Skip to content

Agent Connectivity

Agent Connectivity lets an external AI client use Runnit with your permissions in an organisation you choose.

You need an active Runnit account, current Terms acceptance and permission to connect MCP clients in that organisation. You can’t connect an app while impersonating another user. An organisation policy that blocks delegated MCP credentials can also prevent connection.

Use this option when your client supports OAuth for remote MCP servers.

  1. Open Settings > Agent Connectivity in Runnit and copy the Connection URL for your current environment.
  2. Add that URL as a remote MCP server in your client and choose its OAuth connection option.
  3. Sign in to Runnit when the client opens your browser. Accept the current Terms if prompted.
  4. Review the app name and return address. The name is supplied by the client and isn’t verified by Runnit. A local return address sends the connection code to an app on your computer.
  5. Choose the Organisation the app should use, then select Allow connection. Select Cancel to refuse access.

The browser returns to your client. The app can read and change data using your current permissions in the selected organisation. It refreshes its connection automatically for up to 90 days, after which you need to connect again.

  1. Open Settings > Agent Connectivity and select the relevant organisation.
  2. Find the app under Connected apps. Check its expiry and last-used time.
  3. Select Revoke access.

Revocation takes effect immediately for future requests and prevents the app from refreshing the connection. To use it again, start a new connection in the client and approve it in Runnit.

Signing out of Runnit in your browser doesn’t disconnect an approved app. Use Revoke access to end its connection.

For clients that ask for a pasted token, use Generate a user token on the same page. Check the organisation and connection URL, choose a token lifetime, generate the token, then copy the setup command for your client. Treat the token as a password. Commands appear only after a real token has been generated.

OAuth connections and manual tokens are separate. Revoking a connected app doesn’t revoke a manual token you gave that client earlier.

  • Check that the URL belongs to the workspace you signed in to. A connection issued for one hostname doesn’t transfer to another.
  • If your workspace moves to another deployment, connect your clients again using the destination workspace’s URL.
  • If no organisation is available on the consent page, ask an administrator to check your MCP connection permission and organisation policy.
  • If access was revoked, expired, or refused after a credential was reused, reconnect from the client. Don’t retry an old connection code.
  • If your Terms acceptance is out of date, sign in and accept the current version before retrying.

For client configuration and protocol details, see the MCP server reference. To let Ru use another system, see Agent Integrations.