External connectors
Managing organization-wide remote MCP connectors like Canva, Linear, Atlassian Rovo, Notion, or Pipedrive, and how users authenticate.
Written By Kristė Vagnerytė
Last updated About 3 hours ago
Admin (Cowork) → External connectors
The External connectors tab manages the organization’s remote MCP connectors — managed MCP servers published to every Cowork user through the Cowork bootstrap process, such as Canva, Linear, Atlassian Rovo, Notion, or Pipedrive.
What External connectors is used for
Review every organization-level connector in one place
Enable/disable a connector for the whole organization
Add a new connector, or edit/remove an existing one
See how users authenticate and what tool-permission policy applies
The top of the page shows a summary (e.g. “5 enabled · 5 total”) and when connectors were last updated.

The connector card
Each connector is shown as its own card with:
Name and logo, a status badge (Enabled/Disabled), and the enable toggle on the right
A short description of what the connector allows (e.g. “Search, create, autofill, and export Canva designs.”)
A protocol tag – e.g.
httpAn authentication tag – e.g.
OAuth · CIMD(Client ID Metadata Document) orOAuth · DCR(Dynamic Client Registration)A tools policy –
Tools: ask(each tool call needs user approval) orTools: allow(allowed automatically)The MCP server URL, e.g.
https://mcp.canva.com/mcpEdit and Delete buttons
Adding a new connector
The + Add connector button in the top-right opens the Add custom MCP connector form:
Enabled – whether the connector is active; disabled connectors stay saved but are omitted from the bootstrap
MCP server URL – the connector’s remote MCP endpoint (e.g.
https://mcp.example.com/mcp); Analyze URL reads the server’s public metadata to suggest the right authentication method. Analysis is read-only and does not register an OAuth clientName – a unique bootstrap identifier for the connector, with no spaces (e.g.
github)Transport – the connection protocol, e.g. Streamable HTTP
Description – what the connector provides and who owns it
Default tool approval – the tools policy applied to the connector, e.g. Ask before each tool call
Authentication – the sign-in method used, e.g. No authentication. The detected recommendation can be overridden for legacy or non-standard servers
Editing and removing a connector
Edit – change the connector’s settings (name, URL, authentication, tools policy)
Delete – permanently removes the connector from the organization’s list
The toggle at the top of the card quickly enables or disables the connector without removing its configuration
Refresh updates the list if changes were made elsewhere.
Who can use External connectors
External connectors is only available to admins through the Admin (Cowork) panel. Even when a connector is enabled organization-wide, each user still has to authenticate individually with that service before they can use it.