Custom MCP Servers Technical Overview

Custom MCP servers let the Operations Agent and the Troubleshooting Agent call tools on MCP servers that you connect. This page describes how Monte Carlo handles the credentials for those servers and the data their tools return.

Custom MCP servers follow the same practices as Monte Carlo's other AI features. See AI Agents - Architecture & Data Handling and AI Security & Governance.


Architecture Summary

ComponentDescription
Your MCP serverA remote MCP server that you run or subscribe to. It exposes tools over HTTPS.
Monte Carlo platformStores the server configuration and credentials. Checks who can use each server.
Monte Carlo agentsThe Operations Agent and the Troubleshooting Agent. They load tools from your servers and call them during a conversation or investigation.
AWS Bedrock (LLM)Decides which tools to call, and reads tool results to produce answers.

How a tool call works:

  1. A user starts a conversation or an investigation.
  2. The agent asks the Monte Carlo platform which servers the user can use, and gets the credentials for each.
  3. The agent connects to each server from Monte Carlo's cloud and lists its read-only tools.
  4. The LLM picks a tool. The agent calls your server and sends the result back to the LLM.

Credentials

  • Stored encrypted: API keys, extra headers, and OAuth client secrets are stored encrypted in Monte Carlo's secret store. Monte Carlo never shows them again after you save them.
  • Per-user OAuth tokens: For servers that use the authorization code (PKCE) method, each user's tokens are held by WorkOS, the OAuth service Monte Carlo uses for MCP. Monte Carlo fetches a user's token only when that user runs an agent.
  • Never sent to the LLM: Credentials go only to your MCP server, in request headers. They are masked in Monte Carlo's logs and error reports.
  • Per-user access: With the authorization code (PKCE) method, the agent acts with each user's own access in the other system. With None, API key, or client credentials, every user shares one identity.
  • Revocation: Admins can revoke a user's connection in Monte Carlo, which deletes the stored tokens. Grants in the other system are revoked in that system.

Data Handling

What goes to the LLM

The LLM receives the names, descriptions, and input schemas of your read-only tools, the inputs the agent sends, and the results your server returns. This is processed by AWS Bedrock in Monte Carlo's AWS environment, like the rest of the conversation. AWS Bedrock does not store this data or use it for training.

Tool results are stored with the conversation

Tool results become part of the conversation. Monte Carlo stores them with the rest of the conversation traces for up to 30 days, then deletes them. They are used to answer follow-up questions.

Data TypeWhere It LivesDurationUsed For
Server configurationMonte Carlo platformUntil you delete the serverConnecting to your server
API keys and client secretsMonte Carlo secret store, encryptedUntil you delete or replace themAuthenticating to your server
Per-user OAuth tokensWorkOSUntil revoked or expiredAuthenticating as each user
Tool resultsMonte Carlo AWS environment, with conversation tracesUp to 30 daysConversational features
LLM processingAWS BedrockTransient onlyReal-time AI inference

Safeguards

  • Read-only tools: Agents only call tools that your server marks as read-only with the MCP readOnlyHint annotation.
  • Size and call limits: The Troubleshooting Agent cuts each tool result to 6,000 characters and limits how many tools it calls in each step.
  • Customer isolation: Each account only sees its own servers. Each user only gets credentials for servers they are allowed to use.

Network

  • Monte Carlo connects to your MCP server from Monte Carlo's cloud over HTTPS. The server must be reachable from the internet.
  • Monte Carlo refuses URLs that resolve to private or reserved IP addresses.
  • Monte Carlo sends only the requests needed to list tools and call them, plus the connection test when an admin clicks Test connection.
  • If you set a user identity header, Monte Carlo sends the calling user's email or Monte Carlo user ID to your server in that header.

Your Responsibilities

Your MCP server and the systems behind it are not run by Monte Carlo. You control:

  • Which tools the server exposes, and which ones it marks as read-only.
  • What data each tool returns. Anything a tool returns is sent to the LLM and stored with the conversation.
  • The scopes and permissions of the credentials you give Monte Carlo.

Did this page help you?