Skip to main content
Connect your MintMCP gateway to let Pavo’s agents use the tools your MintMCP admin exposes, for example GitHub and BigQuery, without handing Pavo any of those systems’ credentials. Pavo connects with one agent identity you create for it, calls only tools marked read-only, and reads the gateway live on demand. Nothing is synced or copied into Pavo ahead of time. Three steps, ~10 minutes, done by a MintMCP admin:
  1. Create an agent identity for Pavo in MintMCP.
  2. Check what the identity can see behind the gateway.
  3. Connect in Pavo.

1. Create an agent identity (MintMCP)

In MintMCP, open the gateway Pavo should use, then Agent identities → Create:
  1. Name it e.g. pavo.
  2. Attach the connections Pavo may use, and switch off any tools it should not see.
  3. On the identity’s Agent Setup tab, copy the MCP Server URL. It ends in /mcp.
  4. Pick one authentication method:
    • Agent key: Create key, and copy the key. It is shown only once.
    • M2M client: Create M2M client, and copy the client ID, the client secret, and the Token endpoint. Pavo exchanges them for short-lived access tokens on its own.

2. Check what the identity can see

The gateway forwards Pavo’s calls under the permissions of each connection you attached, so Pavo sees exactly what those connections can see, nothing more. Before you connect:
  • Make sure each attached connection is authorized against the systems, repositories, or datasets you want Pavo to read, with read-only access. Anything the connection cannot see stays out of scope.
  • Make sure each connection can actually be called through the gateway. Some MCP servers need an extra permission or role for that on top of the usual read access; check the setup notes for the connection in MintMCP.
  • Try a read-only tool from MintMCP’s test panel with this identity. If it works there, it works for Pavo. Tools the gateway marks destructive or not read-only are refused by Pavo even when the identity may call them.

3. Connect in Pavo

  1. Go to Pavo → Settings → Add connectors.
  2. Click MintMCP and choose the card for your authentication method.
  3. Enter the MCP Server URL from Step 1.
  4. Enter the agent key (Agent key card), or the client ID, client secret, and Token endpoint (M2M client card).
  5. Click Connect.
Pavo opens a session to the gateway right away and lists the tools it exposes. If the gateway rejects the credential, nothing is saved and you see an error; fix the identity in MintMCP and try again. Questions or need any help? Reach out and we’ll help you set it up.