Hive connects to MCP servers. It does not publish its own MCP server for other AI tools to
call.
Official servers: one-click connect
These vendor-hosted servers are verified to work with Hive and connect with OAuth in one click:
Find them on the provider’s tile in Integrations → Connectors. Tools that offer both OAuth
and MCP (Notion, Linear, Stripe) show one tile with a choice of connect method.
Connect a custom server
1
Open Add a connector
In Integrations → Connectors, select Add integration, then Custom MCP server —
“Any Model Context Protocol server by URL.”
2
Enter the server details
Give the server a name and its URL. The URL must be
https://. Hive speaks Streamable
HTTP only; it never runs local stdio servers.3
Choose how it authenticates
- No auth — a public server with no sign-in.
- Bearer token — paste a static token. Hive seals it in its vault; it is never stored on the connection record or shown again.
- OAuth 2.1 — OAuth 2.1 with PKCE and dynamic client registration. Optionally list the scopes to request, space or comma separated. You are sent to the server’s sign-in page and returned to Hive.
4
Let Hive discover the tools
Once connected (status Live), Hive lists the server’s tools and pins each one. The server
appears under the Built by me filter.
How Hive keeps MCP tools safe
MCP servers are third-party code, so Hive treats every tool as untrusted until you decide otherwise:- Tools are pinned. Hive records a fingerprint of each tool’s name, description and input schema when it discovers it. If a server later changes a tool behind your back — the “rug-pull” attack — the change is caught rather than silently trusted. Malformed tools are skipped with a reason.
- Tools are namespaced per connection, so two servers can never collide or impersonate each other.
- High-risk by default. Every MCP tool starts as blast radius B3 (external, hard to reverse), not reversible and not read-only. Hive ignores a server’s own claim that a tool is read-only; only an operator override can lower the tier.
- Reads vs writes. On the audited official servers, Ask may call read tools automatically while answering your question. On custom servers, reads — and on every server, all writes — go through approval.
- Secrets are sealed. Bearer and OAuth tokens are encrypted in Hive’s vault and never given to the model.
Statuses
Resync and disconnect
- Re-sync re-runs discovery and re-pins the server’s tools — use it after the server adds or changes tools you want to use. Only the connection’s owner can resync.
- Disconnect drops the connection, its pinned tools and all of its sealed secrets.
Related
Incoming webhooks
Push events from any system.
Security overview
How Hive keeps actions safe.