By default, a tool on an MCP server uses the connection configured by the administrator, so every end user shares the administrator's credentials and permissions in the downstream application. You can require end users to provide their own credentials instead, so the Tool accesses the downstream application using the end user's identity and permissions.
Important: This requires the MCP server to use Celigo as the identity provider. If the server uses an external identity provider, it can't prompt end users to set up their own connections. See Set up authentication for an MCP server.
This article covers turning on end user authentication for a connection you've already attached to a tool.
Prerequisites
- The MCP server uses Celigo as the identity provider
- The connection is already attached to at least one tool on the MCP server
Configure end user authentication
You can configure end-user authentication for an individual Tool or for a connection at the MCP server level. The two options behave differently:
- Tool level: Applies only to the selected tool. Other tools that use the same connection continue to use the administrator configured connection unless you configure end-user authentication for them separately.
- Server level: Applies to all tools on the MCP server that use the connection. You don't need to configure end-user authentication for each Tool separately.
Configure end user authentication for a tool
Use this option when you want only a specific tool to use the end user's credentials.
- Go to AI studio > MCP servers, and select the MCP server.
-
In Capabilities, locate the tool you want to configure.
Note: Configure connection appears only for tools that use a connection.
-
Select the gear icon to open the authentication settings for the connection.
Note: Celigo automatically displays the connection already configured for the Tool. The connection appears even if it's currently offline.
- Select Edit auth for the specific connection to turn on End user authentication.
- Enable the End user authentication and then under Select fields, choose the authentication fields the end user must provide. You can pick a custom subset or select all. You can edit your selection later.
- Select Save & close.
- An Auth enabled tag is displayed next to the connection name and the Edit auth is changed to Configure fields.
The Tool is now configured to use the end user's connection.
If another tool uses the same connection but isn't configured for end user authentication, that tool continues to use the administrator configured connection.
Configure end user authentication at server level
Use the Connections tab when you want every tool on the MCP server that uses a connection to require end user credentials.
- Go to AI studio > MCP servers, and select the MCP server.
- Select the Connections tab.
- Enable the End user auth for the required connection you want to configure.
- In the Actions column select Configure authentication.
- In End user authentication, under Select fields, choose the authentication fields the end user must provide. You can pick a custom subset or select all. You can edit your selection later.
- Select Save & close.
All Tools on the MCP server that use this connection now use the end user's configured credentials. You don't need to enable end user authentication separately for each tool.
For example, if tools A, B, and C all use the same connection, turning on end user authentication from the Connections tab applies to all three. If you turn it on only from Tool A's capability configuration, Tools B and C continue to use the administrator-configured connection.
After you save
Once you save, the connection shows an Auth enabled at server level badge next to the connection in the Configure tool, even if you selected only one field for end users to provide.
Configure an OAuth connection
Some connections authenticate through an external application instead of individual fields, OAuth 2.0 connections such as Salesforce or Google Drive, for example. When you open the authentication settings for one of these, the drawer shows "Nothing to configure for this connection," since there's no field to select.
When an end user configures one of these connections, they're redirected to the downstream application's sign in page to authenticate with their own credentials and authorize access.
View connections on the MCP server
The Connections tab lists the connections used by the MCP server's tools. The tab remains available even when the MCP server doesn't currently use any connections. In that case, Celigo displays an empty state message.
After end users configure their own credentials, you can view their connection here, including its status: online, offline, or expired, but not its credential values.
| Column | Description |
| Name | The connection name. Select the name to open and view the connection. |
| Status | The current connection status, such as Online or Offline. |
| Application | The application associated with the connection. |
| API | The API or endpoint configured for the connection. |
| Queue size | The number of requests currently waiting to be processed by the connection. |
| Last updated | The date and time the connection was last updated. |
| End user count | The number of end users who have configured their own credentials for this connection. |
| End user auth | Indicates whether end-user authentication is enabled or disabled for the connection. |
| Actions | Provides options to Edit the connection, View its audit logs, Used by, or Configure authentication. |
Important: Even for a tool that keeps using the administrator configured connection because end user authentication isn't turned on for it, you can still identify which end user made a given request. Check the request log for that connection to see request attribution by user.
Set up your connections as an MCP server end user
Some tools on an MCP server might require you to connect to a downstream application using your own credentials, instead of sharing the administrator's connection. An administrator turns this on for a specific connection, when they do, you're prompted to set up your own credentials the first time you use a tool that needs it. Your credentials are used when those tools access the downstream application on your behalf.
This article covers setting up, viewing, and disconnecting your own connections. For how to connect to the MCP server itself, see Connect to a Celigo MCP server as an end user.
Prerequisites
- An administrator must configure at least one tool you can access to use your own credentials. If none of your available tools require your credentials, you won't see the connection setup step.
Set up your connections
When you connect to an MCP server that has connections available for you to configure:
- From your MCP client, connect to the MCP server and sign in.
- On the Set up your connections page, review the available connections.
- Select a connection you want to configure.
- Complete the required authentication:
- If authentication fields are displayed, enter your credentials.
- If the connection uses OAuth, sign in to the downstream application with your credentials and authorize access.
- Repeat steps 3 to 4 for each additional connection you want to configure.
- Select Continue.
After you select Continue, you're redirected back to your MCP client to complete the connection.
You can configure all, some, or none of the available connections.
Important: You can continue without configuring a connection. However, if you later use a tool that requires an un-configured connection, the Tool returns an error. Tools that don't require that connection continue to work.
Reconnect to an MCP server
Connections you've already configured remain available when you reconnect to the MCP server. You don't need to configure them again.
If a connection requires you to authenticate again, follow the authentication prompts to restore access.
Authenticate with an external application
Some connections use an external authentication flow instead of asking you to enter credentials directly in Celigo.
When you configure one of these connections, you're redirected to the downstream application's sign-in page. Sign in with your own credentials and authorize access. After authentication, return to the connection setup flow and continue.
For example, a Salesforce or Google Drive connection can redirect you to the application's sign in page to complete authentication.
If a tool can't use your connection
If a tool returns a connection related error:
- Check whether you've configured the connection required by the tool.
- If the connection isn't configured, connect to the application using your own credentials.
- If you previously configured the connection but it requires authentication again, complete the authentication prompts.
- Retry the tool from your MCP client.
If the problem continues, contact your MCP server administrator.