All documentation

Documentation Settings: The room

Plugins: addresses, pinning and team limits

How a plugin by address is checked, why a server's tools are pinned at approval, and what a team can restrict.

A server by address

A plugin added by address rather than as a command is reached over HTTP. The Mac tries the current Streamable HTTP transport first and falls back to the older server-sent events transport when that is all the server speaks. Only http and https addresses are accepted.

Private network addresses are refused, because a server address is a door the lead's tools go through, and one that points back into your network could reach things it should not. There are two exceptions: localhost, which you only type on purpose, and a host your team names under Private hosts. Cloud metadata addresses are refused whatever any list says.

Tool pinning

What it is. When you add a server, the app records a fingerprint of every tool it offers: name, description and input schema. If the server later changes any of them, its tools are held back until you approve again.

Where to find it. Not a setting: it is always on, on the Mac, for every plugin. A team's allow-list does not switch it off.

What changes. On the next session after a change, an approval card says the server "changed its tools since you approved it" and names what was added, changed or removed, with a choice to allow the new definitions. Allowing records a new fingerprint. In a run nobody is watching, such as a schedule, a notice says so and the server's tools stay out of the room.

When it matters. A server that rewrites a tool's description after you approved it can try to steer the model, for example into forwarding a file or a token. Pinning turns that into a visible question instead of a silent change.

Settings → The room → Plugins on the Mac, one installed server with its rename its tools list open
Settings → The room → Plugins on the Mac, one installed server with its rename its tools list open

Long tool lists

A server can publish dozens of tools, and the list rides along on every turn. Past a modest size, the lead is given one search tool and the few tools this discussion has already used, and asks for the rest by name. Under that size nothing changes. An answer that does not match the output schema its own server publishes is not passed on; the lead is told which server answered wrongly.

What a team can restrict

Team owners and admins set these in Settings → Account → Governance; they are enforced on each member's Mac.

PolicyWhat it does
MCP servers members may runOne pattern per line, matched against a server's host or whole command, or a package name. Empty allows any
Or a registry file the team servesA file in the MCP registry format whose servers become the allow-list, fetched at start-up and daily; a server no longer listed is stopped
Private hosts members' Macs may reachExact host names or addresses on the company's own network that a server by address may use
Slow an MCP server pastA number of calls a minute to one server; past it the run waits rather than hammering a server the team shares
MCP servers held in the sandbox tooAmong the sandbox protections members cannot switch off

A server that does not match the allow-list cannot be added, and adding a server that announced itself goes through the same check.

Further reading. Model Context Protocol specification — MCP project. LLM06:2025 Excessive Agency — OWASP GenAI Security Project, 2025. Not what you've signed up for: indirect prompt injection — Greshake et al., 2023.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.