Skip to main content

Tools & Connectors

Tools let an assistant do things beyond answering from what it already knows: look up a record, call an API, file a ticket, update a system. Without tools an assistant can only reason over its instructions and its knowledge.

How assistants get tools

Every assistant starts with a set of built-in tools — file generation, web search, and the platform tools for Spaces, records, tasks and workflows. You do not attach those; they are always there. Everything else arrives through an integration. An integration is an MCP server: a service that describes its own tools, so the assistant learns what each one does and what arguments it takes without you writing any of that down.

What is MCP?

MCP (Model Context Protocol) is an open standard for connecting AI models to data and tools. A server exposes a set of operations and describes them in a machine-readable way, so any MCP-aware assistant can discover and use them.
  • Standardised interface across every connector
  • Self-describing — the assistant reads the tool definitions
  • Reusable across assistants in the same account
Assistants do not carry every tool definition in the conversation. They look tools up on demand and call the one they need, so attaching an integration does not add its whole catalogue to every message.

Attaching an integration

1

Open the assistant's Integrations tab

In the assistant editor, the left menu is General, Provider, Instructions, Knowledge, Integrations, Context. Choose Integrations.
2

Click Add Integration

The picker opens with four tabs:
  • Account Integrations — servers already connected in your account
  • Assistants — other assistants in the account, so this one can hand work to a specialist. See Multi-Assistant Systems
  • Marketplace — connectors published for your account to install
  • Custom Integration — build a server from an API description of your own
3

Select what you need and save

The assistant can now reach that server’s tools. It cannot reach anything you have not attached.

Building a custom integration

The Custom Integration tab turns an API description into an MCP server. Upload either:
  • an OpenAPI specification, or
  • a Postman collection (you can add the API server URLs it should target)
Give the server a name and create it. It then appears in Account Integrations and can be attached to any assistant.

Adding a remote MCP server

If a vendor already runs an MCP server for you, add it by URL from Account Integrations → Add an MCP server rather than from an assistant. You supply the endpoint, choose the transport (streamable HTTP or SSE), and say how it signs in — No sign-in needed, OAuth, or a bearer token / JWT. Once registered, attach it to assistants like any other integration.

Authentication

Auth is derived, not chosen

There is no “auth type” dropdown where you declare a server open or protected. Whether credentials are required comes from the server’s own description:
  • If the server declares that it requires authentication, authentication is required — nothing can talk it down to open.
  • If it does not, individual operations can still declare their own security, and those still require credentials.
The practical consequence: a server can look unauthenticated overall and still refuse specific calls. If tool calls come back unauthorised on a server you believed was public, that is why.

Whose credential the call runs as

This is the fact most easily missed, and it changes what an assistant can see.
An assistant running in a flow, on a schedule, or behind a trigger resolves the account’s credential for the server — the one an admin connected for the team. It does not act as whoever started the run.
Creating a shared connection — one the whole account resolves — requires the Admin or Root role. Members below that can connect only on their own behalf.

Storing credentials in Secrets

Sensitive values belong in Secrets, reached from More → Secrets in the sidebar. The page is available to the Admin, Root and Developer roles.
1

Create a secret

Give it a key and a value. Keys are alphanumeric with hyphens and underscores.
2

Reference it from a configuration

Write the reference instead of the value:
It is resolved when the call is made. A malformed reference is refused rather than sent literally.
3

Use a personal secret where each member has their own

A personal secret is namespaced to its author:
Secrets give you one place to rotate a credential, and role-based access to the page itself. Update the secret once and every reference to it picks up the new value.

What gates a tool call — and what does not

Read this section before you connect anything that changes data or moves money.

What genuinely stops a call

An assistant can only call tools from the integrations on its Integrations tab, plus its built-ins. Nothing attached means nothing external is reachable. This is the real control surface — decide what an assistant may touch by deciding what you attach to it.
If the server requires authentication and no credential resolves for the identity making the call, the call fails. That is a hard stop, but it is an availability boundary rather than a policy one: it either works for everything the credential permits, or it works for nothing.
Scopes on an OAuth connection, permissions on an API key, rules inside the service you are calling. This is the only place a limit like “read-only”, “this project only” or “no refunds above X” can actually be enforced. Grant the narrowest credential that does the job.
Only Admin and Root can create an account-wide connection; only Admin, Root and Developer can open Secrets. That governs who can grant reach, not what an assistant does once it has it.

What does not stop a call

Nothing you write in a tool description, a parameter note, or an assistant’s instructions is enforced. It is guidance to a language model, and a model may ignore it.There is no field anywhere on an integration or a tool for rules, thresholds, monetary limits, or an approval requirement. Writing “requires approval above $500” into a description creates no gate of any kind — it reads like a control and behaves like a suggestion.
If an action must not happen without a person agreeing to it, the assistant must not hold a credential that can perform it unsupervised. Give it a read-only credential and route the action through a workflow with a human step, or through a Space task somebody has to complete. Do not rely on wording.

About authorisation prompts

Abbie’s chat can ask before she uses an integration for the first time, and can ask again before a small, explicit set of irreversible actions. That prompt is part of the chat surface.
A configured assistant — one running in a flow, on a schedule, or behind a trigger — has no chat surface to show such a prompt on, so consent is not enforced for it. If it were, the assistant would sit permanently waiting on a question nobody is there to answer. Plan on the assistant proceeding.

Writing instructions about tools

Instructions steer tool choice, which is a real and useful thing to do — just not a safety mechanism. Be specific about when to reach for a tool:
Vague instructions produce vague tool use. “Use tools as needed” tells the assistant nothing. Keep the attached set small. A tighter set of well-named tools is chosen from more reliably than a large one with overlapping purposes.

Troubleshooting

  • Confirm the integration is attached on the Integrations tab
  • Say in the instructions when the tool should be used
  • Check the tool’s own description is specific — a vague description is hard to select against
  • Test the underlying API outside QuivaWorks to confirm it responds
  • Look for tools with near-identical names or descriptions and remove the redundant one
  • Add explicit selection guidance to the instructions
  • Give worked examples of which request maps to which tool
  • Check the credential is connected for the identity actually making the call — a configured assistant uses the account’s connection, not yours
  • A server that looks open can still have operations that demand credentials
  • Confirm an OAuth connection has not been revoked at the provider
  • Confirm the credential’s scopes cover the operation, not just the service
  • Check the external service’s own status and rate limits
  • Narrow the query so the service returns less
  • The assistant’s Timeout setting is on the General tab

Next Steps

Multi-Assistant Systems

Let one assistant hand work to a specialist

Knowledge

Give an assistant documents to work from

Prompt Engineering

Write instructions that steer tool choice

Best Practices

Get more out of your assistants