> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mesh.texturehq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Add a capability

> Connect a provider, choose capabilities, and resolve missing setup requirements.

Open an agent’s **Tools** page to see native tools, remote MCP accounts, and web
capabilities in one searchable catalog. Choose **Add capability** to open the
library, or **Manage** on an existing entry. Existing connections do not require
re-entering their saved credentials.

All acting accounts belong to the selected agent. See the
[identity guardrail](https://github.com/TextureHQ/mesh/blob/main/docs/roadmap.md#agent-owned-acting-identities). Connecting another
agent requires that agent’s own external account; a new token for the same account
does not create a new identity. No shared acting-account selector is offered.

## Native tools

The package supplies configuration fields, credential requirements, operation
descriptions, and operation classes. Enter a credential only to connect or rotate
it; leaving the field blank keeps the stored credential. Secret values are never
read back. Choose **Save capability** to make the configured tools available.
All supported operations are on by default. Open **Manage tools** to turn off
specific operations; saved exclusions survive credential rotation.

GitHub API operations and coding/workspace operations are individually selectable
and labeled. Under **Coding account access**, this agent's own GitHub or GitLab
PAT is usable in its own sandbox by default. Turn off delivery there if needed.
Existing explicit opt-outs stay off. Permission changes
and token rotation invalidate active sandboxes, including continuation-held ones.
See [sandbox credential delivery](/runtime/workspace-credentials) for revocation and
long-lived-token limitations. A default repository does not restrict a shell to
that repository. The runtime card shows the effective instance or agent backend
and links to its settings. Each agent has its own sandbox even when agents share
an instance's execution provider billing key.

Native saves validate configuration and credential presence, not live access to
the provider. The page says when credentials are stored but access is untested.
Operations are saved individually. If a later operation fails, earlier saves may
have succeeded; use **Reload capabilities** to inspect current state before retrying.

GitLab.com coding is available in the same library and editor; see
[GitLab coding](https://github.com/TextureHQ/mesh/blob/main/docs/runtime/gitlab-coding.md) for supported credentials and workflows.

## Model defaults

New agents automatically use configured instance model credentials and model
assignments. The wizard shows the inherited model and continues to memory setup.
Choose **Customize models** to use a separate provider or billing key. Resuming an
existing agent keeps its saved provider choice.

## Remote MCP accounts

Choose a library preset or **Custom MCP**, then choose **API key** or
**Sign in with OAuth**. Presets supply an endpoint and suggested authentication;
you can change them to match your server. OAuth returns to this agent's tools page.

Connecting automatically discovers and activates every supported tool, including
writes. There is no second enablement or Read/Write classification step. Discovery
checks communication and definitions; the server's account permissions determine
which operations can succeed. If discovery fails, credentials stay saved, catalog
health explains the failure, and Mesh retries automatically.

Use **Manage tools** to turn individual tools off, then **Save tool preferences**.
Saving an empty selection is allowed. Exclusions survive catalog refreshes,
changed definitions, removed/reappearing tools, credential rotation, and OAuth
reconnection. New tools turn on automatically. **Turn off** stops the whole
connection immediately without contacting the server; reconnecting keeps an
explicit turn-off until you choose **Turn on**.

Manage an existing account to rotate its token, reconnect OAuth, or inspect catalog
health. Version checks reject stale edits. A new account at an existing endpoint
keeps the other accounts and their credentials unchanged.

## Web access

Search, content reading, and browser interaction use the same descriptor-driven
provider editor. Infrastructure credentials use live instance defaults automatically. Choose
**Customize** for an agent override, **Turn off** for an explicit opt-out, or
**Use instance settings** to restore inheritance. The page shows effective provider, credential source, availability,
and request limits. Saving validates configuration; it does not run a paid query
or browser session to test the provider.

Provider billing keys are infrastructure. Website logins, cookies, and authenticated
browser profiles remain agent-owned and cannot be inherited through this form.

## Moving a native integration to its MCP server

Some services are reachable both ways. Linear ships as a compiled package and as
a bundled MCP preset under the same integration, so one agent can run either or
both while you compare them. Nothing transfers automatically: an acting account
belongs to the agent, so you supply that agent's MCP credential yourself. The
supported tools become available automatically. The native credential is a
different audience and is never offered as the MCP one.

[Migrating Linear](https://github.com/TextureHQ/mesh/blob/main/docs/runtime/linear-migration.md) has the step-by-step path, the rollback,
and what changes for the agent afterwards. It is also the template for any later
native retirement.

## Compatibility and extension

The UI uses the [connection management API](/runtime/connection-management). Package-less
registry tools remain visible and use their existing agent-scoped enablement API;
they are not fabricated server connection records. No credentials are copied and
the setup UI itself requires no migration. Sandbox delivery records automatic defaults separately from operator choices;
the migration preserves all existing permission rows.

Native package manifests and web provider descriptors supply their editor fields.
For an MCP service using existing bearer or OAuth authentication, add preset
metadata in `internal/integration/mcp_presets.json`; no new service-specific form is
needed. A new authentication or transport mechanism still needs adapter support.

For rollback, append `?tools=legacy` to `/agents/{slug}/tools`, or follow **Use legacy
tools setup**. Both views read and write the same authoritative stores. The flag
changes presentation only; it cannot change access policy. OAuth always returns
to the unified page, where the same account remains manageable.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.