secrets stay out of disk and version control.

## OAuth overrides

For most remote servers, OAuth works with zero configuration: Droid discovers the authorization server, registers a client automatically via Dynamic Client Registration (DCR), and uses Factory's published client metadata when the server supports Client ID Metadata Documents (CIMD). **Prefer these defaults.** Only set `oauth` overrides when a provider requires a custom trust or compatibility policy. Set `oauth: false` to disable OAuth for a server entirely.

The `oauth` object on an **http** or **sse** server supports:

| Field | Type | Description |
| :---- | :--- | :---------- |
| `scopes` | `string[]` | OAuth scopes to request instead of the discovered defaults. |
| `resource` | `string \| false` | OAuth resource indicator to send instead of the normalized MCP server URL; set to `false` to omit it. |
| `authorizationServerIssuer` | `string` | Authorization server issuer URL. Required when `clientId` / `clientSecret` are set. |
| `clientId` | `string` | Pre-registered OAuth client ID, skipping dynamic registration. |
| `clientSecret` | `string` | Client secret for the pre-registered client. |
| `clientMetadataUrl` | `string` | HTTPS URL of a custom Client ID Metadata Document (CIMD) to use as the public client identity. |
| `tokenEndpointAuthMethod` | `"none" \| "client_secret_basic" \| "client_secret_post"` | Force a token endpoint authentication method instead of the discovered one. |
| `callbackPort` | `number` | Fixed localhost port for the OAuth callback (1-65535). |

**Constraints:**

- `clientMetadataUrl` must be an HTTPS URL with a non-root path and no credentials, query string, fragment, or dot segments.
- `clientMetadataUrl` is mutually exclusive with `clientId` / `clientSecret`: a metadata document **is** the client identity, so pre-registered credentials cannot be combined with it.
- `clientMetadataUrl` describes a public client, so `tokenEndpointAuthMethod` must be `"none"` (or omitted) when it is set.
- `clientId` / `clientSecret` require `authorizationServerIssuer` to be set.

```json title="mcp.json"
{
  "mcpServers": {
    "internal-tools": {
      "type": "http",
      "url": "https://mcp.internal.example.com/mcp",
      "oauth": {
        "clientMetadataUrl": "https://auth.example.com/oauth/client-metadata.json"
      }
    }
  }
}
```

```json title="mcp.json"
{
  "mcpServers": {
    "partner-api": {
      "type": "http",
      "url": "https://mcp.partner.example.com/mcp",
      "oauth": {
        "tokenEndpointAuthMethod": "none"
      }
    }
  }
}
```

<LabeledDivider label='Tuning and scoping' />

## MCP timeouts

Two independent per-server settings bound how long Droid waits on an MCP server, both in milliseconds:

- `timeout` bounds each tool invocation. Long-running tools (large data exports, browser automations, model-backed servers) can exceed the built-in default and fail with a timeout error.
- `connectTimeout` bounds the initial connection and initialization handshake. Slow-starting servers (heavy `npx` installs, servers that compile on first launch) can exceed the transport default: 10 seconds for `http`/`sse` servers, 30 seconds for `stdio` servers.

```json title="mcp.json"
{
  "mcpServers": {
    "slow-server": {
      "type": "stdio",
      "command": "my-long-running-server",
      "connectTimeout": 60000,
      "timeout": 120000
    }
  }
}
```

A server's values override the built-in defaults; there is no global timeout setting.

<Note>
  Increasing these timeouts only changes how long Droid waits. They do not extend any timeouts enforced by the MCP server itself or its upstream APIs.
</Note>

## Per-droid server selection

[Custom droids](/harness/subagents) can choose which configured MCP servers they may use through the `mcpServers` field in their frontmatter. This scopes a subagent to specific servers (for example `mcpServers: ["linear", "github"]`) instead of inheriting every server in the session. For finer-grained control, a droid's `tools` list can name exact registered MCP tool IDs. See [Selecting MCP servers](/harness/subagents#selecting-mcp-servers) for details.

<LabeledDivider label='Org controls' />

## Enterprise: MCP policy

Organizations can centrally control which MCP servers are allowed through the `mcpPolicy` setting in [org-managed settings](/enterprise/hierarchical-settings-and-org-control#mcp), so users can only connect to vetted servers. A server is allowed when any allowlist entry matches its hostname or stdio command or arguments, not its configured name.

| Field | Type | Description |
| :---- | :--- | :---------- |
| `enabled` | `boolean` | Whether policy enforcement is active (default: `false`). When `false` or absent, no policy is enforced and configured servers are allowed. |
| `allowlist` | `string[]` | Allowed hostname or stdio command matchers, applied only when the policy is enabled. HTTP/HTTPS URL entries are also accepted, but only their hostname is matched. Entries do not match the configured server name. When the policy is enabled with an empty or absent allowlist, all servers are blocked. |

```json title="settings.json"
{
  "mcpPolicy": {
    "enabled": true,
    "allowlist": [
      "https://mcp.linear.app",
      "https://mcp.sentry.dev",
      "*.mcp-gateway.example.com",
      "npx"
    ]
  }
}
```

<Note>
  `mcpPolicy` is enforced through managed settings, and individual users cannot override it. Servers disallowed by policy remain in `mcp.json` and are still loaded into your configuration, but they are filtered out from running or connecting and do not appear as available in the `/mcp` manager.
</Note>

### Remote hostname matching

Remote `http` and `sse` servers are matched by hostname only. You can use a bare hostname or an HTTP/HTTPS URL; a URL is parsed and reduced to its hostname. The scheme, port, credentials, path, query string, and fragment do not restrict access.

In a hostname, `*` matches zero or more characters, including dots, so it can span multiple subdomain levels. Other characters are literal, not regular expressions or extended glob syntax. Entries without wildcards continue to match both the hostname itself and its subdomains.

Each row below is evaluated on its own, with no other allowlist entries:

| Allowlist entry | Example allowed URLs | Example blocked URL |
| :-------------- | :------------------- | :------------------ |
| `example.com` | `https://example.com/mcp`, `https://nested.tools.example.com/mcp` | `https://notexample.com/mcp` |
| `https://example.com/mcp` | `http://example.com:8080/other`, `https://api.example.com/other` | `https://example.com.attacker.example/mcp` |
| `*.example.com` | `https://tools.example.com/mcp`, `https://nested.tools.example.com/mcp` | `https://example.com/mcp` |
| `https://*.example.com/mcp/*` | `http://tools.example.com:8080/other` | `https://example.com/mcp` |
| `tools*.example.com` | `https://tools.example.com/mcp`, `https://tools1.example.com/mcp` | `https://other-tools.example.com/mcp` |
| `*.bücher.example` | `https://tools.bücher.example/mcp`, `https://tools.xn--bcher-kva.example/mcp` | `https://bücher.example/mcp` |
| `bü*.example` | `https://bücher.example/mcp`, `https://xn--bcher-kva.example/mcp` | `https://bĺ.example/mcp` |

<Warning>
  A full URL is not an endpoint restriction. `https://example.com/mcp`, `https://example.com/`, and `example.com` allow the same hostnames, including their subdomains. They also allow HTTP, different ports, and paths other than `/mcp`. Enforce scheme-, port-, path-, or tenant-specific restrictions at your gateway or another network control.
</Warning>

Use a valid HTTP/HTTPS URL when including a scheme, port, or path. For example, `http://localhost:3000/mcp` allows other ports and paths on that hostname. Scheme and port wildcards such as `*://example.com` and `http://localhost:*` are not supported. Bare entries with paths or ports, such as `example.com/` and `example.com:443`, are not hostname matches.

Hostname matching is case-insensitive, trims surrounding whitespace in entries, and ignores a trailing DNS dot. Wildcard matching normalizes internationalized hostnames and compares their decoded form so an embedded wildcard keeps its position. For an internationalized hostname without a wildcard, use a full URL such as `https://bücher.example/mcp` or its ASCII hostname `xn--bcher-kva.example`, not the bare Unicode hostname `bücher.example`. Only a literal ASCII `*` enables wildcard matching; encoded stars such as `%2A` and full-width stars such as `＊` are not wildcard syntax.

A wildcard must match the entire hostname. For example, `*.example.com` does not allow `notexample.com` or `tools.example.com.attacker.example`, and cannot match text in a URL's credentials, path, or fragment. A bare `*` allows every remote hostname, but does not allow malformed URLs, URLs without a hostname, or stdio commands.

These allowlist rules are separate from the picomatch glob patterns in [`mcpAutonomyUrlOverrides`](#enterprise-mcp-autonomy-url-overrides), which control tool risk levels rather than server access.

### Example: allow production and staging gateways

Suppose each approved MCP service has its own subdomain under your production or staging gateway. Add both gateway patterns to your org-managed settings, replacing the example domains with domains your organization controls:

```json title="settings.json"
{
  "mcpPolicy": {
    "enabled": true,
    "allowlist": [
      "*.mcp-gateway.prod.example.com",
      "*.mcp-gateway.staging.example.com"
    ]
  }
}
```

Users can then configure servers such as these in `~/.factory/mcp.json`, or a team can share them in the project's `.factory/mcp.json`:

```json title="mcp.json"
{
  "mcpServers": {
    "ticketing": {
      "type": "http",
      "url": "https://atlassian.mcp-gateway.prod.example.com/mcp"
    },
    "code-search": {
      "type": "http",
      "url": "https://sourcegraph.mcp-gateway.prod.example.com/mcp"
    },
    "staging-tools": {
      "type": "sse",
      "url": "https://tools.mcp-gateway.staging.example.com/sse"
    }
  }
}
```

All three servers pass the policy because of their URL hostnames, regardless of the names `ticketing`, `code-search`, and `staging-tools`. The allowlist does not add servers or authenticate them; users still need to configure them and complete any required authentication.

With only the two gateway entries above:

| Server URL | Policy result | Why |
| :--------- | :------------ | :-- |
| `https://docs.team.mcp-gateway.prod.example.com/mcp` | Allowed | `*` spans multiple subdomain levels. |
| `http://atlassian.mcp-gateway.prod.example.com:8080/other` | Allowed | Scheme, port, and path do not restrict the hostname match. |
| `https://mcp-gateway.prod.example.com/mcp` | Blocked | `*.` does not include the parent hostname. |
| `https://tools.mcp-gateway.dev.example.com/mcp` | Blocked | Neither entry allows the development gateway. |
| `https://tools.mcp-gateway.prod.example.com.attacker.example/mcp` | Blocked | The hostname does not end at the approved domain. |
| `https://attacker.example/atlassian.mcp-gateway.prod.example.com/mcp` | Blocked | An approved hostname in the path does not count. |

To also allow the parent gateway, replace `*.mcp-gateway.prod.example.com` with `mcp-gateway.prod.example.com`; a non-wildcard hostname allows both the parent and its subdomains. This policy does not grant blanket access to stdio servers.

### Local command matching

For `stdio` servers, entries match substrings of the command or individual arguments after lowercasing and removing everything except ASCII letters and digits. Hostname wildcard rules do not apply to `stdio` servers.

For example, with `"command": "npx"` and `"args": ["-y", "figma-mcp"]`:

| Allowlist entry | Policy result | Why |
| :-------------- | :------------ | :-- |
| `npx` | Allowed | Matches the command, so it also allows other servers launched with `npx`. |
| `figma-mcp` | Allowed | Matches an argument after normalization. |
| `figma-*` | Allowed | Becomes `figma`, a substring of the normalized argument; `*` is removed, not expanded. |
| `fig*mcp` | Blocked | Becomes `figmcp`, which is not a substring of the command or any argument. |
| `*` | Blocked | Normalization leaves an empty matcher. |

Choose matchers deliberately: allowing a launcher such as `npx` is broader than matching a package argument. Stdio matching is a substring check, not package identity or integrity verification.

## Enterprise: MCP autonomy URL overrides

Administrators can assign a default [autonomy risk level](/autonomy-and-safety/auto-run) to remote MCP servers by URL with the `mcpAutonomyUrlOverrides` org-managed setting, controlling how much confirmation a matching server's tools require before Droid runs them.

Each rule maps a URL pattern to a risk level:

| Field | Type | Description |
| :---- | :--- | :---------- |
| `urlPattern` | `string` | Glob pattern ([picomatch](https://github.com/micromatch/picomatch) syntax) matched against the server's URL. |
| `defaultLevel` | `"low" \| "medium" \| "high"` | Risk level for the matching server's tools, compared against the user's Autonomy Level to decide auto-run vs. confirm. |

```json
{
  "mcpAutonomyUrlOverrides": [
    { "urlPattern": "https://mcp.internal.example.com/**", "defaultLevel": "low" },
    { "urlPattern": "https://*.partner.example.com/**", "defaultLevel": "medium" },
    { "urlPattern": "https://**", "defaultLevel": "high" }
  ]
}
```

**Matching and precedence:**

{/* sweep-allow: term-bullets */}

- **Remote servers only.** Rules match remote servers that have a URL (`http` and `sse` transports); local `stdio` servers are unaffected.
- **First match wins.** Rules are checked in order, so list the most specific patterns first.
- **Safety floor.** A rule sets a tool's risk *classification*, not an absolute prompt: `high`-classified tools still follow the normal [Autonomy Level](/autonomy-and-safety/auto-run) comparison. The floor is one-directional: `low` or `medium` cannot pull a tool that is not read-only (destructive, or missing safety metadata) below `high`, so you can relax confirmation for read-only tools but never auto-approve destructive ones.
- **Fallback.** Servers with no matching rule use Droid's built-in tool risk classification (read-only hints and curated defaults).

<Note>
  `mcpAutonomyUrlOverrides` is admin-managed (MDM): it is delivered through [org-managed settings](/enterprise/hierarchical-settings-and-org-control) and users cannot override or weaken it.
</Note>

<RelatedLinks>
  <RelatedLink href='/harness/connectors' title='Connectors'>
    Connect supported third-party apps with managed authentication.
  </RelatedLink>
  <RelatedLink href='/harness/subagents' title='Custom droids (subagents)'>
    Scope which MCP servers a subagent may use through its frontmatter.
  </RelatedLink>
  <RelatedLink href='/droid-cli/settings' title='Settings'>
    Configure MCP servers, policy, and autonomy URL overrides at every scope.
  </RelatedLink>
  <RelatedLink href='/autonomy-and-safety/auto-run' title='Autonomy Level'>
    Control when MCP and connector tools require confirmation.
  </RelatedLink>
</RelatedLinks>
