Connect MCP servers
Proxium can hold the MCP servers of your project, such as a GitHub, Jira or docs server. Your agent connects to one URL. It gets the tools of each server, and Proxium makes the calls with the credential of the project.
| MCP URL | https://proxium.tech/mcp?project=<project> |
| Tool names | <server>__<tool>, for example github__create_issue |
| Who adds servers | The owners of the project |
| Who calls tools | The members of the project, and the virtual keys of the project |
| Credential | Sealed for the project. Nobody can read it again after you save it |
Before you start
- You are an owner of the project.
- The MCP server has an
httpsaddress on the public internet. Proxium refuses a private, loopback or link-local address. - The server signs in with no credential, with a bearer token, or with a token in a header. Sign-in with OAuth is not served yet.
1. Add a server
- In the console, open MCP servers.
- Select Add a server.
- In Name, type a short name of lower-case letters, digits and hyphens, such as
github. The nameproxiumis not allowed. - In URL, paste the MCP endpoint of the server, such as
https://mcp.example.com/mcp. - In Sign-in, select no sign-in, bearer token or token in a header. For a header, type its name in Header, such as
x-api-key. - In Credential, paste the token.
- Keep Transport at auto. Proxium tries Streamable HTTP first, then HTTP+SSE.
- Select Add and list its tools.
Proxium reads the tool list of the server. Under Tools, turn off a tool that your agents must not call, and select Save tools. If the server adds a tool later, select Refresh.
2. Connect your agent
The agent uses the URL of Connect an MCP client, with your project in it:
claude mcp add --transport http proxium "https://proxium.tech/mcp?project=acme"
The console shows this URL under Connect an agent.
| Who signs in | Tools that the agent gets |
|---|---|
| A person, with a Proxium account | The tools of Proxium, and the tools of the servers of the project |
An app, with a virtual key of the project as Authorization: Bearer mbk_… | The tools of the servers of the project only |
3. Read the call log
Under Tool calls, the console shows each call: when, which tool, who called it, and the outcome. Proxium does not store the arguments or the answer of a call.
Limits
| Servers in one project | 20 |
| Tools of one server | 500, and 2 MiB of tool list |
| Arguments of one call | 256 KiB |
| Answer of one call | 1 MiB |
| Time of one call | 60 seconds |
| Credential | 8 KiB |
API reference
The console uses these routes. Each one takes the sign-in of the console. The tool list and the call also take a virtual key of the project.
| Route | Who | Does |
|---|---|---|
GET /api/teams/{slug}/mcp/servers | Members | Lists the servers. A URL is shown without its query |
POST /api/teams/{slug}/mcp/servers | Owners | Adds a server: name, url, optional transport, auth_kind, header_name and credential |
PATCH /api/teams/{slug}/mcp/servers/{id} | Owners | Turns a server or some of its tools on or off |
DELETE /api/teams/{slug}/mcp/servers/{id} | Owners | Removes a server and its credential |
PUT /api/teams/{slug}/mcp/servers/{id}/credential | Owners | Replaces the credential. The answer does not hold it |
DELETE /api/teams/{slug}/mcp/servers/{id}/credential | Owners | Removes the credential |
POST /api/teams/{slug}/mcp/servers/{id}/refresh | Owners | Reads the tool list of the server again |
GET /api/teams/{slug}/mcp/tools | Members, keys | The tools that the caller may call |
POST /api/teams/{slug}/mcp/call | Members, keys | Calls one tool: name and arguments |
GET /api/teams/{slug}/mcp/calls | Members | The call log |
How Proxium keeps the projects apart
- Proxium seals each credential with a key of its project. A credential copied to another project cannot be opened.
- The database shows the rows of the MCP tables only to a transaction of their project.
- Proxium checks the address of the server again at each call, and connects only to the address that it checked. It follows no redirect.
- A credential is not in an answer, in the call log or in a project export. A project export holds the URL of a server without its query.