MCP sources
MCP sources give Qubit extra tools from StackJack, HaloPSA's own MCP endpoint or any compatible server, and each person connects their own account where a source asks for one.
Written By Chris Scaminaci
Last updated About 2 hours ago
An MCP source is a connection to a tool server that gives Qubit extra tools. StackJack, HaloPSA's own MCP endpoint and any other compatible server work the same way: you add the source once, and Qubit can then call its tools while it answers you. Every call is checked by Tool Governance and recorded in its audit list.
Open MCP Sources in the sidebar, under Configuration. The page is titled MCP sources. Every signed-in user can open it, and what you can do there depends on your role.
Before you start: a source that asks each person to sign in needs your own sign-in identity to be known in the current session. If the page says it could not be determined, sign out and sign in again. Those sign-ins also need the server's public address to be set up; if a source shows Unavailable, contact TechPulse.
Add a source
- Choose Add source. The New MCP source card opens.
- Under Connection, fill in the fields in the table below.
- Choose the Scope and the Authentication method.
- Under Tool policy, optionally limit which tools Qubit may use.
- Choose Save. The page confirms with a note such as "Saved" followed by the source name.
A new source starts with the scope Tenant: everyone shares one credential for an Administrator. For everyone else it starts with Only me (a personal source), which is the only scope they can choose.
Choose the scope
The scope decides who sees the source and whose account the server sees.
Use Per user for any server that decides what a caller may do from the caller's identity. StackJack is one. A per-user source always uses OAuth sign-in, so the Authentication field switches to it and cannot be changed.
A tenant source that uses OAuth sign-in stores a single sign-in for everybody. Whoever presses Connect is the identity the server sees for every user, and the table marks the row one shared sign-in. Choose Per user instead when the server should know who is asking.
Changing a source's endpoint, its authentication method, its client ID or its scope signs everybody out of it. The page tells you how many sign-ins it removed, and each person presses Connect again. Changing the name, the OAuth scopes, a secret or the tool filters keeps the sign-ins.
Allow and deny tools
Allowed tools and Denied tools take comma-separated patterns, for example halo_*. A * stands for any run of characters. The patterns are matched against each tool's own name on the server.
- If Allowed tools is blank, every tool is allowed.
- A tool that matches Denied tools is never offered, even when it also matches Allowed tools.
These filters decide which tools Qubit is shown. Tool Governance decides which of those it may run, and whether a person must approve each call.
Connect to a source
A source that signs each person in appears under My connections, which lists the per-user sources your Administrator added and your own personal sources. Each row shows the Source, its Kind (Per user (from your administrator) or Personal) and Your status.
- Press Connect on the row. The server's own sign-in page opens in a new tab.
- Sign in there with your own account. A short page says Connected and you can close the tab.
- Return to this page and press Test. The row shows how many tools your account gets and how long the call took.
Your status can read:
Press Disconnect to remove your own sign-in. It never affects anyone else's. You can reconnect at any time.
Per-user sources and OAuth sign-ins are switched off for a session whose sign-in identity could not be determined. A banner at the top of the page says so; sign out and back in.
Review the sources and test them
Configured sources lists every source you can see. For each one it shows the endpoint, the scope (Per user, Tenant (shared) or Personal), the authentication method and a status: Connected, Connected (you) (a per-user source you have connected), Not connected, Not connected for you (a per-user source you have not connected) or Disabled. A small line under the status shows the last connection result, how many tools were found and the state of the sign-in.
- Test connects to the source and reports how many tools it returned and how long it took. If the source needs a sign-in, the page tells you to press Connect.
- Tools opens Tools exposed by the source. The Exposed name column is the name Qubit uses: your alias, two underscores, then the tool's own name (Original). Hints marks tools the server flags as Read-only or Destructive.
- Connect and Disconnect appear on sources that use OAuth sign-in, and Disconnect only once you are connected. On a tenant source only an Administrator sees them.
- The pencil edits a source and the bin deletes it. Deleting asks you to confirm and removes the stored credentials and sign-ins. You can edit and delete your own personal sources. An Administrator manages tenant and per-user sources.
If Tools shows no tools, check the allow and deny patterns and the connection.
A failed test shows a general failure message rather than the server's reply. Check the address, the credentials and the filters, then contact TechPulse if it persists.
Addresses Qubit will not connect to
QuantumOps refuses endpoints it should not reach:
- Local addresses such as
localhost, addresses of the machine itself and link-local addresses are always refused. - Addresses on a private network are refused as well, unless TechPulse has allowed them for your instance.
- Your HaloPSA's own MCP address is exempt, because QuantumOps builds it from your HaloPSA address. See HaloPSA's native MCP source.
When an address is refused, the page tells you to use a publicly routable endpoint.
Add StackJack or HaloPSA's native MCP
Two cards above the source list set up the common sources without the editor. They are for Administrators; other users see a Not configured note for the HaloPSA card until an Administrator sets it up.
- StackJack for this tenant: each person signs in adds StackJack as a per-user source. See StackJack.
- HaloPSA native MCP for this tenant registers your HaloPSA instance's own MCP endpoint. See HaloPSA's native MCP source.
Where sources are used
- Qubit chat uses the enabled sources you can see, with your own sign-in where a source needs one. See What Qubit can use: tools and sources.
- The Slack and Teams assistant uses the sources an Administrator allows for it, which is every source unless the list is limited. A personal source works there too, for its owner once linked with a code, while the list is not limited. See Channel Assistant settings.
- Agent Runners can use only tenant sources that do not need a person to sign in. A per-user source, or a source that uses OAuth sign-in, is never offered to a runner.
Messages you may see
The wording on screen can differ slightly from the messages below.
Related pages
- Tool Governance: allow, approve or deny the tools these sources provide.
- StackJack: the recommended per-user setup for StackJack.
- HaloPSA's native MCP source: the HaloPSA endpoint, one sign-in per technician.
- What Qubit can use: tools and sources: how Qubit decides which tools to use.
- Channel Assistant settings: which sources the Slack and Teams assistant may use.
Was this helpful?
Still need help? Ask the team