mcp.servers in config, and the tools they expose go through the same tool-profile and tool-policy controls as everything else — connecting a server does not bypass your policy.
This guide is about connecting third-party MCP servers to OpenClaw. For the reverse — exposing OpenClaw channel conversations to another MCP client — use
openclaw mcp serve.Add a server from Settings
- Open the Control UI and go to Settings → MCP.
- Under Configured servers, select Add server.
- Give it a unique name and pick a transport: Streamable HTTP, SSE, or Stdio.
- For the HTTP transports, enter the server’s
http://orhttps://URL. For stdio, enter the command followed by its arguments. - Select Add server.
mcp.servers entry through the Gateway. For anything beyond the basics — headers, environment values, OAuth metadata, TLS settings, timeouts, parallel-tool-call hints, tool filters — use the scoped config editor further down the page. The server rows also let you enable, disable, or remove a definition.
Once the server is saved, verify it actually answers:
Add a server from the CLI
A local stdio server:openclaw mcp status --verbose for a config-only summary, openclaw mcp probe <name> for live capabilities, and openclaw mcp login <name> when an HTTP server uses OAuth. The MCP CLI reference documents every command, flag, and output shape, plus the separate mcp serve bridge.
Configure a server directly
The samedocs server, written straight into config:
enabled: false keeps the definition around without connecting it. Keep credentials out of config literals — store sensitive headers and environment values through the supported secret mechanisms.
Troubleshooting
The server appears in Settings but exposes no tools
Runopenclaw mcp doctor <name> --probe. Doctor validates the saved definition first, then opens a live connection and reports the tools and other capabilities the server advertises. If it connects but expected tools are missing, check toolFilter.include and toolFilter.exclude.
A stdio server does not start
Confirm thecommand resolves in the Gateway process environment and that cwd exists. Arguments belong in args, and an explicit transport: "stdio" requires a non-empty command.
An HTTP server needs authorization
Setauth: "oauth" plus any required oauth metadata, then:
--code when prompted.
Changes do not reach an active agent
openclaw mcp reload refreshes runtimes owned by the current CLI process. A Gateway or agent running elsewhere needs its own reload, config publish, or restart.