Skip to main content
Connect

Agent gateway (MCP)

rsync.ai runs an MCP server. An AI agent that speaks MCP over HTTP can read your workspace's pipelines, runs, schemas and models, ask why a run failed, and draft pipelines, workflows and dashboards for you to review.

What an agent can and can't do

  • It reads metadata, never data. No row values, sample rows, query results, row counts, connection settings or credentials are ever returned.
  • It writes only through a scope. A token can add a connector, build and schedule models, and propose a pipeline, workflow or dashboard. A person checks and turns on anything it proposes.
  • It never runs, edits or deletes a pipeline or a connection.
  • It acts as you. Every tool runs through the same handlers as the UI, so an agent sees what you see in that workspace and nothing more.

Make a token

In Settings → AI apps, under Connect your AI app:

  1. Name the token after where it will live, such as “Claude Code on my laptop”.
  2. Pick when it expires: 30 days, 90 days or 1 year. Every token expires.
  3. Tick only what the agent should do besides read.
  4. Select Create token. It's shown once; rsync.ai keeps only its hash.

A token starts with rsat_. You can hold 20 live tokens in each workspace, and you revoke one in the same place. An agent using a revoked token gets a 401 on its next call.

If Settings has no AI apps tab, the gateway is off. Self-hosted installs ship with it off; set RSYNC_AGENT_GATEWAY_ENABLED=true on the api-gateway service and restart it.

Connect an agent

Settings shows the exact address for your deployment: your API address followed by /api/agent/v1/mcp. With https://rsync.example.com as that address:

Claude Code

claude mcp add --transport http rsync-ai https://rsync.example.com/api/agent/v1/mcp \
  --header "Authorization: Bearer rsat_..."

Cursor

In .cursor/mcp.json:

{
  "mcpServers": {
    "rsync-ai": {
      "url": "https://rsync.example.com/api/agent/v1/mcp",
      "headers": { "Authorization": "Bearer rsat_..." }
    }
  }
}

Copilot in VS Code

In .vscode/mcp.json. It asks for the token when it starts the server, so the file never holds it:

{
  "inputs": [
    { "type": "promptString", "id": "rsync-ai-token", "description": "rsync.ai agent token", "password": true }
  ],
  "servers": {
    "rsync-ai": {
      "type": "http",
      "url": "https://rsync.example.com/api/agent/v1/mcp",
      "headers": { "Authorization": "Bearer ${input:rsync-ai-token}" }
    }
  }
}

Gemini CLI

In ~/.gemini/settings.json, reading the token from RSYNC_AGENT_TOKEN in your shell:

{
  "mcpServers": {
    "rsync-ai": {
      "httpUrl": "https://rsync.example.com/api/agent/v1/mcp",
      "headers": { "Authorization": "Bearer ${RSYNC_AGENT_TOKEN}" }
    }
  }
}

Mistral Le Chat

Connectors → Add connector → Custom MCP, with the address above and API key / Bearer authentication. Le Chat keeps the token, so give it a short expiry.

The Claude Code and Cursor configs hold the token in plain text. Keep them in a user-level config, never in a file you commit, and revoke the token if it leaks. Clients that connect only through OAuth, such as the claude.ai and ChatGPT web connectors, can't use the gateway: it accepts agent tokens only.

Scopes and tools

Every token has metadata:read, which opens the read tools. Each write tool needs its own scope, and four of them also need your role to be owner or admin on every call. Demote the token's user and they stop working.

AreaScopeRole neededTools
Readmetadata:readAny rolelist_connections, describe_schema, list_pipelines, get_pipeline, get_pipeline_health, get_run_status, list_runs, diagnose_run, list_connectors, get_connector_generation, list_models, get_model, list_model_runs, list_model_checks, plan_model_checks, list_workflows, list_chart_sources, describe_chart_source, list_dashboards, get_dashboard, get_usage, read_guide
Pipelinespipelines:planMember and aboveplan_pipeline
Connectorsconnectors:generateOwner or admingenerate_connector
Modelsmodels:writeOwner or admincreate_model, create_silver_model, schedule_model, run_model, pause_model_schedule, resume_model_schedule
Workflowsworkflows:writeOwner or adminplan_workflow, plan_workflow_change
Dashboardsdashboards:writeOwner or adminplan_dashboard, plan_dashboard_change
The Connect your AI app screen offers the pipeline, connector and model scopes. workflows:write and dashboards:write are granted when you create the token through the API (POST /api/v1/agent-tokens, as an owner or admin).

What each write tool does

  • plan_pipeline proposes a pipeline. It creates nothing; a person creates it from the link it returns.
  • generate_connectortakes a name and the https URL of a public API's OpenAPI document or docs page, and returns a run to poll. It adds the connector to the catalog but doesn't start it, and never takes credentials. Connector generation is part of rsync.ai Cloud.
  • The model tools create, schedule, run, pause and resume models. See Models.
  • plan_workflow and plan_workflow_change draft a workflow or a change to its conditions. A person tests and turns it on.
  • plan_dashboard and plan_dashboard_change draft a dashboard or a one-tile change. An owner or admin saves or applies it.

Safety and audit

  • One workspace. A token is bound to the workspace that was open when you made it.
  • Checked on every call. Each call re-checks that the token is unrevoked and unexpired, that your account is active, and your role as it is at that moment.
  • Never a platform admin, whatever your own account is.
  • Not a session. The REST API rejects an agent token, and a token can't create or revoke tokens.
  • 120 calls a minute per token. Past that the gateway answers 429 with a Retry-After header.
  • Every call is auditedas the token's user, with the tool, the outcome and the token's id.
  • Text from your systems is treated as data. Names and error messages are capped, stripped of control characters, and the server tells the agent to treat them as data, not instructions. Error text has quoted values, hosts, emails and credentials masked.

The gateway calls no model of its own. For the in-app chat that uses the same tools, see Ask rsync.ai.

Ready to try it?

Start building on rsync.ai Cloud today — or self-host on your own infrastructure.

Start free