- Create an agent identity for Pavo in MintMCP.
- Check what the identity can see behind the gateway.
- Connect in Pavo.
1. Create an agent identity (MintMCP)
In MintMCP, open the gateway Pavo should use, then Agent identities → Create:- Name it e.g. pavo.
- Attach the connections Pavo may use, and switch off any tools it should not see.
- On the identity’s Agent Setup tab, copy the MCP Server URL. It ends in
/mcp. - Pick one authentication method:
- Agent key: Create key, and copy the key. It is shown only once.
- M2M client: Create M2M client, and copy the client ID, the client secret, and the Token endpoint. Pavo exchanges them for short-lived access tokens on its own.
2. Check what the identity can see
The gateway forwards Pavo’s calls under the permissions of each connection you attached, so Pavo sees exactly what those connections can see, nothing more. Before you connect:- Make sure each attached connection is authorized against the systems, repositories, or datasets you want Pavo to read, with read-only access. Anything the connection cannot see stays out of scope.
- Make sure each connection can actually be called through the gateway. Some MCP servers need an extra permission or role for that on top of the usual read access; check the setup notes for the connection in MintMCP.
- Try a read-only tool from MintMCP’s test panel with this identity. If it works there, it works for Pavo. Tools the gateway marks destructive or not read-only are refused by Pavo even when the identity may call them.
3. Connect in Pavo
- Go to Pavo → Settings → Add connectors.
- Click MintMCP and choose the card for your authentication method.
- Enter the MCP Server URL from Step 1.
- Enter the agent key (Agent key card), or the client ID, client secret, and Token endpoint (M2M client card).
- Click Connect.