guide Updated 2026-10-06

AI Agent Connections

Give an AI agent scoped access to your workspace over MCP.

What a connection does

A connection lets an AI agent work in your workspace on your behalf, with your access level — over the Model Context Protocol (MCP). The agent can read what you can read and do what you can do, scoped to that workspace and bounded by the capabilities you leave enabled on the connection.

Everything below happens in Workspace Settings → Integrations. Every member can see the workspace's connections (name, owner, status, expiry) — transparency without secrets. Owners manage their own; admins can revoke any.

Agent connections are a Pro feature. Each member can hold up to 10 connections per workspace.

Creating a connection

New connection

Open the Integrations tab and create one. Give it a name you will recognize later — `Claude Code — laptop` beats `test` — and choose an expiry: 90 days by default, or 30 / 90 / 365 / never.

Copy the token — once

The connection token (`nv_live_…`) is shown a single time. Copy it into your client before closing the dialog; if you lose it, rotate the connection and copy a fresh one.

Wire up your client

Pick your client and paste the pre-filled snippet — the dialog provides one for **Claude Code**, **Claude Desktop**, **Cursor**, and a generic "Other" form. For Claude Code:
claude mcp add --transport http nimbus https://workspace.nimbusvault.app/mcp \
  --header "Authorization: Bearer nv_live_…"

For JSON-based clients (Claude Desktop, Cursor):

{
  "mcpServers": {
    "nimbus": {
      "type": "http",
      "url": "https://workspace.nimbusvault.app/mcp",
      "headers": { "Authorization": "Bearer nv_live_…" }
    }
  }
}

First prompt

Ask your agent: *"Use Nimbus to show my workspace context."* The first exchange flips the connection from **Never** to recently used — proof the loop works.

What the agent can do

The agent receives a curated tool surface — the read and write operations that map to the vault's workflows:

  • Read — workspace context, search across the vault, programs and assets, an asset's component digest, ranked suggestions, the checklist, history, and change feeds.
  • Act — link observed components, resolve prompts, record outcomes, and create library entries, following the same methodology the docs describe.

Each connection has capability toggles — open a connection's row to tune exactly which of those the agent may use. Start narrow; widen deliberately.

Agents also receive Nimbus's working guide as part of the connection, so they follow the same map → suggest → confirm → record loop you do.

Managing connections

  • Status chips — Active, Expired, or Revoked, at a glance.
  • Rename / renew / rotate — lifecycle actions for the owner. Rotate immediately if a token leaks.
  • Revoke — owners revoke their own; admins can revoke any. Revocation takes effect at the next exchange, and live sessions end shortly after.
  • Delete — removes revoked or expired rows permanently.
  • Leaving or being removed from a workspace deletes your connections for it.

Security model

  • Workspace-scoped. A token reaches one workspace and nothing else.
  • No secret at rest. The raw token is never stored or logged — only a hash, used to mint short-lived sessions.
  • Expiry by default. Connections come with an end date unless you deliberately choose otherwise.
  • Audited. Connecting, revoking, and every write the agent makes are recorded in the workspace's audit log.

What's next