MCP servers
Give the agent your tools, not your keys.
Connect Linear, Sentry, Supabase or your own MCP server and every fleet run can use it. Talyn holds the credential and attaches it per request from outside the sandbox, so the agent never sees a token it could leak.
- Linear, Sentry, Supabase, Stripe, or any remote MCP server you run
- The credential stays with Talyn — the sandbox gets a plain URL with no token on it
- A per-server tool allow-list, so a server can be connected without being fully exposed
- Uncapped on every plan, including free
Running 1
Fix CI #412
12s ago · Working
Queued 1
Reply review #418
PostHog Code
Fix failing CI
An agent fixing a bug should be able to read the bug
A run that is responding to a review comment referencing a Linear ticket, or fixing a crash that has a Sentry issue, is working with one hand tied behind its back if it cannot open either. MCP is the standard answer to that, and connecting one to a cloud sandbox is where it usually gets uncomfortable.
The uncomfortable part is the credential. Handing your Linear API key to a machine that is about to check out a repository and execute code from it is a bet on that code being friendly.
Talyn holds the credential, and the sandbox never does
The guest is configured with a plain URL that carries no token at all. When the agent calls a tool, the request goes to the host's proxy, and the proxy attaches the secret on the way out. An agent that has just read a hostile repository and decided to exfiltrate your Linear key has nothing in its environment to find.
This is the same shape as how your Claude or ChatGPT subscription token is handled on the fleet, and for the same reason. There is exactly one function in the codebase that decrypts a stored MCP secret, and it runs on the host.
Running 1
Fix CI #412
12s ago · Working
Queued 1
Reply review #418
PostHog Code
Fix failing CI
Per-server tool allow-lists, and no arbitrary caps
Some servers expose a lot of tools, and not all of them should be reachable from a coding agent. So each connected server can carry an allow-list: exactly these tools, nothing else.
What there is not is a cap on how many servers a run may use, or how many tools a server may expose. Those were considered and dropped — they were round numbers with no reasoning behind them, and the allow-list gives you the same saving as a deliberate choice rather than an arbitrary ceiling. The one limit that stays is a 64-character tool name, because that is a hard provider limit and an over-long name fails the whole request rather than one call.
- All tools, a chosen subset, or none — three distinct states, and none of them is guessed
- Remote streamable HTTP servers, over HTTPS
- OAuth servers connect with PKCE; API-key servers store the key sealed
Free on every plan, deliberately
Tasks, queued pull requests, workflows and loops all have a free-plan cap. MCP servers do not, on any plan. A connected server costs nothing until a run uses one, and what a run costs is already bounded by the task cap — so charging for the connection would be charging twice for the same thing.
Fleet only
This works on Talyn Fleet, which is where the proxy that holds your credentials lives. PostHog Code has no equivalent, so the option is hidden there and refused by the API if something asks anyway.
Questions, answered.
Any remote streamable HTTP server over HTTPS — Linear, Sentry, Supabase, Stripe, or one you run yourself. There is a catalogue of common ones to save you finding the URL. Local stdio servers are not supported, because the sandbox is not your machine.
No. The sandbox is given a plain URL with no credential on it, and the host's proxy attaches the secret per request from outside the machine. That is the whole design.
Yes, per server. Leave it unset for all tools, choose a subset, or choose none. Those are three genuinely different states and Talyn does not collapse them — reading an empty list as 'all' would make 'run this with no tools' the one thing you could not ask for.
No, and there is no cap. A connected server spends nothing until a run uses it, and the run is already bounded by the task limit.
No, it is Talyn Fleet only. The credential-attaching proxy is part of the fleet.
Talyn does this for you.
Mission control for your GitHub pull requests, running on the Claude or ChatGPT subscription you already pay for. Free for three tasks at a time.