Skip to content
  • Everything in KeplarEvery feature and whether it is liveLive demoAsk a question now, no sign-upCreateDescribe or speak a site or appCreate showcaseDemos that set the barKeplar-OneThe engine behind every answerTeamsShared workspaces, roles and approvals
  • DocsHow everything worksAPI and widgetKeys, endpoints, embed scriptCommunity gallerySites people chose to shareChangelogWhat shipped, whenRoadmapWhat is next, what is not doneSecurityHow your data is protected
  • Pricing
  • Download
Sign InTry Keplar→
  • Product
  • Live demo
  • Create
  • Create showcase
  • Keplar-One
  • Teams
  • Resources
  • API and widget
  • Community gallery
  • Changelog
  • Roadmap
  • Security
  • Pricing
  • Download
Sign InTry Keplar→

One question. Multiple intelligences. One answer.

team@keplar.one

Product

  • Everything in Keplar
  • Overview
  • Live demo
  • How it works
  • Create
  • Create showcase
  • Community gallery
  • Keplar-One
  • Pricing
  • Download

Use Keplar

  • For you
  • For business
  • Agents
  • API and widget
  • Referral program
  • Create an account

Learn

  • AI answer engine
  • Compare AI models
  • AI study tool
  • AI slideshow maker
  • What is superintelligence?
  • Multi-model AI
  • Models we use
  • Guides
  • Docs
  • Blog
  • Changelog
  • Roadmap
  • Glossary
  • Prompt library

Company

  • About
  • Inquire
  • Help
  • Contact
  • Status

Legal

  • Privacy
  • Terms
  • Security

© 2026 Keplar One.

Theme
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do
Docs menu
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do

Docs/Connectors and agents

Add a connection

Connect an MCP server step by step, test it with a handshake, enable only the tools you want, and the address and credential rules that apply.

Updated October 3, 20261 min read

On this page
  1. Steps
  2. Address rules
  3. Testing your own server
  4. Credentials
  5. Removing a connection

Steps

  1. Open Business, then Connected apps, then Add a connection.
  2. Pick a listed connector, or enter your own server's address.
  3. Choose how it authenticates: none, a bearer token or API key, or OAuth (Beta).
  4. Save, then press Test. Keplar sends a real handshake and lists the tools the server offers.
  5. Enable only the tools you want. Each starts disabled. Mark read-only tools as read so they can be considered for auto-run; leave everything else on approval.
  6. Grant the tools to the places that may use them: Ask (chat) and specific agents, with daily call and monthly credit budgets.
  7. Try a read-only tool in a chat with Tools switched on, and check the receipt.

Address rules

  • HTTPS only in production.
  • No credentials or secrets in the URL's query string. Put keys in the credential field.
  • The hostname must resolve to public addresses. Loopback, private, link-local, shared, multicast, reserved and cloud metadata addresses are blocked, and the connection is pinned to the checked address so DNS cannot be swapped between check and use.
  • Redirects are followed manually (at most three) and every hop is checked again. Auth headers are dropped on cross-origin redirects.
  • Timeouts and response-size limits apply.

Testing your own server

If you build an MCP server, you can check it responds to an initialize request before you add it:

bash
curl -sS -X POST "https://your-server.example/mcp" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"curl-check","version":"0.0.1"}}}'

A working server answers with its name, version and capabilities. The older two-endpoint SSE transport is reported as unsupported.

Credentials

Tokens and API keys are encrypted at rest with a key derived per workspace, bound to the record so they cannot be moved between users, and never sent back to the browser (it only learns that a secret exists). In production, Keplar refuses to store a credential if the server's encryption secret is missing.

Removing a connection

Deleting a connection removes its tools, grants and stored secret. Account export and deletion include connected-app data.

Related

  • Connected apps (MCP) overview: Connect remote Model Context Protocol servers so Keplar and its agents can use outside tools, with per-tool permissions, approvals and plan limits.
  • Tool permissions and approvals: Read versus write tools, grants, auto-run rules, approval cards, schema-change locks and how scheduled runs always ask first.
  • Connected app security: How Keplar defends against server-side request forgery, prompt injection through tool output, secret leaks and silent tool changes when you connect MCP servers.
PreviousConnected apps (MCP) overviewNextConnect with OAuth (Beta)

Questions this page does not answer? Write to team@keplar.one, or try Keplar on your own question.

Try Keplar freeOpen Keplar→

On this page

  1. Steps
  2. Address rules
  3. Testing your own server
  4. Credentials
  5. Removing a connection