Connecting Other Tools to Guru (via MCP)

Guru's third-party MCP integration lets you connect external tools and services to your Knowledge Agents using the Model Context Protocol (MCP). This enables your agents to retrieve data and take actions in tools like Asana, Slack, Salesforce, and more - directly within Guru's chat interface.

👥

Access Required

Admins manage which MCP servers are available and how people connect to them. Knowledge Agent Owners configure which MCPs each agent uses. On Personal connections, individual users authenticate and control permissions for their own connections. On Shared connections, an admin authenticates once for everyone.


❗️

Want to access Guru FROM other applications?

Learn how to use Guru as an MCP server in Claude, CoPilot, and other tools here.

What is third-party MCP integration?

Third-party MCP integration uses the Model Context Protocol to connect Knowledge Agents to external tools that support OAuth authentication. This standardized approach lets you:

  • Retrieve data from connected tools in real-time
  • Execute actions like creating tasks, sending messages, or updating records
  • Maintain security with granular permission controls at every level
  • Track activity with full logging in the AI Agent Center

How it's different from Guru's MCP Server:
Guru's MCP Server lets external tools access your Guru knowledge. Third-party MCP integration works in the opposite direction - it lets Guru's Knowledge Agents access external tools.


How third-party MCP works

MCP integration operates with three layers of control:

Workspace level: Admins determine which MCP servers your workspace can use and choose a connection type for each one: Personal or Shared. Adding an MCP server requires a URL that supports OAuth, which Guru validates during setup.

Knowledge Agent level: Agent Owners select which MCPs each agent should access. Each MCP can be marked as Required or Optional:

  • Required MCPs block chat until users authenticate
  • Optional MCPs can be activated by users as needed

User level: On Personal connections, individual users authenticate via OAuth. On both connection types, users manage their own permission preferences for each MCP action.


Setting up MCP servers (Workspace Admins)

  1. Navigate to Manage > Apps & Integrations > Third-Party MCP Servers.
  2. Click Add MCP Server.
  3. Enter the MCP server URL. The server must support OAuth 2.0 with Dynamic Discovery. The MCP server must support HTTP Streaming. Guru does not support Server Side Events (SSE). Guru will validate the URL and display a status:
    1. Valid. The server supports OAuth and can be added.
    2. Invalid. The server doesn't support OAuth or the URL is incorrect
  4. Select a connection type: Personal or Shared. Read Choosing a connection type below if you're not sure which to pick.
    1. If you chose Shared, authorize the connection with the account you want everyone to act through.
  1. Click Add to make the MCP server available to your workspace.
✍️

Note

Adding an MCP server at the workspace level doesn't automatically enable it for any Knowledge Agents—Agent Owners must explicitly add it to their agents.

You choose the connection type when you add the server, and you can't change it afterward. To switch a server from Personal to Shared, or from Shared to Personal, add the server again with the other connection type.


Choosing a connection type

Personal. Each person who uses a Knowledge Agent with this server signs in with their own account. Actions run as that person, with that person's permissions in the external tool. Choose Personal when actions should be attributed to individual users.

Shared. An admin authorizes the connection once. Everyone who uses a Knowledge Agent that has this server enabled is connected right away, with no Connect button and no sign-in prompt. Actions run as the account the admin authorized with. Choose Shared when your integration runs on a service account or a single team credential, or when you want a Knowledge Agent to work for a large group without asking each person to sign in.

💡

Tip

Authorize a Shared connection with a service account whenever you can. Everything the server does runs with that account's access in the external tool, so choose the account on purpose.

Not sure where to start? Add a low-stakes internal tool as a Shared connection, enable it on one Knowledge Agent, and let a few teammates try it in chat. They can use it without a single connect prompt.


Configuring MCPs for Knowledge Agents (Agent Owners)

  1. Navigate to Manage > Knowledge Agents.
  2. Select the Knowledge Agent you want to configure.
  3. Go to the MCP Connectors tab.
  4. Click Add MCP Connector and select from available workspace MCPs.
  5. Choose whether the MCP is Required or Optional:
  • Required: Users must authenticate before using the agent
  • Optional: Users can choose to enable the MCP during chat
  1. Click Save.
💡

Tip

Mark MCPs as Required when the agent's core functionality depends on data from that tool. Use Optional for supplementary data sources.

The Required and Optional setting doesn't apply to Shared servers. A Shared server is always active in chat, because there's nothing for people to sign in to.


Authenticating and managing MCPs (Users)

✍️

Note

If your admin set up an MCP server as a Shared connection, you don't need to authenticate. The server is ready to use as soon as you chat with a Knowledge Agent that has it enabled. The steps below apply to Personal connections.

When you first interact with a Knowledge Agent that uses MCPs, you'll see a connector option in the chat interface.

Authenticating an MCP:

  1. Click the connector icon in the chat interface.
  2. Select the MCP you want to authenticate.
  3. Follow the OAuth flow to sign in to the external tool.
  4. Grant Guru permission to access your account.

Managing MCP permissions:

During chat, you'll see permission prompts when the agent wants to use an MCP action:

  • Allow Once – Approve this specific action
  • Allow Always – Pre-approve all read-only actions from this MCP
  • Deny – Block this action

Approvals stay personal on Shared connections too. You still see the Allow Once, Allow Always, and Deny prompts, and your choices are tracked separately from everyone else's.

Your permission preferences are remembered across chat threads.

💡

TIp

Read-only actions (like searching or viewing data) can be pre-approved if the MCP server marks them with read-only hints. Destructive actions (like creating or deleting content) always require confirmation.

Resetting your MCP connection:

To clear all permission preferences and start fresh:

  1. Click the connector icon in chat.
  2. Find the connected MCP.
  3. Click Disconnect.
  4. Reconnect and re-authenticate to reset all settings.

How MCPs work in Chat and Research

In Chat:
When a Knowledge Agent with MCPs is active, you can:

  • Ask questions that pull data from connected tools
  • Approve or deny each MCP action individually
  • See which MCP was used in the agent's citations

In Research:
When starting a Research task, you'll:

  • Review the research plan upfront
  • Batch-approve all MCP actions needed for the research
  • See MCP data integrated into the final research report with proper citations
❗️

Important

In the AI Agent Center, only the person who asked a question that used MCPs can see the full answer. This prevents data leakage across users with different permissions


Understanding permission controls

Third-party MCP integration includes multiple permission layers:

Tool-level permissions: Users must have appropriate access in the external tool itself (e.g., access to specific Asana projects).

Guru workspace permissions: Users must have access to the Knowledge Agent using the MCP.

Source permissions: If the MCP server is also connected as a Source in Guru, standard Source permissions apply.

User authentication: Each user authenticates their own MCP connections—permissions can't be shared.


Did this page help you?