> ## Documentation Index
> Fetch the complete documentation index at: https://trytilde.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage tools

> Connect tool accounts, add MCP servers and Tilde tool servers, and choose which tools each agent can use.

You manage tools in two places. The **Tools** section holds the accounts and servers your installation can use. Each agent's **Tools** tab then picks which of them that agent uses.

## Connect a managed tool

<Steps>
  <Step title="Open the catalog">
    In **Tools**, select **Connections**, then **Tilde Catalog**. Filter by category, or search for a tool.
  </Step>

  <Step title="Review the provider">
    Select a provider. Tilde shows the authentication methods it supports and the tools it offers.
  </Step>

  <Step title="Add an account">
    Select **Add account**, and choose an authentication method if there are several. Enter the credential, or complete the provider's OAuth flow.
  </Step>
</Steps>

Tilde encrypts the credential, and OAuth tokens [rotate automatically](/docs/connections#automatic-token-rotation).

### Sign in with Tilde's OAuth app <span className="cloud-tag">CLOUD</span>

For Google, GitHub, and Sentry, Tilde Cloud can sign you in with Tilde's own OAuth app, so you do not need to register one. In Tilde OSS and Tilde Enterprise, you register your own OAuth app with the provider, and enter its client ID and secret during setup.

## Add an MCP server

In **Tools**, select **Connections**, then **Add MCP server**.

* **Choose existing** connects another account to a server that is already registered.
* **Create new** registers a new server by URL. Only administrators can do this, because it adds a provider to the installation.

When you create a server, choose how Tilde authenticates to it:

| Method | How Tilde sends the credential |
| - | - |
| **No authentication** | No credential. |
| **Sign in with OAuth** | An OAuth access token. Tilde discovers the server's authorization server, and registers a client for itself. |
| **Bearer token** | An `Authorization: Bearer` header. |
| **API key header** | A header you name, with an optional value prefix. |
| **API key query parameter** | A query parameter you name. |

Tilde dials every URL an MCP server supplies over HTTPS, to public addresses only.

MCP servers you add appear under **Tools** > **Remote servers**, with 12 hours of health history. Tilde does not rediscover a server's tools in the background. Select **Refresh tools** on the connection after the server changes.

## Add a Tilde tool server

In **Tools**, select **Connections**, then **Add Tilde tool server**, and choose how it runs.

<Tabs>
  <Tab title="Self-hosted">
    Name the server, and select **Add server**. Tilde shows a token once. Set it as `TILDE_TOOL_HOST_TOKEN` on your tool server, then start it. The server dials out, and publishes its tools.

    Rotate the token from the server's page. A server that stays silent for 30 seconds stops being offered to agents.
  </Tab>

  <Tab title="AWS Lambda">
    Name the server, enter its **Function ARN**, and select **Add server**. The gateway invokes the function with its own AWS credentials, and asks it for its tools. Select **Refresh tools** after you deploy a new version.
  </Tab>
</Tabs>

If the tool server declares its own sign-in, select **Add instance** on its page for each account. Tool servers sign in with your own OAuth client, over HTTPS.

## Choose an agent's tools

Open the agent in the Agent Registry, and select **Tools**.

<Steps>
  <Step title="Add a tool source">
    Select **Add tool**. **Choose existing** adds a connection or tool server that you can view. **Connect a new tool** opens the catalog. A new source's tools start switched off.
  </Step>

  <Step title="Switch tools on">
    Switch on each tool the agent should use in the **Use** column.
  </Step>

  <Step title="Set how each call appears">
    In **Displayed**, choose **Full**, **Summary**, or **Hidden**. This controls how the call appears in the session. Switch on **Background** for long-running tools.
  </Step>

  <Step title="Choose a discovery mode">
    Select **Listed directly** or **Found by search**. See [Tool discovery](/docs/tools/overview#tool-discovery).
  </Step>
</Steps>

You can edit a tool's summary and description for one agent. Tilde marks the tool as edited, and leaves other agents unchanged.

Bundled tools appear in a read-only **From code** group. The list comes from the serving deployment. The agent's **Deployment** tab lists the tools each deployment declared.

Each connection's page lists the agents that use it under **Used by**.

## Who can manage tools <span className="cloud-tag">CLOUD</span><span className="enterprise-tag">ENTERPRISE</span>

Tilde Cloud and Tilde Enterprise control tool management with [operator roles](/docs/operator-access).

| Action | Needs |
| - | - |
| Add a tool source to an agent | `edit_tools` on the agent, and `view` on the connection or tool server. |
| Remove a tool source, pick tools, or set the mode | `edit_tools` on the agent. |
| Change, share, or delete a connection or tool server | `edit` or `share` on it. Rotating a tool server token counts as an edit. |
| Register an MCP server by URL | Administrator. |

The person who creates a connection or tool server becomes its editor.
