Connect other MCP clients (Microsoft Foundry and generic)
StackJack works with any MCP client that supports Streamable HTTP transport (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). This page covers Microsoft…
Written By Christopher Scaminaci
Last updated 6 days ago
StackJack works with any MCP client that supports Streamable HTTP transport (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). This page covers Microsoft Foundry, which needs a credentialed connection, plus the reference values for wiring up any other client.
Microsoft Foundry
Foundry uses a credentialed project connection — it cannot register itself with StackJack, so there is no URL-only sign-in — so have an owner, co-owner, or Administrator create an MCP client or API key first (see Managing MCP credentials).
Give each Foundry project its own credential. Anyone with access to a Foundry project can read an API key stored in one of its project connections (Microsoft's own warning). So create a dedicated MCP client or API key for each Foundry project (or agent), restrict its tool selection to what that agent needs, and never reuse a person's credential or one another tool uses. When you rotate it in StackJack, update the Foundry project connection too: rotation stops the old secret on its next request.
Open your project and agent. In ai.azure.com, open (or create) a project and an agent.
Add a custom MCP tool. Go to Add Tools → Custom tab → Model Context Protocol → Create. Set the name (server label) and the server URL. Use the compact endpoint —
https://compact.stackjack.io/mcpfor a US workspace,https://compact-eu.stackjack.io/mcpfor an EU one — or a per-connector endpoint. Copy the exact address from MCP Setup; your workspace's region decides the hostname.Why compact first: Foundry sends the server's whole tool list — every name, description and parameter schema — to the model on every run, and the standard endpoint (
https://mcp.stackjack.io/mcpin the US,https://mcp-eu.stackjack.io/mcpin the EU) can serve hundreds or thousands of tools. Foundry'sallowed_toolslimits what the agent may call, but it was not shown to shrink that list. The compact endpoint always serves StackJack's small searchable catalog — with nothing to enable for your organization — and the agent finds and runs the rest on demand. A per-connector endpoint serves one connector's tools instead.Add the credential. Create a project connection with a credential name and value — either:
- name
Authorization, valueBasic <base64(CLIENT_ID:CLIENT_SECRET)>, or - name
X-API-Key, valuesjk_...
- name
Decide the approval setting deliberately.
require_approvalcontrols whether Foundry pauses for a human before the agent calls a StackJack tool. It is a real safety choice, not a setup step:- Keep approvals on while you are building and testing, and for any agent that can reach write or destructive tools. StackJack tools act on your live PSA, RMM, and documentation systems, and an approval prompt is the last point at which a person can stop a wrong call.
- Only turn approvals off for an agent you have deliberately narrowed first. If a run must be unattended, scope the agent to a specific, small set of tools with
allowed_tools, and give it a StackJack credential whose own tool selection is limited to what that job needs. Do both:allowed_toolsis the agent's setting, and the credential's tool selection is the boundary StackJack enforces.
Turning approvals off on an agent that can reach your whole catalog means every tool runs unattended, including destructive ones.
Write it as an object. Through the Foundry API and SDK,
require_approvalis an object, not a plain string:{"always": {}},{"never": {}}, or a per-tool list such as{"always": {"tool_names": [...]}}. The Foundry portal may show it as a toggle instead. Which tool names a per-tool list should hold depends on the endpoint:On the compact endpoint the agent reaches every connector tool through StackJack's catalog tools, so connector tool names never reach Foundry.
stackjack_run_toolruns any connector tool, including writes and destructive ones;stackjack_run_readonly_toolruns read-only tools only;stackjack_search_toolsandstackjack_describe_toolsonly read the catalog. The compact endpoint also lists StackJack's own platform tools, and some of those write too. So let only the read-only tools run without a prompt, and leave everything else to approval:{ "never": { "tool_names": [ "stackjack_describe_agent_schema", "stackjack_describe_tools", "stackjack_get_agent_config", "stackjack_get_agent_definition", "stackjack_get_agent_run", "stackjack_get_catalog_mode", "stackjack_get_doc_page", "stackjack_get_quota_status", "stackjack_get_release_notes", "stackjack_get_run_transcript", "stackjack_get_service_status", "stackjack_get_support_ticket", "stackjack_get_tool_catalog", "stackjack_get_tool_guidance", "stackjack_health_check", "stackjack_inspect_agent", "stackjack_list_advisories", "stackjack_list_agent_configs", "stackjack_list_connections", "stackjack_list_support_tickets", "stackjack_list_tools", "stackjack_run_readonly_tool", "stackjack_search_docs", "stackjack_search_tools", "stackjack_session_info", "stackjack_suggest_agent_tools" ] } }Every tool not in that list asks for approval:
stackjack_run_tool, and StackJack's own write tools — for examplestackjack_run_agent(it starts an automation run),stackjack_delete_agentandstackjack_set_agent_lifecycle. That relies on Foundry treating a tool it finds in no list asalways, which Microsoft documents as the default. Confirm it once in a test run — ask the agent to call a write tool and check that Foundry asks first — and if it does not ask, use{"always": {}}instead.On a per-connector endpoint the connector's real tool names are served, together with StackJack's platform tools. Use the same shape: add that connector's read-only tools to the
neverlist above, and every write and destructive tool — the connector's and StackJack's own — asks for approval.
Generic MCP client reference
For any other MCP client, these are the values you need:
Notes:
- Prefer the sign-in path wherever the client supports it — no secrets to store, and access follows your team membership. See How AI tools authenticate.
- A credential only works in its own lane: an API key cannot be sent as Basic auth, and a Client ID + Secret cannot be sent as an API key.
- If the client rejects the connection with a 401 that mentions OAuth metadata, that's normal discovery behavior — it means the client found StackJack but hasn't authenticated yet.
A separate URL per connector
A common ask for generic clients is "give this one client its own URL so it only sees one thing." There is one supported way to do that, one legacy way to serve a smaller catalog, and one form that looks right and is not.
The supported answer: a per-connector endpoint
StackJack can serve a per-connector endpoint — a hostname that serves one connector's tools plus the StackJack platform tools, instead of your whole catalog. That is the right building block for a client-per-connector setup: one URL for HaloPSA, one for NinjaOne, one for CIPP, each configured in its own client or its own agent.
- Get the URL from the portal. When per-connector endpoints are available to your workspace, MCP Setup lists them beneath the standard and compact endpoint cards, one copyable URL per connector you are subscribed to. If the list is not there, per-connector endpoints are not published for your workspace yet, and the standard endpoint keeps serving everything as it always has.
- The shape.
https://{slug}.mcp.stackjack.io/mcpfor the US region andhttps://{slug}.mcp-eu.stackjack.io/mcpfor the EU region, where{slug}is the connector's short name —halo,cipp,ninjarmm,connectwise,msgraph, and so on. Copy it rather than typing it: an address that has not been published for your region does not resolve at all. - Nothing else about the client changes. Same transport, same sign-in or credential, same headers as the table above.
Point one MCP client at this URL to get only this connector's tools. Your tool selection and subscriptions are unchanged.
And the limit of what it does, which matters most on a page like this one:
The connector host is a serving profile, not a credential restriction;
AllowedTools+ subscriptions remain the only restriction boundary.
A per-connector URL decides what StackJack shows a cooperating client. It is not a fence: the same credential still works on https://mcp.stackjack.io/mcp and still gets everything it is permitted to call. When you need a genuine limit, restrict the MCP client credential's tool selection or the person's tool roles — How do I narrow a connection? lays the options side by side. Full detail on the endpoints themselves is in Per-connector endpoints.
The legacy note: the ?tools= parameter
The one query parameter you can add to a StackJack server URL is ?tools= — for example https://mcp.stackjack.io/mcp?tools=compact. Be precise about what it does: ?tools= selects a catalog mode (compact, minimal, or full), which controls how many tools StackJack serves. It has never selected a connector, it takes effect only once an administrator has enabled catalog modes for the organization, and it applies only on your standard endpoint address — a serving-profile address such as the compact endpoint always serves its own catalog and ignores the parameter.
It still works, and clients already configured with it keep working — nothing here withdraws that. But no new client should be configured with it: several harnesses strip or reject query strings on an MCP server URL (Microsoft Copilot Studio has no room for one at all), so a setting that silently disappears is a poor place to put configuration. Use a per-connector endpoint, or the compact endpoint, or set the mode in the portal instead. See Overriding per connection with .
?connector= is not a form that works
There is no ?connector= parameter, and adding one to your URL does not narrow anything. StackJack tolerates query parameters it does not recognize, so https://mcp.stackjack.io/mcp?connector=halo connects normally and returns your full tool catalog — exactly the opposite of what someone typing it is asking for, and with no error to reveal the mistake. Do not put it in a client configuration, and if you find it in an existing one, replace it with a per-connector endpoint URL.
Tool limits
Whatever the client, keep the tool list purposeful: StackJack can expose hundreds of tools depending on your connectors and plan. Use a client credential with a restricted tool selection (and the harness's own tool filtering, like Foundry's allowed_tools), point the client at a per-connector endpoint, or switch StackJack to compact catalog mode so it serves a small tool list and the client discovers the rest on demand. On the standard endpoint an admin must first enable catalog modes for your organization on the Settings page; until then StackJack serves the full tool list there. The compact endpoint address needs nothing enabled: it always serves the small catalog. See Choosing tools for each client and managing harness tool limits.
Troubleshooting
See Connection troubleshooting for the common failure signatures across all clients.