Custom MCP Servers Technical Overview
Custom MCP servers let the Operations Agent and the Troubleshooting Agent call tools on MCP servers that you connect. This page describes how Monte Carlo handles the credentials for those servers and the data their tools return.
Custom MCP servers follow the same practices as Monte Carlo's other AI features. See AI Agents - Architecture & Data Handling and AI Security & Governance.
Architecture Summary
| Component | Description |
|---|---|
| Your MCP server | A remote MCP server that you run or subscribe to. It exposes tools over HTTPS. |
| Monte Carlo platform | Stores the server configuration and credentials. Checks who can use each server. |
| Monte Carlo agents | The Operations Agent and the Troubleshooting Agent. They load tools from your servers and call them during a conversation or investigation. |
| AWS Bedrock (LLM) | Decides which tools to call, and reads tool results to produce answers. |
How a tool call works:
- A user starts a conversation or an investigation.
- The agent asks the Monte Carlo platform which servers the user can use, and gets the credentials for each.
- The agent connects to each server from Monte Carlo's cloud and lists its read-only tools.
- The LLM picks a tool. The agent calls your server and sends the result back to the LLM.
Credentials
- Stored encrypted: API keys, extra headers, and OAuth client secrets are stored encrypted in Monte Carlo's secret store. Monte Carlo never shows them again after you save them.
- Per-user OAuth tokens: For servers that use the authorization code (PKCE) method, each user's tokens are held by WorkOS, the OAuth service Monte Carlo uses for MCP. Monte Carlo fetches a user's token only when that user runs an agent.
- Never sent to the LLM: Credentials go only to your MCP server, in request headers. They are masked in Monte Carlo's logs and error reports.
- Per-user access: With the authorization code (PKCE) method, the agent acts with each user's own access in the other system. With None, API key, or client credentials, every user shares one identity.
- Revocation: Admins can revoke a user's connection in Monte Carlo, which deletes the stored tokens. Grants in the other system are revoked in that system.
Data Handling
What goes to the LLM
The LLM receives the names, descriptions, and input schemas of your read-only tools, the inputs the agent sends, and the results your server returns. This is processed by AWS Bedrock in Monte Carlo's AWS environment, like the rest of the conversation. AWS Bedrock does not store this data or use it for training.
Tool results are stored with the conversation
Tool results become part of the conversation. Monte Carlo stores them with the rest of the conversation traces for up to 30 days, then deletes them. They are used to answer follow-up questions.
| Data Type | Where It Lives | Duration | Used For |
|---|---|---|---|
| Server configuration | Monte Carlo platform | Until you delete the server | Connecting to your server |
| API keys and client secrets | Monte Carlo secret store, encrypted | Until you delete or replace them | Authenticating to your server |
| Per-user OAuth tokens | WorkOS | Until revoked or expired | Authenticating as each user |
| Tool results | Monte Carlo AWS environment, with conversation traces | Up to 30 days | Conversational features |
| LLM processing | AWS Bedrock | Transient only | Real-time AI inference |
Safeguards
- Read-only tools: Agents only call tools that your server marks as read-only with the MCP
readOnlyHintannotation. - Size and call limits: The Troubleshooting Agent cuts each tool result to 6,000 characters and limits how many tools it calls in each step.
- Customer isolation: Each account only sees its own servers. Each user only gets credentials for servers they are allowed to use.
Network
- Monte Carlo connects to your MCP server from Monte Carlo's cloud over HTTPS. The server must be reachable from the internet.
- Monte Carlo refuses URLs that resolve to private or reserved IP addresses.
- Monte Carlo sends only the requests needed to list tools and call them, plus the connection test when an admin clicks Test connection.
- If you set a user identity header, Monte Carlo sends the calling user's email or Monte Carlo user ID to your server in that header.
Your Responsibilities
Your MCP server and the systems behind it are not run by Monte Carlo. You control:
- Which tools the server exposes, and which ones it marks as read-only.
- What data each tool returns. Anything a tool returns is sent to the LLM and stored with the conversation.
- The scopes and permissions of the credentials you give Monte Carlo.
Updated 2 days ago
