MCP automation connections
What this page covers
Section titled “What this page covers”The backend serves streamable HTTP at POST /api/v1/mcp. A host that supports it connects directly with an expiring agent token. A stdio-only host installs the adapter from the public custodexa-mcp project. The server ships with the product; the adapter forwards calls.
How to set it up
Section titled “How to set it up”- Create an identity, owner, and expiring token under AI agent accounts and tokens.
- Configure the token in the host. Point an HTTP host at
/api/v1/mcp; install the adapter from the publiccustodexa-mcpproject for a stdio host and point it at the same service. - Use
list_assetsfor visible assets,request_accessfor per-asset account scopes and a reason, andcheck_requestfor the decision. Connect only with approved task items. - Pass an explicit task ID to
open_session, use tools appropriate to the asset, then callclose_sessionand submit a report withclose_task.
For a stdio host, run go install github.com/custodexa/custodexa-mcp@latest. Set CUSTODEXA_MCP_URL to the HTTPS /api/v1/mcp endpoint and supply the token through CUSTODEXA_AGENT_TOKEN. Keep the token out of command arguments and task reports.
The ten tools are list_assets, request_access, check_request, open_session, run_command, send_keys, query, read_screen, close_session, and close_task. run_command serves SSH and container terminals, query serves database queries, and read_screen and send_keys interact with managed screens. When a tool reports an uncertain outcome, inspect the task, session, and ledger before proceeding.


What auditors can see
Section titled “What auditors can see”Calls attributable to a task, and tools allowed before a task exists, put their decisions and results in the tool call ledger. Calls rejected at entry because a task or session ID is missing or cannot be attributed are recorded in MCP HTTP request audit; a denied open_session also has a connection denial record. Sensitive content is masked before output is returned to the agent. The recording preserves the original screen and is the source of truth for text sessions; input without echo leaves no command-text record. The structured query statement record is the source of truth for that query.