Connect is Dokki's connection center. Use it to decide what is connecting, which direction data moves, who owns the connection, and which permissions apply before opening a module-specific setup guide.
Choose a Connect module
AI Clients
Use AI Clients when Claude, Codex, Cursor, another MCP client, or an automation needs to work with Dokki resources. The client connects inbound to Dokki through MCP and acts with the authorized user's or credential's Dokki permissions.
Direction: external AI client → Dokki.
Authentication: OAuth, tenant API Key, or a Workspace MCP Connector.
Typical work: search, read, create, edit, share, message, publish, and preview when authorized.
Open AI Clients for endpoints, client-by-client setup, capability details, verification, troubleshooting, and revocation.
Workspace MCP Connectors
Use a Workspace MCP Connector when an external client or automation must stay inside one fixed workspace and should not inherit a person's wider Personal or Organization access.
Direction: external client → one Dokki workspace.
Owner: a workspace admin creates and revokes the credential.
Flavors: Documents, Publish, or Memory.
Open Workspace MCP Connectors for creation, generated URLs, client configuration, verification, rotation, and permission boundaries.
MCP Apps
Use MCP Apps when Dokki Copilot or an Agent needs to use an external service such as GitHub, Slack, Gmail, a calendar, a drive, or an issue tracker through the authorizing user's connected account.
Direction: Dokki → external service.
Owner: the Dokki user who authorizes the external account.
Permissions: both Dokki access and the external provider's permissions must allow the task.
Open MCP Apps for authorization, account ownership, Copilot and Agent use, imports, confirmations, troubleshooting, and disconnecting.
Chat Channels
Use Chat Channels when people should send messages to the built-in Dokki Agent from a supported messaging service.
Direction: messaging service → Dokki Agent, with replies returning through the channel.
Purpose: conversations and notifications, not general MCP access to Dokki resources.
Open Chat Channels for connection steps, supported behavior, privacy boundaries, changes, and disconnection.
Do not mix the modules
An AI Client credential lets an external AI system call Dokki tools. It does not connect the user's GitHub, Gmail, Slack, or other SaaS account.
An MCP App lets Dokki use an external account. It does not grant that provider general access to Dokki.
A Chat Channel carries messages to and from the Dokki Agent. It is not an AI Client connection or an MCP App account.
An Agent's own MCP tab configures an external MCP server for that installed Agent. Manage it with the Agent's workspace access, skills, schedules, and run permissions.
Shared authorization model
Every connection is evaluated through multiple boundaries. A successful sign-in does not grant unlimited access.
Identify the direction and the acting client, user, or Agent.
Resolve the connection's tenant, selected workspace, fixed workspace, or external-account scope.
Apply current Dokki workspace membership and resource permissions.
Apply module-specific tool and action permissions.
For MCP Apps, apply the external provider's permissions as an additional boundary.
Require confirmation for consequential actions where the interface or tool requests it.
Connection lifecycle
Choose the correct module before creating a credential or authorizing an account.
Grant the smallest scope needed for the task.
Store tokens only in the client or approved secret store; never in documents, chats, Agent instructions, memory, or screenshots.
Start with a read-only test and verify the returned workspace, resource, or external account.
Test one permitted action and one expected denial so the boundary is visible.
Review recent use, schedules, and ownership periodically.
Revoke, disconnect, or rotate the connection when its owner, client, workspace, or purpose changes.
Where to start
Open Workspace → Extensions → Connect in Dokki. Choose AI Clients, Channels, or MCP Apps for the product flow. Workspace administrators manage fixed-workspace credentials under Connectors. Installed Agents manage dedicated external MCP servers from the Agent's MCP tab.
