Agent gateway (MCP)
rsync.ai runs an MCP server. An AI agent that speaks MCP over HTTP can read your workspace's pipelines, runs, schemas and models, ask why a run failed, and draft pipelines, workflows and dashboards for you to review.
What an agent can and can't do
- It reads metadata, never data. No row values, sample rows, query results, row counts, connection settings or credentials are ever returned.
- It writes only through a scope. A token can add a connector, build and schedule models, and propose a pipeline, workflow or dashboard. A person checks and turns on anything it proposes.
- It never runs, edits or deletes a pipeline or a connection.
- It acts as you. Every tool runs through the same handlers as the UI, so an agent sees what you see in that workspace and nothing more.
Make a token
In Settings → AI apps, under Connect your AI app:
- Name the token after where it will live, such as “Claude Code on my laptop”.
- Pick when it expires: 30 days, 90 days or 1 year. Every token expires.
- Tick only what the agent should do besides read.
- Select Create token. It's shown once; rsync.ai keeps only its hash.
A token starts with rsat_. You can hold 20 live tokens in each workspace, and you revoke one in the same place. An agent using a revoked token gets a 401 on its next call.
RSYNC_AGENT_GATEWAY_ENABLED=true on the api-gateway service and restart it.Connect an agent
Settings shows the exact address for your deployment: your API address followed by /api/agent/v1/mcp. With https://rsync.example.com as that address:
Claude Code
claude mcp add --transport http rsync-ai https://rsync.example.com/api/agent/v1/mcp \ --header "Authorization: Bearer rsat_..."
Cursor
In .cursor/mcp.json:
{
"mcpServers": {
"rsync-ai": {
"url": "https://rsync.example.com/api/agent/v1/mcp",
"headers": { "Authorization": "Bearer rsat_..." }
}
}
}Copilot in VS Code
In .vscode/mcp.json. It asks for the token when it starts the server, so the file never holds it:
{
"inputs": [
{ "type": "promptString", "id": "rsync-ai-token", "description": "rsync.ai agent token", "password": true }
],
"servers": {
"rsync-ai": {
"type": "http",
"url": "https://rsync.example.com/api/agent/v1/mcp",
"headers": { "Authorization": "Bearer ${input:rsync-ai-token}" }
}
}
}Gemini CLI
In ~/.gemini/settings.json, reading the token from RSYNC_AGENT_TOKEN in your shell:
{
"mcpServers": {
"rsync-ai": {
"httpUrl": "https://rsync.example.com/api/agent/v1/mcp",
"headers": { "Authorization": "Bearer ${RSYNC_AGENT_TOKEN}" }
}
}
}Mistral Le Chat
Connectors → Add connector → Custom MCP, with the address above and API key / Bearer authentication. Le Chat keeps the token, so give it a short expiry.
Scopes and tools
Every token has metadata:read, which opens the read tools. Each write tool needs its own scope, and four of them also need your role to be owner or admin on every call. Demote the token's user and they stop working.
| Area | Scope | Role needed | Tools |
|---|---|---|---|
| Read | metadata:read | Any role | list_connections, describe_schema, list_pipelines, get_pipeline, get_pipeline_health, get_run_status, list_runs, diagnose_run, list_connectors, get_connector_generation, list_models, get_model, list_model_runs, list_model_checks, plan_model_checks, list_workflows, list_chart_sources, describe_chart_source, list_dashboards, get_dashboard, get_usage, read_guide |
| Pipelines | pipelines:plan | Member and above | plan_pipeline |
| Connectors | connectors:generate | Owner or admin | generate_connector |
| Models | models:write | Owner or admin | create_model, create_silver_model, schedule_model, run_model, pause_model_schedule, resume_model_schedule |
| Workflows | workflows:write | Owner or admin | plan_workflow, plan_workflow_change |
| Dashboards | dashboards:write | Owner or admin | plan_dashboard, plan_dashboard_change |
workflows:write and dashboards:write are granted when you create the token through the API (POST /api/v1/agent-tokens, as an owner or admin).What each write tool does
plan_pipelineproposes a pipeline. It creates nothing; a person creates it from the link it returns.generate_connectortakes a name and the https URL of a public API's OpenAPI document or docs page, and returns a run to poll. It adds the connector to the catalog but doesn't start it, and never takes credentials. Connector generation is part of rsync.ai Cloud.- The model tools create, schedule, run, pause and resume models. See Models.
plan_workflowandplan_workflow_changedraft a workflow or a change to its conditions. A person tests and turns it on.plan_dashboardandplan_dashboard_changedraft a dashboard or a one-tile change. An owner or admin saves or applies it.
Safety and audit
- One workspace. A token is bound to the workspace that was open when you made it.
- Checked on every call. Each call re-checks that the token is unrevoked and unexpired, that your account is active, and your role as it is at that moment.
- Never a platform admin, whatever your own account is.
- Not a session. The REST API rejects an agent token, and a token can't create or revoke tokens.
- 120 calls a minute per token. Past that the gateway answers 429 with a
Retry-Afterheader. - Every call is auditedas the token's user, with the tool, the outcome and the token's id.
- Text from your systems is treated as data. Names and error messages are capped, stripped of control characters, and the server tells the agent to treat them as data, not instructions. Error text has quoted values, hosts, emails and credentials masked.
The gateway calls no model of its own. For the in-app chat that uses the same tools, see Ask rsync.ai.
Ready to try it?
Start building on rsync.ai Cloud today — or self-host on your own infrastructure.