AI Agent Connections
Give an AI agent scoped access to your workspace over MCP.
What a connection does
A connection lets an AI agent work in your workspace on your behalf, with your access level — over the Model Context Protocol (MCP). The agent can read what you can read and do what you can do, scoped to that workspace and bounded by the capabilities you leave enabled on the connection.
Everything below happens in Workspace Settings → Integrations. Every member can see the workspace's connections (name, owner, status, expiry) — transparency without secrets. Owners manage their own; admins can revoke any.
Creating a connection
New connection
Copy the token — once
Wire up your client
claude mcp add --transport http nimbus https://workspace.nimbusvault.app/mcp \
--header "Authorization: Bearer nv_live_…"
For JSON-based clients (Claude Desktop, Cursor):
{
"mcpServers": {
"nimbus": {
"type": "http",
"url": "https://workspace.nimbusvault.app/mcp",
"headers": { "Authorization": "Bearer nv_live_…" }
}
}
}
First prompt
What the agent can do
The agent receives a curated tool surface — the read and write operations that map to the vault's workflows:
- Read — workspace context, search across the vault, programs and assets, an asset's component digest, ranked suggestions, the checklist, history, and change feeds.
- Act — link observed components, resolve prompts, record outcomes, and create library entries, following the same methodology the docs describe.
Each connection has capability toggles — open a connection's row to tune exactly which of those the agent may use. Start narrow; widen deliberately.
Agents also receive Nimbus's working guide as part of the connection, so they follow the same map → suggest → confirm → record loop you do.
Managing connections
- Status chips — Active, Expired, or Revoked, at a glance.
- Rename / renew / rotate — lifecycle actions for the owner. Rotate immediately if a token leaks.
- Revoke — owners revoke their own; admins can revoke any. Revocation takes effect at the next exchange, and live sessions end shortly after.
- Delete — removes revoked or expired rows permanently.
- Leaving or being removed from a workspace deletes your connections for it.
Security model
- Workspace-scoped. A token reaches one workspace and nothing else.
- No secret at rest. The raw token is never stored or logged — only a hash, used to mint short-lived sessions.
- Expiry by default. Connections come with an end date unless you deliberately choose otherwise.
- Audited. Connecting, revoking, and every write the agent makes are recorded in the workspace's audit log.
What's next
- Share and Collaborate — the human side of working together.
- Search the Workspace — the same surface, driven by you.