From a2583fcc979851689a5160ce97d9a3b59a5ec0c9 Mon Sep 17 00:00:00 2001 From: Walker Lockard Date: Thu, 17 Sep 2026 15:19:20 -0700 Subject: [PATCH] docs: align setup guides with current Control Plane UI --- doctrine/CHANGELOG.md | 22 +++ doctrine/speakeasy-setup.md | 189 ++++++++++++---------- guides/asana/speakeasy.md | 59 +++++-- guides/atlassian/speakeasy.md | 53 +++--- guides/box/speakeasy.md | 51 +++--- guides/github/speakeasy.md | 41 +++-- guides/gmail/speakeasy.md | 78 +++++++-- guides/google-big-query/speakeasy.md | 76 +++++++-- guides/google-calendar/speakeasy.md | 86 +++++++--- guides/google-compute-engine/speakeasy.md | 81 ++++++++-- guides/google-docs/speakeasy.md | 77 +++++++-- guides/google-drive/speakeasy.md | 77 +++++++-- guides/google-people/speakeasy.md | 86 +++++++--- guides/google-sheets/speakeasy.md | 77 +++++++-- guides/google-slides/speakeasy.md | 77 +++++++-- guides/hubspot/speakeasy.md | 48 ++++-- guides/intercom/speakeasy.md | 53 +++--- guides/netsuite/speakeasy.md | 44 +++-- guides/salesforce/speakeasy.md | 49 ++++-- guides/snowflake/speakeasy.md | 46 ++++-- guides/x-docs/speakeasy.md | 10 +- guides/x/speakeasy.md | 10 +- guides/zapier/speakeasy.md | 79 ++++++--- 23 files changed, 1074 insertions(+), 395 deletions(-) diff --git a/doctrine/CHANGELOG.md b/doctrine/CHANGELOG.md index d8ffee5..8e74776 100644 --- a/doctrine/CHANGELOG.md +++ b/doctrine/CHANGELOG.md @@ -6,6 +6,28 @@ evidence (Run Records / Retro Notes) behind it. Required by constitution invariant I8; written by `/tune-pipeline` when a human approves a proposal, or by hand for direct human edits. +## 2026-09-17 — align in-app setup steps with current Control Plane UI + +Files: `doctrine/speakeasy-setup.md`, `guides/*/speakeasy.md`, +`go/generated/**`. + +Evidence: the human reported that **Configure Manually** was absent in +their setup experience and approved the concrete correction scope and +copy in this conversation. Source audit against `speakeasy-api/gram` +main `8fa18729608e34de305e789b53f36eb2c6c853c9` found state-dependent +authentication controls and stale navigation/creation instructions. + +- Use MCP Gateway → MCP → Add new; distinguish catalog installation's + Configure MCP settings action from custom-remote Verify connectivity → Save. +- Handle configured authentication, existing providers/clients, and new + issuer setup explicitly; do not globally replace Configure Manually. +- Treat discovery as automatic when seeded; check the redirect URI before + attachment closes the sheet. Preserve provider-specific credentials. +- Refresh the authored guides and regenerate their embedded copies. + +Verification is source-level plus repository validation; this entry does +not claim a production-browser walkthrough. I8: human-approved correction. + ## Bounded decision evidence file transport Files: `factory/prompts/{endpoint,reconcile,finalize-research}.md`. diff --git a/doctrine/speakeasy-setup.md b/doctrine/speakeasy-setup.md index 3d34795..d910c23 100644 --- a/doctrine/speakeasy-setup.md +++ b/doctrine/speakeasy-setup.md @@ -12,18 +12,19 @@ Consumers may omit this file when Speakeasy setup is already in context `external.md`). UI facts below are drawn from the product source -(`speakeasy-api/gram`, `client/dashboard`, branch `main`): add-server and -Manual OAuth / Upstream Headers labels from commit `96f7f73` (observed -2026-07-23); Dynamic Client Registration (DCR) attach-sheet labels from -commit `f1d60da` (observed 2026-07-27). Labels are verbatim code-level -strings; a rendered-UI spot check on first use is still worthwhile. No -role may invent a label this file does not carry. +(`speakeasy-api/gram`, `client/dashboard`, branch `main`), commit +`8fa18729608e34de305e789b53f36eb2c6c853c9` (observed 2026-09-17). +Navigation and creation: `pages/mcp/MCP.tsx`, `pages/mcp/add/AddMcpServer.tsx`, +`pages/sources/remote-mcp/CreateRemoteMcp.tsx`, and `pages/catalog/`. +Authentication: `pages/mcp/x/tabs/settings/sections/authentication/`. +Labels are code-level strings; a rendered-UI spot check is still worthwhile. +Controls depend on configuration state and write permission. No role may +invent a label this file does not carry. ## Per-guide values (recorded in the Dossier's Speakeasy setup section) -- `` — from `meta.yaml` `remotes`. (The Control Plane - proxies remote servers over streamable-http; the add form's - **Transport** field is read-only.) Mark each remote +- `` — from `meta.yaml` `remotes`. The Control Plane + proxies remote servers over streamable-http. Mark each remote `tenanted: true` when the reader must paste a region, instance, or org-specific URL rather than a single shared public endpoint. When the URL is shared but the guide must still skip the catalog (unreliable @@ -34,9 +35,12 @@ role may invent a label this file does not carry. `custom-remote`. - The Authentication Option the guide documents, which External-setup step produced each credential field, and — for OAuth options — any - scopes the provider requires. For DCR, also record the **Issuer URL** - (often the remote origin) when the Control Plane cannot discover it - from protected-resource metadata alone. + scopes the provider requires. For every OAuth option, record the + **Issuer URL**, discovery support, and documented authorization/token + endpoints when discovery is unavailable; DCR also needs a registration + endpoint. Do not assume the remote MCP URL is the OAuth issuer. Missing + provider-specific issuer/endpoint evidence is an open question, not a + value the Writer may invent. - `` — the provider's primary MCP documentation page, for the closing pointer. @@ -52,7 +56,7 @@ override applies. - `custom-remote` → Custom remote only - `catalog` → catalog only - `auto` / omitted → Pulse catalog presence in operator notes: - - **present** → catalog (3rd-party server) only + - **present** → catalog (**From the catalog**) only - **absent** → Custom remote only - **ambiguous** / **skipped** / no lookup → both bullets + soft catalog-presence open question @@ -70,91 +74,112 @@ when presence is known. ### Add the server in Speakeasy {#add-server-in-speakeasy} -In the Speakeasy AI Control Plane sidebar, under **Connect**, select -**Sources**, then click **Add Source**. +In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select +**MCP**, then click **Add new** to open **Add MCP server**. **Catalog path** (Pulse **present** with `auto`, or `speakeasy_add_server: catalog`; never when tenanted or -`custom-remote`): choose **3rd-party server**. On the **MCP Catalog** -page, find (the search box reads **Search MCP servers...**), -open its entry with **View**, and click **Add**. In the **Add to -Project** dialog, click **Add to Project**. +`custom-remote`): choose **From the catalog**. On the **MCP Catalog** +page, find using **Search MCP servers...**, open its catalog +entry, and click **Add**. In the **Add to Project** dialog, click +**Add to Project**. Wait for installation to complete, then click +**Configure MCP settings** to open the created server. **Custom remote path** (tenanted, `speakeasy_add_server: custom-remote`, -or Pulse **absent**): choose **Custom remote server**. On the **Add a -custom remote MCP server** page, paste `` into **Remote MCP -server URL** and click **Add server**. +or Pulse **absent**): choose **Hosted remotely**. On **New remote MCP +server**, paste `` into **MCP server URL**. Optionally enter +**Display name (optional)**. Click **Verify connectivity**, then, after +verification succeeds, click **Save**. This creates the hosted MCP server +and opens its **Overview** page. **Dual conditional** (Pulse **ambiguous** / **skipped** only, `auto`, and not tenanted / not forced) — keep both as bullets: -- If is in the catalog: choose **3rd-party server**. On the - **MCP Catalog** page, find (the search box reads - **Search MCP servers...**), open its entry with **View**, and click - **Add**. In the **Add to Project** dialog, click **Add to Project**. -- If it is not: choose **Custom remote server**. On the - **Add a custom remote MCP server** page, paste `` into - **Remote MCP server URL** and click **Add server**. +- If is in the catalog: choose **From the catalog**. Find + using **Search MCP servers...**, open its catalog entry, + and click **Add**. In **Add to Project**, click **Add to Project**. + After installation, click **Configure MCP settings**. +- If it is not: choose **Hosted remotely**. On **New remote MCP server**, + paste `` into **MCP server URL**. Click **Verify + connectivity**, then **Save** after verification succeeds. This opens + the server's **Overview** page. -Either resolved path (or either dual branch) creates the hosted MCP -server and opens its **Overview** page. When only one path is emitted, -close with: This creates the hosted MCP server and opens its -**Overview** page. +Do not describe catalog installation as automatically opening Overview. - + ### Connect your credentials {#connect-speakeasy-credentials} -From the server's **Overview**, open **Settings**. The Writer renders -only the variant matching the guide's Authentication Option, names the -guide's actual fields, and cross-links each value to the External-setup -step that produced it (or, for DCR with no External credentials, to the -step that produced the issuer / region URL). - -- OAuth with a pre-registered client: under **Authentication**, click - **Configure Manually** (or **Use Discovered** when offered — the - Dossier records whether the provider publishes discoverable OAuth - metadata). In the **Attach Remote Identity Provider** sheet, set - **Client Type** to **Manual**. The sheet shows the **Redirect URI** - with a copy button — the callback URL the guide had the reader - register in External setup (`{{ gram.oauth.callback_url }}`). - - Paste the **Client ID** and **Client Secret (optional)** from - External setup, then click **Attach Identity Provider**. Confirm the - sheet's **Redirect URI** matches the `{{ gram.oauth.callback_url }}` - value registered under the provider's redirect/callback field in - External setup — readers paste that template key directly there; they - do not visit this sheet mid–External-setup only to copy the URI. -- OAuth with Dynamic Client Registration (DCR): under **Authentication**, - click **Configure Manually** (or **Use Discovered** when offered — the - Dossier records whether protected-resource metadata makes discovery - available without a pasted issuer). In the **Attach Remote Identity - Provider** sheet, when the issuer is not already known, paste the - provider **Issuer URL** from External setup (typically the remote MCP - origin). Keep the auto-derived **Slug** and **Display name (optional)** - unless the Dossier records a project naming requirement. Under - **Endpoints**, click **Discover** so authorization, token, and - registration endpoints fill from the provider's authorization-server - metadata. Under **Session Client**, keep **Client Type** set to - **Dynamic Client Registration (DCR)** (the default when a registration - endpoint is discovered). Keep **Token Endpoint Auth Method** at the +Open the server's **Settings**. The Writer renders only the variant +matching the guide's Authentication Option, names the guide's actual +fields, and cross-links each value to the External-setup step that +produced it. Include provider-specific issuer and endpoint values from +the Dossier where needed, rather than making readers guess. + +For OAuth, under **Authentication**: + +- If authentication is not configured, choose **Use Discovered** when + available; otherwise choose **Configure Manually**. +- If authentication is already configured, find **Connected services**. + If no provider is attached, click **Add provider**. If the intended + provider is already attached, review its existing configuration instead + of attaching it again. Adding another provider is not available for + every server type. Changes require write permission. + +In **Attach Remote Identity Provider**, choose **Select existing** to +reuse the intended project provider, or **Add new** to configure one. +The selector appears when existing providers are available; otherwise +the new-provider form is shown directly. For a new provider, enter the +provider's **Issuer URL** when not already populated, retain the derived +**Slug**, and optionally set **Display name (optional)**. A discovered +issuer starts endpoint discovery automatically. Verify the populated +endpoints; if entering or changing the issuer manually, click **Discover** +under **Endpoints** when available. If discovery is unavailable, use the +documented authorization and token endpoints (and registration endpoint +for DCR). + +Under **Session Client**, reuse the intended existing client with +**Select existing**, or choose **Add new** when that selector is shown. +Reusing a client uses its stored credentials, scopes, and audience; do +not instruct readers to re-enter new-client fields in this branch. +Confirm its read-only configuration matches the guide. If it does not, +choose **Add new** rather than implying the attach sheet can edit a reused +client. For a pre-registered client, check the provider's registered +callback against `{{ gram.oauth.callback_url }}` before attachment; +**Redirect URI** is not displayed when selecting an existing client. Then click **Attach Identity Provider**. The +following credential variants apply to a **new** session client: + +- OAuth with a pre-registered client: set **Client Type** to **Manual**. + Paste the **Client ID** and **Client Secret (optional)** from External + setup, and any provider-required overrides. **Scope (override)** takes + comma-separated scopes. The label does not make a + secret optional when the provider requires it. Before clicking + **Attach Identity Provider**, confirm the displayed **Redirect URI** + matches the callback URL registered during External setup + (`{{ gram.oauth.callback_url }}`). Readers receive the rendered callback + URL, not the literal template key. Successful attachment closes the + sheet, so do not put this check after attachment. +- OAuth with Dynamic Client Registration (DCR): verify the registration + endpoint is populated, then set **Client Type** to **Dynamic Client + Registration (DCR)**. Keep **Token Endpoint Auth Method** at the discovered default unless the Dossier records a required override. Leave **Scope (override)** and **Audience (optional)** empty unless - the Dossier records values to enter. Click **Attach Identity - Provider**. The Control Plane registers the OAuth client at the - provider's registration endpoint — there is no **Client ID** or - **Client Secret** to paste, and readers do not register - `{{ gram.oauth.callback_url }}` on the provider for this path. When a - client first needs provider access, complete the provider's on-screen - browser authorization prompts with the intended account (exact prompt - labels are provider-specific; do not invent them). -- API key / token: under **Upstream Headers**, click **Add header**, - enter the **Header name** (for example `Authorization`), leave - **Value source** as **Static value**, paste the value from External - setup, check **Secret**, and click **Save**. (Catalog installs may - collect the same headers earlier, in the **Add to Project** dialog's - **Upstream headers** section.) - + the Dossier records values to enter. Click **Attach Identity Provider**. + The Control Plane registers the OAuth client at the provider's + registration endpoint — there is no **Client ID** or **Client Secret** + to paste, and readers do not register `{{ gram.oauth.callback_url }}` + on the provider for this path. When a client first needs provider + access, complete the provider's browser authorization prompts with the + intended account (exact prompt labels are provider-specific). + +For an API key / token, under **Upstream Headers**, click **Add header**, +enter the **Header name** (for example `Authorization`), leave **Value +source** as **Static value**, paste the value from External setup, check +**Secret**, and click **Save**. Catalog installs may collect these headers +earlier in **Add to Project** under **Upstream headers**; do not add them +a second time. + + ## The closing pointer diff --git a/guides/asana/speakeasy.md b/guides/asana/speakeasy.md index cb63850..b0974b2 100644 --- a/guides/asana/speakeasy.md +++ b/guides/asana/speakeasy.md @@ -2,29 +2,62 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Select **Add Source**. -3. Choose **3rd-party server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Select **Add new** to open the **Add MCP server** page. +3. Choose **From the catalog**. 4. On the **MCP Catalog** page, find **Asana** using **Search MCP servers...**. -5. Select **View**. +5. Open the **Asana** entry. 6. Select **Add**. 7. In **Add to Project**, select **Add to Project**. -This creates the hosted MCP server and opens its **Overview** page. +After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} +Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +For a new provider, enter **Issuer URL** `https://app.asana.com` and keep the auto-derived **Slug**. If discovery does not populate **Endpoints**, enter: + +Authorization endpoint: + +```text +https://app.asana.com/-/oauth_authorize +``` + +Token endpoint: + +```text +https://app.asana.com/-/oauth_token +``` + + + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + Do not enter a scope during this setup. -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, select **Use Discovered** when offered; otherwise, select **Configure Manually**. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Confirm that **Redirect URI** matches the `{{ gram.oauth.callback_url }}` value entered in [Configure the OAuth redirect](external.md#configure-oauth-redirect). -5. Paste the **Client ID** saved in [Create the MCP app](external.md#create-mcp-app) into **Client ID**. -6. Paste the **Client secret** saved in [Create the MCP app](external.md#create-mcp-app) into **Client Secret (optional)**. -7. Select **Attach Identity Provider**. +1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. +1. Paste the **Client ID** saved in [Create the MCP app](external.md#create-mcp-app) into **Client ID**. +1. Paste the **Client secret** saved in [Create the MCP app](external.md#create-mcp-app) into **Client Secret (optional)**. + +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Configure the OAuth redirect](external.md#configure-oauth-redirect). diff --git a/guides/atlassian/speakeasy.md b/guides/atlassian/speakeasy.md index e94fa67..df01446 100644 --- a/guides/atlassian/speakeasy.md +++ b/guides/atlassian/speakeasy.md @@ -2,49 +2,64 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, find **Connect** and select **Sources**. -2. Click **Add Source**. +1. In the Speakeasy AI Control Plane sidebar, find **MCP Gateway** and select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. If an **Atlassian Rovo** result in the catalog clearly identifies the current remote URL shown below: -1. Choose **3rd-party server**. +1. Choose **From the catalog**. 2. On the **MCP Catalog** page, enter `Atlassian` in **Search MCP servers...**. -3. Open that result with **View**. +3. Open that result. 4. Click **Add**. 5. In **Add to Project**, click **Add to Project**. If no clearly current **Atlassian Rovo** result appears in the catalog, use the custom remote path: -1. Choose **Custom remote server**. -2. On **Add a custom remote MCP server**, paste this value into **Remote MCP server URL**: +1. Choose **Hosted remotely**. +2. On **New remote MCP server**, paste this value into **MCP server URL**: ``` https://mcp.atlassian.com/v1/mcp/authv2 ``` -3. Click **Add server**. +3. Click **Verify connectivity**, then **Save**. -Either path opens the server's **Overview** page. +After catalog installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. Saving a custom remote server opens **Overview**; open **Settings** from there. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, select **Use Discovered**. -3. In **Attach Remote Identity Provider**, confirm that the issuer/base auth URL is: +Open the server’s **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +1. In **Attach Remote Identity Provider**, confirm that the issuer/base auth URL is: ``` https://auth.atlassian.com ``` +1. Keep the automatically derived **Slug**. +1. Keep the automatically derived **Display name (optional)**. +1. Under **Endpoints**, wait for automatic discovery of the seeded issuer. After typing or changing **Issuer URL**, click **Discover** only if offered, then confirm the authorization, token, and registration endpoints. + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Attach the provider** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. Under **Session Client**, keep **Client Type** set to **Dynamic Client Registration (DCR)**. +1. Keep the discovered **Token Endpoint Auth Method**. +1. Leave **Scope (override)** and **Audience (optional)** empty. + +#### Attach the provider -4. Keep the automatically derived **Slug**. -5. Keep the automatically derived **Display name (optional)**. -6. Under **Endpoints**, click **Discover** so the authorization, token, and registration endpoints fill from Atlassian's discovery chain. -7. Under **Session Client**, keep **Client Type** set to **Dynamic Client Registration (DCR)**. -8. Keep the discovered **Token Endpoint Auth Method**. -9. Leave **Scope (override)** and **Audience (optional)** empty. -10. Click **Attach Identity Provider**. +Click **Attach Identity Provider**. DCR handles client registration; you do not need to register a callback URL manually. You do not need to paste a **Client ID** or **Client Secret**. diff --git a/guides/box/speakeasy.md b/guides/box/speakeasy.md index 4fe3c25..7aa16f8 100644 --- a/guides/box/speakeasy.md +++ b/guides/box/speakeasy.md @@ -2,35 +2,48 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select - **Sources**. -2. Click **Add Source**. -3. Choose **3rd-party server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. +3. Choose **From the catalog**. 4. On the **MCP Catalog** page, use **Search MCP servers...** to find **Box**. -5. Click **View** on the Box entry. +5. Open the **Box** entry. 6. Click **Add**. 7. In the **Add to Project** dialog, click **Add to Project**. -This creates the hosted MCP server and opens its **Overview** page. +After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**, or click - **Use Discovered** when offered. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Before entering credentials, verify that `{{ gram.oauth.callback_url }}` has - rendered as a concrete Speakeasy **Redirect URI** in the sheet. Do not enter - the literal template marker in Box. -5. Paste the [Box Client ID](external.md#copy-client-credentials) into +Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +For **Identity Provider > Add new**, use **Issuer URL** `https://api.box.com/`, authorization endpoint `https://account.box.com/api/oauth2/authorize`, and token endpoint `https://api.box.com/oauth2/token`. Keep the auto-derived **Slug**. + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. +1. Paste the [Box Client ID](external.md#copy-client-credentials) into **Client ID**. -6. Paste the [Box Client Secret](external.md#copy-client-credentials) into +1. Paste the [Box Client Secret](external.md#copy-client-credentials) into **Client Secret (optional)**. -7. Click **Attach Identity Provider**. -8. Confirm that the attached identity provider's **Redirect URI** matches the - value registered in Box under [Redirect URIs](external.md#set-redirect-uri). + +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Redirect URIs](external.md#set-redirect-uri). diff --git a/guides/github/speakeasy.md b/guides/github/speakeasy.md index db0e0a0..5f45e08 100644 --- a/guides/github/speakeasy.md +++ b/guides/github/speakeasy.md @@ -2,29 +2,46 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **3rd-party server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. +3. Choose **From the catalog**. 4. On the **MCP Catalog** page, find GitHub using **Search MCP servers...**. -5. Open its entry with **View**. +5. Open its entry. 6. Click **Add**. 7. In the **Add to Project** dialog, click **Add to Project**. -This creates the hosted MCP server and opens its **Overview** page. +After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -From the server's **Overview**, open **Settings**. +Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. -If **Use Discovered** is offered under **Authentication**, click it. Otherwise, click **Configure Manually**. +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +For a new provider, use the authorization-server issuer `https://github.com/login/oauth` identified by GitHub’s protected-resource metadata. If discovery does not supply the endpoints, ask your administrator for the documented authorization and token endpoints before continuing; do not infer them from the MCP URL. + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: 1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -2. Paste the **Client ID** saved in [Generate the OAuth credentials](external.md#generate-oauth-credentials) into **Client ID**. -3. Paste the saved client secret into **Client Secret (optional)** — although the field is labeled optional, this OAuth connection requires it. -4. Click **Attach Identity Provider**. -5. Confirm that **Redirect URI** matches the `{{ gram.oauth.callback_url }}` value entered in [Register the OAuth app](external.md#register-oauth-app). +1. Paste the **Client ID** saved in [Generate the OAuth credentials](external.md#generate-oauth-credentials) into **Client ID**. +1. Paste the saved client secret into **Client Secret (optional)** — although the field is labeled optional, this OAuth connection requires it. + +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Register the OAuth app](external.md#register-oauth-app). If the target organization restricts OAuth apps, have a user authorize the connection, then complete the following: diff --git a/guides/gmail/speakeasy.md b/guides/gmail/speakeasy.md index 9698e23..8fa9e4c 100644 --- a/guides/gmail/speakeasy.md +++ b/guides/gmail/speakeasy.md @@ -2,29 +2,79 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On the **Add a custom remote MCP server** page, paste this value into **Remote MCP server URL**: +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **Hosted remotely**. +4. On the **New remote MCP server** page, paste this value into **MCP server URL**: ```text https://gmailmcp.googleapis.com/mcp/v1 ``` -5. Click **Add server**. This creates the hosted MCP server and opens its **Overview** page. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**. -3. In the **Attach Remote Identity Provider** sheet, set **Client Type** to **Manual**. -4. Locate the displayed **Redirect URI** and its copy button. -5. Paste the **Client ID** from [Create the OAuth client](external.md#create-oauth-client) into **Client ID**. -6. Paste the **Client Secret** from [Create the OAuth client](external.md#create-oauth-client) into **Client Secret (optional)**. The Gmail setup requires this value despite the generic optional label. -7. Click **Attach Identity Provider**. -8. Confirm that the sheet's **Redirect URI** matches the `{{ gram.oauth.callback_url }}` value registered under **Authorized redirect URIs**. +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). + +#### Choose an authentication provider + +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. Paste the **Client ID** from [Create the OAuth client](external.md#create-oauth-client) into **Client ID**. +1. Paste the **Client Secret** from [Create the OAuth client](external.md#create-oauth-client) into **Client Secret (optional)**. The Gmail setup requires this value despite the generic optional label. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +For a new client, enter these comma-separated scopes in **Scope (override)**. For a reused client, inspect its read-only **Scope** value; if it does not include both scopes, choose **Add new** instead. The scopes must also match the Google app's **Data Access** configuration: + +```text +https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.compose +``` + +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. diff --git a/guides/google-big-query/speakeasy.md b/guides/google-big-query/speakeasy.md index 4381dd6..e9f9928 100644 --- a/guides/google-big-query/speakeasy.md +++ b/guides/google-big-query/speakeasy.md @@ -2,41 +2,87 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**, then click **Add Source**. +In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**, then click **Add new** to open **Add MCP server**. -1. Choose **Custom remote server**. -2. On the **Add a custom remote MCP server** page, paste this URL into **Remote MCP server URL**: +1. Choose **Hosted remotely**. +2. On the **New remote MCP server** page, paste this URL into **MCP server URL**: ``` https://bigquery.googleapis.com/mcp ``` -3. Click **Add server**. +3. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -Google's web client requires its generated secret even though the Speakeasy AI Control Plane field is labeled **Client Secret (optional)**. +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually** or, if offered, **Use Discovered**. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. +#### Choose an authentication provider -The sheet shows **Redirect URI** with a copy button. It is the callback URL registered in [Create the OAuth client](external.md#create-oauth-client) with `{{ gram.oauth.callback_url }}`. +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. -4. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials) into **Client ID**. -5. Paste the **Client secret** from [Copy the client credentials](external.md#copy-client-credentials) into **Client Secret (optional)**. -6. In **Scope (override)**, enter this value: +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +Google's web client requires its generated secret even though the field is labeled **Client Secret (optional)**. + +1. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials) into **Client ID**. +1. Paste the **Client secret** from [Copy the client credentials](external.md#copy-client-credentials) into **Client Secret (optional)**. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. + +For a new client, enter this value: ``` https://www.googleapis.com/auth/bigquery ``` -7. Click **Attach Identity Provider**. -8. Confirm that the sheet's **Redirect URI** matches the `{{ gram.oauth.callback_url }}` value registered under **Authorized redirect URIs** in [Create the OAuth client](external.md#create-oauth-client). You entered that template directly during provider setup; do not visit this sheet midway through provider setup only to copy the URI. +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). diff --git a/guides/google-calendar/speakeasy.md b/guides/google-calendar/speakeasy.md index 20aad2a..57c92d4 100644 --- a/guides/google-calendar/speakeasy.md +++ b/guides/google-calendar/speakeasy.md @@ -2,37 +2,87 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste this URL into **Remote MCP server URL**: +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste this URL into **MCP server URL**: ``` https://calendarmcp.googleapis.com/mcp/v1 ``` -5. Click **Add server**. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its Overview page. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually** or **Use Discovered** when offered. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. The sheet shows **Redirect URI** with a copy button. -4. Confirm that **Redirect URI** matches `{{ gram.oauth.callback_url }}` entered when you [created the OAuth client](external.md#create-oauth-client). -5. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). -6. Paste the **Client Secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client Secret (optional)**. Google requires this value despite the optional Speakeasy label. -7. Make **Scope (override)** contain all three required scopes below. Speakeasy's public setup material does not document how the field separates multiple values, so follow the current field guidance rather than assuming a delimiter: +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). - - `https://www.googleapis.com/auth/calendar.calendarlist.readonly` - - `https://www.googleapis.com/auth/calendar.events.freebusy` - - `https://www.googleapis.com/auth/calendar.events.readonly` +#### Choose an authentication provider -8. Click **Attach Identity Provider**. -9. At first connection, authorize the requested access with an intended Google account that is eligible under the Developer Preview terms, has `mcp.tools.call` on the project, access to the required calendars, applicable **Test user** status, and Workspace API-control approval when required. **MCP Tool User** is the normal predefined grant for `mcp.tools.call`, but another role containing the permission can suffice. Use the visible controls on Google's authorization screen. +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). +1. Paste the **Client Secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client Secret (optional)**. Google requires this value despite the optional Speakeasy label. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. + +For a new client, enter all three scopes as a comma-separated value in **Scope (override)**: + +```text +https://www.googleapis.com/auth/calendar.calendarlist.readonly, https://www.googleapis.com/auth/calendar.events.freebusy, https://www.googleapis.com/auth/calendar.events.readonly +``` + +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [created the OAuth client](external.md#create-oauth-client). + +At first connection, authorize the requested access with an intended Google account that is eligible under the Developer Preview terms, has `mcp.tools.call` on the project, access to the required calendars, applicable **Test user** status, and Workspace API-control approval when required. **MCP Tool User** is the normal predefined grant for `mcp.tools.call`, but another role containing the permission can suffice. Use the visible controls on Google's authorization screen. diff --git a/guides/google-compute-engine/speakeasy.md b/guides/google-compute-engine/speakeasy.md index 21aa95a..e99d22b 100644 --- a/guides/google-compute-engine/speakeasy.md +++ b/guides/google-compute-engine/speakeasy.md @@ -2,33 +2,80 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**, then click **Add Source**. +In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**, then click **Add new** to open **Add MCP server**. -Choose **3rd-party server**. On the **MCP Catalog** page, search for `Google Compute Engine` in **Search MCP servers...**, open the matched entry with **View**, and click **Add**. In the **Add to Project** dialog, click **Add to Project**. +Choose **From the catalog**. On the **MCP Catalog** page, search for `Google Compute Engine` in **Search MCP servers...**, open the matched entry, and click **Add**. In the **Add to Project** dialog, click **Add to Project**. -This creates the hosted MCP server and opens its **Overview** page. +After the server is added, click **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview** page, open **Settings**. -2. Under **Authentication**, click **Configure Manually**. If - **Use Discovered** is offered, choose **Configure Manually** anyway — - manual configuration matches the client you created in - [Create the OAuth client](external.md#create-oauth-client). This opens the - **Attach Remote Identity Provider** sheet. -3. Set **Client Type** to **Manual**. -4. Confirm the **Redirect URI** the sheet shows matches the URL you - entered under **Authorized redirect URIs** in - [Create the OAuth client](external.md#create-oauth-client). -5. Paste the client ID from +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). + +#### Choose an authentication provider + +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. Paste the client ID from [Copy the client credentials](external.md#copy-client-credentials) into **Client ID**. -6. Paste the client secret into **Client Secret (optional)** — despite +1. Paste the client secret into **Client Secret (optional)** — despite the label, Google requires the secret, so treat the field as required. -7. Click **Attach Identity Provider**. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Verify the new or reused Google client has these required scopes, matching the Google app's **Data Access** configuration: + +```text +https://www.googleapis.com/auth/compute +``` + +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). diff --git a/guides/google-docs/speakeasy.md b/guides/google-docs/speakeasy.md index 2b5988a..2d9ecd0 100644 --- a/guides/google-docs/speakeasy.md +++ b/guides/google-docs/speakeasy.md @@ -2,36 +2,85 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste this URL into **Remote MCP server URL**: +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste this URL into **MCP server URL**: ``` https://docsmcp.googleapis.com/mcp/v1 ``` -5. Click **Add server**. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. The **Transport** field is read-only. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**, or click **Use Discovered** when offered. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Confirm that **Redirect URI** matches `{{ gram.oauth.callback_url }}`, which you entered when you [created the OAuth client](external.md#create-oauth-client). -5. In **Client ID**, paste the value you [copied from Google](external.md#copy-client-credentials). -6. In **Client Secret (optional)**, paste the secret you [copied from Google](external.md#copy-client-credentials). Google requires this value. -7. In **Scope (override)**, enter this value: +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). + +#### Choose an authentication provider + +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. In **Client ID**, paste the value you [copied from Google](external.md#copy-client-credentials). +1. In **Client Secret (optional)**, paste the secret you [copied from Google](external.md#copy-client-credentials). Google requires this value. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. + +For a new client, enter this value: ``` https://www.googleapis.com/auth/drive.readonly, https://www.googleapis.com/auth/drive.file, https://www.googleapis.com/auth/documents.readonly, https://www.googleapis.com/auth/documents ``` -8. Click **Attach Identity Provider**. +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [created the OAuth client](external.md#create-oauth-client). Complete Google's browser authorization with the intended account. If the app is **External** and in **Testing**, that account must be listed under **Test users**. diff --git a/guides/google-drive/speakeasy.md b/guides/google-drive/speakeasy.md index 2a2a50a..1a3318f 100644 --- a/guides/google-drive/speakeasy.md +++ b/guides/google-drive/speakeasy.md @@ -2,37 +2,86 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste this URL into **Remote MCP server URL**: +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste this URL into **MCP server URL**: ``` https://drivemcp.googleapis.com/mcp/v1 ``` -5. Click **Add server**. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**. If **Use Discovered** is offered, you may select it instead. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Confirm that **Redirect URI** matches the `{{ gram.oauth.callback_url }}` value registered in [Create the OAuth client](external.md#create-oauth-client). -5. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). -6. Paste the **Client Secret (optional)** from the same section. Google's Web application flow requires the generated secret despite the optional field label. -7. Configure these two scopes as required: +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). + +#### Choose an authentication provider + +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). +1. Paste the **Client Secret (optional)** from the same section. Google's Web application flow requires the generated secret despite the optional field label. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. + +Configure these two scopes as required: ``` https://www.googleapis.com/auth/drive.readonly https://www.googleapis.com/auth/drive.file ``` -8. Click **Attach Identity Provider**. +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). diff --git a/guides/google-people/speakeasy.md b/guides/google-people/speakeasy.md index 9c8cf13..d4df93e 100644 --- a/guides/google-people/speakeasy.md +++ b/guides/google-people/speakeasy.md @@ -2,38 +2,82 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. - If **Google People** is in the catalog: - 1. Choose **3rd-party server**. + 1. Choose **From the catalog**. 2. On the **MCP Catalog** page, find Google People in **Search MCP servers...**. - 3. Open the matching entry with **View**. + 3. Open the matching entry. 4. Click **Add**. 5. In **Add to Project**, click **Add to Project**. - If no matching catalog entry is available: - 1. Choose **Custom remote server**. - 2. On **Add a custom remote MCP server**, paste this URL into **Remote MCP server URL**: + 1. Choose **Hosted remotely**. + 2. On **New remote MCP server**, paste this URL into **MCP server URL**: ``` https://people.googleapis.com/mcp/v1 ``` - 3. Click **Add server**. + 3. Click **Verify connectivity**, then **Save**. -Either path creates the hosted MCP server and opens its **Overview** page. +For the catalog path, click **Configure MCP settings** on the completion screen to open the server, then open **Settings**. The **Hosted remotely** path opens **Overview** after **Save**; open **Settings** there. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually** or **Use Discovered** when offered. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Confirm that **Redirect URI** matches `{{ gram.oauth.callback_url }}` entered when you [created the OAuth client](external.md#create-oauth-client). -5. Paste the **Client ID** from the [OAuth credentials](external.md#copy-oauth-credentials). -6. Paste the **Client Secret (optional)** from the [OAuth credentials](external.md#copy-oauth-credentials). Google requires this secret even though the field is labeled optional. -7. In **Scope (override)**, enter these three identifiers using the field's visible or equivalent multi-scope format: +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). + +#### Choose an authentication provider + +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. Paste the **Client ID** from the [OAuth credentials](external.md#copy-oauth-credentials). +1. Paste the **Client Secret (optional)** from the [OAuth credentials](external.md#copy-oauth-credentials). Google requires this secret even though the field is labeled optional. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. + +For a new client, enter these three identifiers using the field's visible or equivalent multi-scope format: ``` https://www.googleapis.com/auth/directory.readonly @@ -41,8 +85,14 @@ Either path creates the hosted MCP server and opens its **Overview** page. https://www.googleapis.com/auth/contacts.readonly ``` -8. Click **Attach Identity Provider**. -9. At first connection, follow Google's visible or equivalent browser authorization controls with an account that has [MCP Tool User access](external.md#grant-mcp-tool-user). +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [created the OAuth client](external.md#create-oauth-client). + +At first connection, follow Google's visible or equivalent browser authorization controls with an account that has [MCP Tool User access](external.md#grant-mcp-tool-user). diff --git a/guides/google-sheets/speakeasy.md b/guides/google-sheets/speakeasy.md index b0fd31d..29883e7 100644 --- a/guides/google-sheets/speakeasy.md +++ b/guides/google-sheets/speakeasy.md @@ -2,36 +2,85 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste this URL into **Remote MCP server URL**: +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste this URL into **MCP server URL**: ``` https://sheetsmcp.googleapis.com/mcp/v1 ``` -5. Click **Add server**. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually** or **Use Discovered** when offered. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Confirm that **Redirect URI** matches `{{ gram.oauth.callback_url }}` from [Create the OAuth client](external.md#create-oauth-client). -5. In **Client ID**, paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). -6. In **Client Secret (optional)**, paste the **Client secret** from the same step. Google requires this generated secret. -7. In **Scope (override)**, enter this value: +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). + +#### Choose an authentication provider + +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. In **Client ID**, paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). +1. In **Client Secret (optional)**, paste the **Client secret** from the same step. Google requires this generated secret. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. + +For a new client, enter this value: ``` https://www.googleapis.com/auth/drive.readonly,https://www.googleapis.com/auth/drive.file,https://www.googleapis.com/auth/spreadsheets.readonly,https://www.googleapis.com/auth/spreadsheets ``` -8. Click **Attach Identity Provider**. +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). At first connection, complete Google's browser authorization with an account granted [MCP Tool User](external.md#grant-mcp-tool-user) and access to the intended spreadsheets. diff --git a/guides/google-slides/speakeasy.md b/guides/google-slides/speakeasy.md index 3a42deb..48cdcf0 100644 --- a/guides/google-slides/speakeasy.md +++ b/guides/google-slides/speakeasy.md @@ -2,36 +2,85 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste this URL into **Remote MCP server URL**: +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open **Add MCP server**. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste this URL into **MCP server URL**: ``` https://slidesmcp.googleapis.com/mcp/v1 ``` -5. Click **Add server**. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. **Transport** is read-only. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**, or **Use Discovered** when offered. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Confirm that **Redirect URI** matches `{{ gram.oauth.callback_url }}` entered in [Create the OAuth client](external.md#create-oauth-client). -5. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). -6. Paste the **Client Secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client Secret (optional)**. Google's web client requires this generated secret. -7. In **Scope (override)**, enter this value: +Open the server's **Settings** (from **Overview** for a hosted remote server, or **Configure MCP settings** after a catalog addition). + +#### Choose an authentication provider + +- If **Authentication** is unconfigured, choose **Use Discovered** when available; otherwise choose **Configure Manually**. +- If authentication is configured but no provider is attached, use **Connected services** > **Add provider**. +- If the intended provider is already attached, use its existing controls. Do not attach a duplicate; check its client against the requirements below and skip **Verify and attach**. + +In **Attach Remote Identity Provider**, the provider selector defaults to **Select existing** when the project has issuers. Select the appropriate existing Google provider and skip new-provider setup. + +#### New provider only + +1. Choose **Add new** and enter **Issuer URL**: + + ```text + https://accounts.google.com/ + ``` + +2. Confirm the auto-derived **Slug** is unique in the project. +3. Discovery runs automatically for a seeded issuer URL. After typing or changing the URL, click **Discover** only if offered. +4. Review the endpoints, or enter these Google OAuth values if discovery does not populate them. + + Authorization endpoint: + + ```text + https://accounts.google.com/o/oauth2/v2/auth + ``` + + Token endpoint: + + ```text + https://oauth2.googleapis.com/token + ``` + +#### Choose a session client + +- **Reuse:** Under **Session Client**, choose **Select existing** when available and select the appropriate Google OAuth client. Skip credential entry; continue to **Check client requirements**. +- **Create:** Choose **Add new** when available and set **Client Type** to **Manual**. For a new provider, complete the new-client form below. + +#### New session client only + +1. Paste the **Client ID** from [Copy the OAuth credentials](external.md#copy-oauth-credentials). +1. Paste the **Client Secret** from [Copy the OAuth credentials](external.md#copy-oauth-credentials) into **Client Secret (optional)**. Google's web client requires this generated secret. + +#### Check client requirements + +For both new and reused clients, verify the Google app's approved audience and publishing status. An **External** app in **Testing** must list each connecting account under **Test users**. Reusing a client does not require entering its credentials again. + +Confirm the selected client includes the required scopes below. For a new client, configure **Scope (override)**; for a reused client, inspect the read-only **Scope** value. If it does not match, choose **Add new** to create a correctly scoped client; the attach sheet cannot edit a reused client. + +For a new client, enter this value: ``` https://www.googleapis.com/auth/drive.readonly,https://www.googleapis.com/auth/drive.file,https://www.googleapis.com/auth/presentations.readonly,https://www.googleapis.com/auth/presentations ``` -8. Click **Attach Identity Provider**. +#### Verify and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Create the OAuth client](external.md#create-oauth-client). At first connection, complete Google's browser authorization with an account granted **MCP Tool User** in [Grant MCP Tool User access](external.md#grant-mcp-tool-user) and access to the intended presentations. An **External** app in **Testing** also requires that account under **Test users**. diff --git a/guides/hubspot/speakeasy.md b/guides/hubspot/speakeasy.md index e96f55c..c6521de 100644 --- a/guides/hubspot/speakeasy.md +++ b/guides/hubspot/speakeasy.md @@ -2,34 +2,48 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select - **Sources**. -2. Click **Add Source**. -3. Choose **3rd-party server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. +3. Choose **From the catalog**. 4. On the **MCP Catalog** page, use **Search MCP servers...** to find **HubSpot**. -5. Open the **HubSpot** entry with **View**. +5. Open the **HubSpot** entry. 6. Click **Add**. 7. In the **Add to Project** dialog, click **Add to Project**. -This creates the hosted MCP server and opens its **Overview** page. +After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**, or click - **Use Discovered** if it is available. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Confirm that **Redirect URI** matches the `{{ gram.oauth.callback_url }}` - value registered in HubSpot's **Redirect URL** field. -5. Paste the **Client ID** copied in +Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +For **Identity Provider > Add new**, use **Issuer URL** `https://mcp.hubspot.com`, authorization endpoint `https://mcp.hubspot.com/oauth/authorize/user`, and token endpoint `https://mcp.hubspot.com/oauth/v3/token`. Keep the auto-derived **Slug**. + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. +1. Paste the **Client ID** copied in [Copy the client credentials](external.md#copy-client-credentials). -6. Paste the **Client Secret (optional)** copied in +1. Paste the **Client Secret (optional)** copied in [Copy the client credentials](external.md#copy-client-credentials). -7. Leave any scope override empty. -8. Click **Attach Identity Provider**. +1. Leave any scope override empty. + +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. diff --git a/guides/intercom/speakeasy.md b/guides/intercom/speakeasy.md index f9dea6b..ce91917 100644 --- a/guides/intercom/speakeasy.md +++ b/guides/intercom/speakeasy.md @@ -2,35 +2,52 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste the remote URL from [Identify the workspace region](external.md#identify-workspace-region) into **Remote MCP server URL**. -5. Click **Add server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste the remote URL from [Identify the workspace region](external.md#identify-workspace-region) into **MCP server URL**. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Enter `https://mcp.intercom.com` as **Issuer URL**. -5. Under **Endpoints**, set the authorization endpoint to `https://app.intercom.com/oauth`. -6. Set the token endpoint to this URL: +From the server's **Overview**, open **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +1. Enter `https://mcp.intercom.com` as **Issuer URL**. +1. Under **Endpoints**, set the authorization endpoint to `https://app.intercom.com/oauth`. +1. Set the token endpoint to this URL: ``` https://api.intercom.io/auth/eagle/token ``` -7. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). -8. Paste the **Client Secret (optional)** from [Copy the client credentials](external.md#copy-client-credentials). -9. Leave **Scope (override)** empty. -10. Leave **Audience (optional)** empty. -11. Confirm that **Redirect URI** is `{{ gram.oauth.callback_url }}`, matching the value registered in [Configure OAuth](external.md#configure-oauth). -12. Click **Attach Identity Provider**. +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. +1. Paste the **Client ID** from [Copy the client credentials](external.md#copy-client-credentials). +1. Paste the **Client Secret (optional)** from [Copy the client credentials](external.md#copy-client-credentials). +1. Leave **Scope (override)** empty. +1. Leave **Audience (optional)** empty. + +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Configure OAuth](external.md#configure-oauth). diff --git a/guides/netsuite/speakeasy.md b/guides/netsuite/speakeasy.md index 283733f..a94825d 100644 --- a/guides/netsuite/speakeasy.md +++ b/guides/netsuite/speakeasy.md @@ -2,23 +2,41 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On **Add a custom remote MCP server**, paste the account-specific endpoint you formed in [Record the account-specific MCP URL](external.md#record-account-mcp-url) into **Remote MCP server URL**. **Transport** is read-only. -5. Click **Add server**. This creates the hosted MCP server and opens its **Overview** page. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. +3. Choose **Hosted remotely**. +4. On **New remote MCP server**, paste the account-specific endpoint you formed in [Record the account-specific MCP URL](external.md#record-account-mcp-url) into **MCP server URL**. **Transport** is read-only. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**. -3. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. -4. Before entering credentials, use the displayed **Redirect URI** and its copy button to confirm that the value matches the callback registered in [Create the OAuth integration](external.md#create-oauth-integration). -5. Paste the **Client ID** copied in that step. -6. Leave **Client Secret (optional)** empty. -7. Click **Attach Identity Provider**. +From the server's **Overview**, open **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +If no matching provider or complete discovered configuration is available, ask your administrator for the documented **Issuer URL** and authorization and token **Endpoints** before continuing. Do not infer them from the MCP server URL. + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. In **Attach Remote Identity Provider**, set **Client Type** to **Manual**. +1. Use the displayed **Redirect URI** and its copy button to confirm that the value matches the callback registered in [Create the OAuth integration](external.md#create-oauth-integration). +1. Paste the **Client ID** copied in that step. +1. Leave **Client Secret (optional)** empty. + +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. When a client first requests access, sign in to NetSuite with the scoped non-Administrator role assigned in [Configure a scoped non-admin role](external.md#configure-scoped-role). Review the allow/deny prompt, then allow access only after reviewing your organization's data-sharing controls. diff --git a/guides/salesforce/speakeasy.md b/guides/salesforce/speakeasy.md index ea7c520..7bfc63a 100644 --- a/guides/salesforce/speakeasy.md +++ b/guides/salesforce/speakeasy.md @@ -4,33 +4,50 @@ Follow these steps after [creating your own Salesforce app](external.md#create-y ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Select **Add Source**. -3. Choose **Custom remote server**. -4. On the **Add a custom remote MCP server** page, paste the URL recorded in [Enable the selected MCP server](external.md#enable-sobject-server) into **Remote MCP server URL**. -5. Select **Add server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Select **Add new** to open the **Add MCP server** page. +3. Choose **Hosted remotely**. +4. On the **New remote MCP server** page, paste the URL recorded in [Enable the selected MCP server](external.md#enable-sobject-server) into **MCP server URL**. +5. Select **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -If attachment still fails after the app's 30-minute activation window, stop and escalate; do not change the OAuth settings. +From the server's **Overview**, open **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +If no matching provider or complete discovered configuration is available, ask your administrator for the documented **Issuer URL** and authorization and token **Endpoints** before continuing. Do not infer them from the MCP server URL. + +#### Select the session client -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, select **Configure Manually**. -3. In the **Attach Remote Identity Provider** sheet, set **Client Type** to **Manual**. +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. In the **Attach Remote Identity Provider** sheet, set **Client Type** to **Manual**. The sheet shows the **Redirect URI** with a copy button. It is the callback URL registered in Salesforce as `{{ gram.oauth.callback_url }}`. -4. Paste the [**Consumer Key**](external.md#copy-consumer-key) into **Client ID**. -5. Leave **Client Secret (optional)** empty. -6. Select **Attach Identity Provider**. -7. Confirm that the sheet's **Redirect URI** matches the `{{ gram.oauth.callback_url }}` value registered in [**Callback URL**](external.md#configure-oauth-settings). +1. Paste the [**Consumer Key**](external.md#copy-consumer-key) into **Client ID**. +1. Leave **Client Secret (optional)** empty. - +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [**Callback URL**](external.md#configure-oauth-settings). -These steps configure the server and attach its identity provider; they do not verify Salesforce authorization or a working connection. +If attachment still fails after the app's 30-minute activation window, stop and escalate; do not change the OAuth settings. + + This guide covers setup only. For anything beyond it — billing, tool behavior, limits — see [Salesforce's MCP documentation](https://developer.salesforce.com/docs/platform/hosted-mcp-servers/guide/hosted-mcp-servers-overview.html). diff --git a/guides/snowflake/speakeasy.md b/guides/snowflake/speakeasy.md index 39bd0a5..16d19aa 100644 --- a/guides/snowflake/speakeasy.md +++ b/guides/snowflake/speakeasy.md @@ -2,26 +2,44 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **Custom remote server**. -4. On the **Add a custom remote MCP server** page, paste the account-specific URL retained in [Create the Cortex Agent MCP server](external.md#create-cortex-agent-mcp-server) into **Remote MCP server URL**. -5. Click **Add server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. +3. Choose **Hosted remotely**. +4. On the **New remote MCP server** page, paste the account-specific URL retained in [Create the Cortex Agent MCP server](external.md#create-cortex-agent-mcp-server) into **MCP server URL**. +5. Click **Verify connectivity**, then **Save**. This creates the hosted MCP server and opens its **Overview** page. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview**, open **Settings**. -2. Under **Authentication**, click **Configure Manually**. -3. In the **Attach Remote Identity Provider** sheet, set **Client Type** to **Manual**. -4. Locate the displayed **Redirect URI** and its copy button. -5. Confirm that the displayed **Redirect URI** matches the `{{ gram.oauth.callback_url }}` value registered in [Create the OAuth integration](external.md#create-oauth-integration). -6. Paste the [**Client ID**](external.md#copy-oauth-credentials) into **Client ID**. -7. Paste the [**Client Secret**](external.md#copy-oauth-credentials) into **Client Secret (optional)**. -8. Click **Attach Identity Provider**. +From the server's **Overview**, open **Settings**. + +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. + +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +If no matching provider or complete discovered configuration is available, ask your administrator for the documented **Issuer URL** and authorization and token **Endpoints** before continuing. Do not infer them from the MCP server URL. + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Verify the callback and attach** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. In the **Attach Remote Identity Provider** sheet, set **Client Type** to **Manual**. +1. Paste the [**Client ID**](external.md#copy-oauth-credentials) into **Client ID**. +1. Paste the [**Client Secret**](external.md#copy-oauth-credentials) into **Client Secret (optional)**. + +#### Verify the callback and attach + +1. Confirm that the callback URL registered with the provider is `{{ gram.oauth.callback_url }}`. For a new manual client, also compare it with the sheet's displayed **Redirect URI**. The existing-client selection does not display that field; check the registered callback in the provider's app settings instead. +2. Click **Attach Identity Provider**. + +For the provider-side callback setting, see [Create the OAuth integration](external.md#create-oauth-integration). diff --git a/guides/x-docs/speakeasy.md b/guides/x-docs/speakeasy.md index 76b999f..f5e86f3 100644 --- a/guides/x-docs/speakeasy.md +++ b/guides/x-docs/speakeasy.md @@ -2,15 +2,15 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**. -2. Click **Add Source**. -3. Choose **3rd-party server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Click **Add new** to open the **Add MCP server** page. +3. Choose **From the catalog**. 4. On the **MCP Catalog** page, enter `X Docs` in **Search MCP servers...**. -5. Open the **X Docs** entry with **View**. +5. Open the **X Docs** entry. 6. Click **Add**. 7. In the **Add to Project** dialog, click **Add to Project**. -This creates the hosted MCP server and opens its **Overview** page. +After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. diff --git a/guides/x/speakeasy.md b/guides/x/speakeasy.md index 2f1eb27..e460d2e 100644 --- a/guides/x/speakeasy.md +++ b/guides/x/speakeasy.md @@ -2,17 +2,17 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -In the Speakeasy AI Control Plane sidebar, under **Connect**, select **Sources**, then click **Add Source**. +In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**, then click **Add new** to open the **Add MCP server** page. -Choose **3rd-party server**. On the **MCP Catalog** page, enter `X` in **Search MCP servers...**, open the X result with **View**, and click **Add**. If the **Add to Project** dialog requests headers during installation, configure its **Upstream headers** section before continuing — follow steps 3–6 under [Connect your credentials](#connect-speakeasy-credentials). In the **Add to Project** dialog, click **Add to Project**. +Choose **From the catalog**. On the **MCP Catalog** page, enter `X` in **Search MCP servers...**, open the X result, and click **Add**. If the **Add to Project** dialog requests headers during installation, enter `Bearer ` followed by your saved [**Bearer Token**](external.md#copy-bearer-token) in the provided `Authorization` value field under **Upstream headers**. The dialog supplies the header name and secret handling; it does not show the Settings editor's controls. If no header field is offered, follow [Connect your credentials](#connect-speakeasy-credentials) after installation. In the **Add to Project** dialog, click **Add to Project**. -This creates the hosted MCP Server and opens its **Overview** page. +After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -If you configured headers in the **Add to Project** dialog, skip this section. Otherwise, from the server's **Overview** page: +If you configured headers in the **Add to Project** dialog, skip this section. Otherwise, select **Configure MCP settings** on the completion screen: 1. Open **Settings**. 2. Under **Upstream Headers**, select **Add header**. diff --git a/guides/zapier/speakeasy.md b/guides/zapier/speakeasy.md index be2f347..822ea0e 100644 --- a/guides/zapier/speakeasy.md +++ b/guides/zapier/speakeasy.md @@ -2,45 +2,76 @@ ### Add the server in Speakeasy {#add-server-in-speakeasy} -1. In the Speakeasy AI Control Plane sidebar, under **Connect**, select - **Sources**. -2. Select **Add Source**. -3. Choose **3rd-party server**. +1. In the Speakeasy AI Control Plane sidebar, under **MCP Gateway**, select **MCP**. +2. Select **Add new** to open the **Add MCP server** page. +3. Choose **From the catalog**. 4. On the **MCP Catalog** page, enter `Zapier` in **Search MCP servers...**. -5. On the **Zapier** entry, select **View**. +5. Open the **Zapier** entry. 6. Select **Add**. 7. In the **Add to Project** dialog, select **Add to Project**. -This creates the hosted MCP server and opens its **Overview** page. +After installation, select **Configure MCP settings** on the completion screen to open the server, then open **Settings**. - + ### Connect your credentials {#connect-speakeasy-credentials} -1. From the server's **Overview** page, open **Settings**. -2. Under **Authentication**, select **Use Discovered** when offered; - otherwise, select **Configure Manually**. +Select **Configure MCP settings** on the completion screen, then open the server’s **Settings**. -This opens the **Attach Remote Identity Provider** sheet. OAuth discovery -uses Zapier's metadata without requiring you to paste an issuer. +Under **Authentication**, if unconfigured, select **Use Discovered** when available; otherwise select **Configure Manually**. If configured but no provider is attached, use **Connected services > Add provider**. If the intended provider is already attached, use its existing controls and skip the provider/client creation and attachment steps below; do not add a duplicate. -3. Keep the auto-derived **Slug**. -4. Keep the auto-derived **Display name (optional)**. -5. Under **Endpoints**, select **Discover** to fill the authorization, token, - and registration endpoints. -6. Under **Session Client**, keep **Client Type** set to **Dynamic Client +#### Select the identity provider + +In **Attach Remote Identity Provider**, **Identity Provider** defaults to **Select existing** when project issuers are available. Select the matching provider and skip the new-provider fields below. Otherwise choose **Add new** (or use the new-provider form shown when none exist). + +For a new provider only, confirm **Issuer URL**, the auto-derived **Slug**, and **Endpoints**. Discovery runs automatically for a seeded issuer; after typing or changing the URL, select **Discover** only if offered. + +For a new provider, enter **Issuer URL** `https://mcp.zapier.com` and keep the auto-derived **Slug**. If discovery does not populate **Endpoints**, enter: + +Authorization endpoint: + +```text +https://mcp.zapier.com/oauth/authorize +``` + +Token endpoint: + +```text +https://mcp.zapier.com/api/v1/oauth/token +``` + +Registration endpoint: + +```text +https://mcp.zapier.com/api/v1/oauth/register +``` + + + +1. Keep the auto-derived **Slug**. +1. Keep the auto-derived **Display name (optional)**. +1. Under **Endpoints**, wait for automatic discovery of the seeded issuer. After typing or changing **Issuer URL**, select **Discover** only if offered, then confirm the authorization, token, and registration endpoints. + +#### Select the session client + +Under **Session Client**, choose **Select existing** only for a client whose saved credentials, scopes, and audience match the requirements below; otherwise choose **Add new**. When reusing a matching client, skip directly to **Attach the provider** below. Do not create credentials or register the client again. Otherwise choose **Add new** (or use the new-client form shown when no clients exist) and complete these new-client-only steps: + +1. Under **Session Client**, keep **Client Type** set to **Dynamic Client Registration (DCR)**. -7. Keep **Token Endpoint Auth Method** at its discovered default. -8. Leave **Scope (override)** empty. -9. Leave **Audience (optional)** empty. -10. Select **Attach Identity Provider**. +1. Keep **Token Endpoint Auth Method** at its discovered default. +1. Leave **Scope (override)** empty. +1. Leave **Audience (optional)** empty. + +#### Attach the provider + +Click **Attach Identity Provider**. DCR handles client registration; you do not need to register a callback URL manually. -The Speakeasy AI Control Plane registers the OAuth client with Zapier. You do +For a new DCR client, the Speakeasy AI Control Plane registers the OAuth client with Zapier. You do not need to paste a **Client ID** or **Client Secret**. -11. When provider access is first requested, sign in to Zapier with the account +1. When provider access is first requested, sign in to Zapier with the account whose app connections should be available. -12. Complete Zapier's on-screen authorization prompts. +2. Complete Zapier's on-screen authorization prompts.