External connectors

Managing organization-wide remote MCP connectors like Canva, Linear, Atlassian Rovo, Notion, or Pipedrive, and how users authenticate.

Written By Kristė Vagnerytė

Last updated About 1 hour ago

Admin (Cowork) → External connectors

The External connectors tab manages the organization’s remote MCP connectors — managed MCP servers published to every Cowork user through the Cowork bootstrap process, such as Canva, Linear, Atlassian Rovo, Notion, or Pipedrive.

What External connectors is used for

  • Review every organization-level connector in one place

  • Enable/disable a connector for the whole organization

  • Add a new connector, or edit/remove an existing one

  • See how users authenticate and what tool-permission policy applies

The top of the page shows a summary (e.g. “5 enabled · 5 total”) and when connectors were last updated.

The connector card

Each connector is shown as its own card with:

  • Name and logo, a status badge (Enabled/Disabled), and the enable toggle on the right

  • A short description of what the connector allows (e.g. “Search, create, autofill, and export Canva designs.”)

  • A protocol tag – e.g. http

  • An authentication tag – e.g. OAuth · CIMD (Client ID Metadata Document) or OAuth · DCR (Dynamic Client Registration)

  • A tools policyTools: ask (each tool call needs user approval) or Tools: allow (allowed automatically)

  • The MCP server URL, e.g. https://mcp.canva.com/mcp

  • Edit and Delete buttons

Adding a new connector

The + Add connector button in the top-right opens the Add custom MCP connector form:

  • Enabled – whether the connector is active; disabled connectors stay saved but are omitted from the bootstrap

  • MCP server URL – the connector’s remote MCP endpoint (e.g. https://mcp.example.com/mcp); Analyze URL reads the server’s public metadata to suggest the right authentication method. Analysis is read-only and does not register an OAuth client

  • Name – a unique bootstrap identifier for the connector, with no spaces (e.g. github)

  • Transport – the connection protocol, e.g. Streamable HTTP

  • Description – what the connector provides and who owns it

  • Default tool approval – the tools policy applied to the connector, e.g. Ask before each tool call

  • Authentication – the sign-in method used, e.g. No authentication. The detected recommendation can be overridden for legacy or non-standard servers

Editing and removing a connector

  • Edit – change the connector’s settings (name, URL, authentication, tools policy)

  • Delete – permanently removes the connector from the organization’s list

  • The toggle at the top of the card quickly enables or disables the connector without removing its configuration

Refresh updates the list if changes were made elsewhere.

Who can use External connectors

External connectors is only available to admins through the Admin (Cowork) panel. Even when a connector is enabled organization-wide, each user still has to authenticate individually with that service before they can use it.

What to read next