MCP Hub
Connect MCP servers.
Govern every tool call.
Discover external MCP tools, encrypt their credentials, scope them to the right bots, enforce per-tool policy, and investigate every production outcome from one control plane.
13
built-in catalog entries
3
supported transports
5
authentication modes
3
permission states
MCP Hub starts on Lite and manages servers your Rylvo bots call. Rylvo's separate authenticated /mcp endpoint exposes workspace tools to AI editors.
From server to governed tool
Control the path, not just the connection.
Discovery, credentials, bot scope, policy, guardrails, invocation, and production operations live in one managed lifecycle.
One governed path from bot to tool
scope → policy → transport → audit
Scoped Rylvo bot
Only active, global or linked servers enter its turn.
External MCP server
HTTP, SSE, or stdio through the configured runner.
Choose or propose
Use the built-in catalog, search remote entries from the official MCP Registry, connect a custom server, or submit one for admin review.
Authenticate
Use no auth, API key, bearer token, OAuth 2.1, or a custom header. Secrets are encrypted before persistence.
Discover
Run tools/list against the live server and store its tool descriptions and input schemas.
Scope
Link the server to selected bots or make it global. Unassigned servers remain unreachable to bots.
Govern
Allow, deny, or require approval per tool, with optional per-bot overrides and guardrail checks.
Operate
Inspect health, calls, latency, attributed cost, denials, approvals, schema drift, and anomalies.
Find, connect, approve
Use the catalog—or bring your own server.
Start from built-in entries, search the official MCP Registry, or establish an organization-specific connection.
MCP HUB / SERVERS
1 APPROVAL PENDINGTool permissions · support-bot
customers.search
readautoinvoices.list
readautorefunds.create
writeapprovalsubscriptions.cancel
writedeniedrefunds.create · awaiting approval
support-bot · $240.00 · order NS-40912
13 built-in entries
10 carry the Rylvo Verified label; three aggregator entries are Community. Installation still requires auth, scope, and activation.
Official Registry browser
Search the official MCP Registry and prefill supported remote HTTP or SSE endpoints into the external-server form.
Custom and submitted
Admins connect custom servers directly; team proposals can become approved, organization-specific catalog entries.
Transport reality
Three transports, two hosted paths.
HTTP and SSE execute against remote endpoints. Production stdio requires the isolated MCP runner; without it, the runtime returns a structured configuration error.
HTTP
Streamable hosted path
SSE
Legacy event-stream response
stdio
Production runner required
Policy at tool granularity
The server connects. You decide what runs.
Resolve policy per tool and per bot, then evaluate arguments and results against the bot’s guardrails.
Allow
Expose the tool to the scoped bot and run it without operator review, subject to guardrails and runtime limits.
Require approval
Interactive dashboard chat creates a review request with the arguments and model rationale before execution resumes.
Deny
Hide the tool from the bot. Automated API and channel surfaces also block tools that require interactive approval.
Interactive approval path
Request
Gate
Queue
Review
Resume
Automated API and channel surfaces reject approval-required tools instead of pretending to pause.
Five authentication modes
Persisted secrets use AES-256-GCM and return only a masked hint to the UI.
Production operations
Catch failures and post-install changes.
Health probes, rediscovery, schema checks, rollups, and anomalies keep the connection observable after its first successful call.
30-minute health checks
Active HTTP and SSE servers receive tools/list probes. Three consecutive failures open a deduplicated outage alert.
Six-hour rediscovery
New tools appear, removed tools are retained as undiscovered, and schemas refresh without deleting policy history.
Schema-drift alerts
Breaking input-schema changes and removed tools are surfaced for operator review after installation.
Append-only call records
Filter success, failure, block, and timeout outcomes; inspect previews and export the current view as CSV.
Usage analytics
Seven- and thirty-day views cover calls, failure rate, denials, latency, and operational cost attribution.
Anomaly alerts
Hourly checks detect cost spikes, failure-rate spikes, and approval backlogs; stale approvals expire automatically.
Three MCP directions
Related concepts. Different boundaries.
Rylvo calls external servers, exposes workspace tools to authenticated editors, and composes bots internally—through distinct paths.
Rylvo bot → external MCP
Outbound: MCP Hub
Discover external tools, scope and govern them, then record each invocation outcome.
AI editor → 129 Rylvo tools
Inbound: Rylvo /mcp
OAuth-protected Streamable HTTP lets registered clients manage workspace resources.
Rylvo bot → protected Rylvo bot
Internal: bot export
Expose a bot-turn tool and optional KB search behind the production internal secret.
Availability & limits
MCP Hub starts on Lite.
Server count and attributed MCP cost are plan controls. Attribution is not a vendor invoice or wallet debit.
Free
Not included
—
Lite
5 servers
$25 attributed cost cap
Pro
Unlimited
$100 attributed cost cap
Team
Unlimited
$250 attributed cost cap
Enterprise
Unlimited
Unlimited cap
Free, Low, Medium, and High tools attribute $0, $0.001, $0.005, or $0.01 per successful call for MCP operations.
View full pricingClear expectations
What MCP Hub does—and does not do.
Direct answers about transport, approvals, credentials, bot export, and cost attribution.
What exactly does MCP Hub manage?
MCP Hub manages the outbound direction: external MCP servers that Rylvo bots call. It keeps transport, auth references, discovered tools, bot scope, permissions, health, approvals, call records, and analytics together.
Which MCP transports work?
Hosted HTTP and SSE servers run directly. stdio runs through the separately deployed MCP runner in the production engine; without that runner, hosted stdio calls return a structured error. Supported dashboard server environments also have an allowlisted stdio bridge.
Does Require approval work on every channel?
No. Interactive dashboard conversations can pause and resume after an operator decision. Public API, channel, and webhook invocations reject approval-required tools because those surfaces cannot hold an interactive approval session.
How are credentials stored?
A secret is submitted to a server route, encrypted with AES-256-GCM, and only ciphertext, IV, auth tag, metadata, and a masked last-four hint are persisted. The server decrypts it for discovery, health, OAuth refresh, or invocation; the UI cannot read the plaintext back.
Can I expose a Rylvo bot as an MCP server?
Yes, for internal composition. Bot export creates a protected internal MCP endpoint with a bot-turn tool and, when knowledge is linked, a KB-search tool. Production access requires the internal export secret, so this is not a public third-party endpoint.
How is the 129-tool Rylvo endpoint different?
Rylvo’s authenticated /mcp endpoint is the inbound direction used by Architect and AI editors to manage a workspace through 129 Rylvo tools. MCP Hub is primarily the outbound control plane for tools Rylvo bots call.
Does MCP cost attribution charge my wallet?
No. Tools are tagged Free, Low, Medium, or High for operational attribution and plan-budget enforcement. BYOK provider charges remain with your provider, and this attribution does not emit a Rylvo wallet debit.
Connect deliberately
Make every MCP tool visible, scoped, and accountable.
Register the server, discover live tools, set policy per bot, and operate the connection through schema drift.
