search_issues, lookup_order) and runs them when asked. Many products ship one, and you can write your own.
When you give an agent an MCP tool, Orca connects to that server, discovers its tools, and lets the model call them. Unlike function tools, your application does not need to be online to answer: Orca calls the MCP server directly.
How it fits together
Two pieces work together:- The agent lists the MCP server’s URL and, optionally, which of its tools the model may use.
- A vault credential holds the server’s access token, if it needs one. You attach the vault to the session. The token is never shown to the model.
Before you start
- Remote MCP servers are currently blocked on hosted Orca; see the note above.
- Get a token for the MCP server if it requires authentication. An admin stores it in a vault.
Example
Examples on this page assumeclient is an OpenAI client configured as in the quickstart.
This creates a vault and credential for the server, an agent that may use one of its tools, and a session that uses both.
The tool definition
Put tokens in a vault, never in the agent. Orca rejects agents whose MCP
headers contain Authorization, Cookie, or similar secret headers.
What happens at runtime
- At session start, Orca connects to each MCP server and fetches its tool list. If a server is unreachable, or a credential it needs is missing, session creation fails with an error instead of starting a broken session.
- During a turn, each call is recorded as an
mcp_callitem in the history, with its arguments and result. Use these to audit what the agent did. - The calls come from the Orca server by default, not from your application. To make them from inside the session’s sandbox instead, for example to reach a server that only the sandbox’s network can see, set
"connection_origin": "environment"on the tool. That requires a session with a sandbox.
Keep it safe
- Allow only what is needed. Use
allowed_tools, and prefer read-only tools. Add write tools only when the task requires them. - Treat results as untrusted. An MCP server can return any text, including text that tries to give the model new instructions. Do not give an agent that reads untrusted content access to dangerous tools.
- Scope credentials tightly. Each credential works only for its exact server URL. Use tokens with the smallest permissions the server supports.
Troubleshooting
See also: credentials and vaults, runnable MCP examples, and the vault reference.