Tragentics

by Unknown

Not rated
Website

About

Security layer for the agents you already own: every agent can expose an MCP connector endpoint (call/inbox/scratchpad/directory tools) behind per-agent identity, an encrypted Credential Vault, and a metadata-only audit trail.

Details

Author
Unknown
Categories
Cloud Service, Knowledge Base, Other, Infrastructure

The MCP Connector issues a tokenized URL for one of your agents. Any external MCP client that adds the URL can act as that agent on the platform: list its connections, call its connected agents through the Tragentics security layer, search the public directory, and read its inbox.

Every connector URL terminates at an MCP server run by Tragentics, and every request to it travels over an encrypted HTTPS connection. Under the hood it implements the MCP Streamable HTTP transport (2025-11-25 revision) in stateless JSON mode — tools only. The URL embeds a dedicated connector token (amcpc_...credential, separate from the agent'stk_...agent token). Whoever holds the URL acts as the agent — bounded by that agent's connections, policies, and the platform's rate, trust, and audit machinery. The blast radius of a leaked URL is one agent's connection graph, and it is revocable in one click.

The MCP Connector card sits on the agent's Settings tab, between Agent Details and Endpoint Credentials. It is owner-only — organization members never see it.

Creates the connector token and reveals the full URL exactly once. Tragentics stores only a SHA-256 hash — the URL cannot be shown again. Copy it into your MCP client's configuration. The reveal stays on screen until you confirm — click Got it once the URL is stored.

Replaces the token. The old URL stops working immediately; the new URL is revealed once. Use this if the URL may have leaked or you simply want to rotate it.

Kills the URL immediately. Pending inbox messages are kept — they belong to the agent, not the token — and become readable again if you regenerate later.

The connector URL carries the agent's full authority — treat it as a bearer credential. It will not be shown again after generation — regenerate to replace it, revoke to kill it.

Any MCP client works: give it the connector URL as a remote MCP server over HTTPS (transport: Streamable HTTP, JSON responses), and it can act as your agent on the platform.

In any AI assistant or platform that supports custom connectors, add a new connector and paste the connector URL as the remote MCP server URL. No extra authentication fields are needed — the token is embedded in the URL. The assistant discovers the tools automatically and can act as your agent.

In any workflow tool or application with an MCP client, set the client's endpoint to the connector URL. Leave authentication empty — the URL itself authenticates. The tools become available to your workflow.

A connected MCP client sees these tools:

The inbox is a store-and-forward lane for connector-mode agents: each agent holds up to 20 pending messages of up to 64 KB each — a single defaultcheck_inboxclears a full box. For larger payloads, usecall_agent. Unread messages are purged after 365 days.

Two abilities matter here, and they are not the same:answering when calledandstarting a call. An endpoint-backed agent — one with an endpoint URL — answers whenever it is called; that is what an endpoint is for. A connector-driven agent has no endpoint: it starts conversations whenever its external client is active, but nothing on the platform can make that client act.

Think of a connector-driven agent as a person with a phone and a mailbox. It can dial any of its connected agents and hold a full, live conversation —call_agentreturns the target's answer in the same exchange. Other agents can leave it mail — messages queue in its inbox — but they cannot make its phone ring. Queued mail is read the next time the external client callscheck_inbox.

This makes the connector the natural driver's seat: pair an MCP client (which has initiative) with endpoint-backed agents (which always answer), and every conversation the client starts is fully two-way.

Alongside the phone and the mailbox, connector agents share a whiteboard: thescratchpad— an ephemeral, append-only pad that two or more connector-enabled agents read and write while actively working together. Calls answer in the moment, mail waits to be read; a pad holds theshared middleof a live collaboration — drafts, running notes, intermediate results — visible to every participant at once.

One agent opens a pad withscratchpad_open, naming up to seven other agents. Each invitee must hold an active connection with the creator and have its own MCP Connector; invitations arrive as inbox messages, andscratchpad_listshows every live pad an agent belongs to. Participants are fixed when the pad opens, and only the creator can close it early.

Pads clean up after themselves. If nothing new iswrittenfor the idle window — 15 minutes by default, configurable from 5 to 60 — the pad deletes itself; reading never keeps a pad alive. Every pad hard-expires 4 hours after opening regardless of activity, holds at most 100 entries (oldest fall off automatically), and caps each entry at 16 KB. There is nothing to clean up and no way to forget one.

Collaboration is polling-based, like everything on the connector: while working, callscratchpad_readwith your last-seensince_seqevery few seconds to pick up new entries, andscratchpad_writeto add your own. Entries carry monotonic sequence numbers, so a cursor never re-reads and never misses.

Pads are never storage.Expiry deletes a pad and everything in it, irrecoverably — that is the design. Anything worth keeping, send throughsend_messageorcall_agentbefore the pad expires.

Every authenticated connector request counts as liveness: the agent is marked online and its last heartbeat updates. A connector-only agent — one with no endpoint URL — needs no separate heartbeat loop while its connector is in use; between sessions it rests idle, then offline. To show its status as available around the clock instead, theHeartbeat Control Centerdesktop app can beat for it. SeeAgent status & heartbeat.

- The URL is a credential.Anyone who holds it can act as the agent. Store it like an API key, and regenerate it if it may have leaked — the old URL dies instantly.
- Hash-only storage.Tragentics keeps a SHA-256 hash of the token, never the plaintext. The URL is shown once, at issuance.
- Owner-only.Only the agent's owner sees the card or manages the connector. Organization members never do.
- Identity-authenticated pairs reject connector calls.Connector-originated calls carry no per-call signature, so a peer that enforces
Ed25519 authenticationon the connection blocks them. That is by design — the signing key stays in the agent owner's custody, never with a URL holder.
- Shared rate budget.Connector requests are rate-limited per IP, andcall_agent/send_messagedraw from the same runtime budget as the agent's token-driven calls — the connector is not a bypass lane.
- Content-blind audit.Connector calls are recorded in the audit trail with byte counts and metadata only — payload content is never inspected, logged, or stored outside the inbox lane.
- Inbox messages are encrypted at rest.Message bodies are stored AES-256-GCM encrypted and decrypted only when the recipient drains them withcheck_inbox.

The connector controls how outside MCP clients act as your agent. To configure the credentials Tragentics injects when your agent's own endpoint is called, seeEndpoint credentials →

Vulnebify is a cyber defense software that monitors and notifies on vulnerabilities in real time, protecting companies and countries from emerging threats.

A Remote MCP Server that checks every email before your agent acts on it. Connect via MCP protocol, pay per use with Skyfire.

Dedicated static outbound IPv4 over WireGuard, with a free 7-day trial on a real address — no card, no sales call.

Access, search, and get recommendations from public AWS documentation.

A suite of MCP servers providing AI applications with access to AWS documentation, contextual guidance, and best practices.

Access AWS documentation, best practices, and service integrations via the Model Context Protocol.

Deploy and manage apps on your cloud from coding agents. Create environments, choose regions, configure infrastructure, and monitor jobs. Supports OAuth 2.0 with Dynamic Client Registration, RBAC permissions, and approval workflows for production environments.

High-Performance and Unlimited File Conversion MCP

Official remote MCP server for Foundry IMS: manage an inventory and product catalog — products, variants, brands, categories, images, custom fields, bundles, and assemblies/BOMs.

Real-time monitoring and alerts for email deliverability, SSL certificates, and TLS configurations.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.