RylvoRylvo

MCP Hub

Connect MCP servers.
Govern every tool call.

Discover external MCP tools, encrypt their credentials, scope them to the right bots, enforce per-tool policy, and investigate every production outcome from one control plane.

13

built-in catalog entries

3

supported transports

5

authentication modes

3

permission states

MCP Hub starts on Lite and manages servers your Rylvo bots call. Rylvo's separate authenticated /mcp endpoint exposes workspace tools to AI editors.

From server to governed tool

Control the path, not just the connection.

Discovery, credentials, bot scope, policy, guardrails, invocation, and production operations live in one managed lifecycle.

One governed path from bot to tool

scope → policy → transport → audit

Scoped Rylvo bot

Only active, global or linked servers enter its turn.

Registrylifecycle · scope · inventory
Policypermission · guardrails
Vaultencrypted auth · OAuth
Operationshealth · logs · alerts

External MCP server

HTTP, SSE, or stdio through the configured runner.

01

Choose or propose

Use the built-in catalog, search remote entries from the official MCP Registry, connect a custom server, or submit one for admin review.

02

Authenticate

Use no auth, API key, bearer token, OAuth 2.1, or a custom header. Secrets are encrypted before persistence.

03

Discover

Run tools/list against the live server and store its tool descriptions and input schemas.

04

Scope

Link the server to selected bots or make it global. Unassigned servers remain unreachable to bots.

05

Govern

Allow, deny, or require approval per tool, with optional per-bot overrides and guardrail checks.

06

Operate

Inspect health, calls, latency, attributed cost, denials, approvals, schema drift, and anomalies.

Find, connect, approve

Use the catalog—or bring your own server.

Start from built-in entries, search the official MCP Registry, or establish an organization-specific connection.

MCP HUB / SERVERS

1 APPROVAL PENDING

Tool permissions · support-bot

customers.search

readauto

invoices.list

readauto

refunds.create

writeapproval

subscriptions.cancel

writedenied

refunds.create · awaiting approval

support-bot · $240.00 · order NS-40912

ApproveDeny

13 built-in entries

10 carry the Rylvo Verified label; three aggregator entries are Community. Installation still requires auth, scope, and activation.

Official Registry browser

Search the official MCP Registry and prefill supported remote HTTP or SSE endpoints into the external-server form.

Custom and submitted

Admins connect custom servers directly; team proposals can become approved, organization-specific catalog entries.

Transport reality

Three transports, two hosted paths.

HTTP and SSE execute against remote endpoints. Production stdio requires the isolated MCP runner; without it, the runtime returns a structured configuration error.

HTTP

Streamable hosted path

SSE

Legacy event-stream response

stdio

Production runner required

Policy at tool granularity

The server connects. You decide what runs.

Resolve policy per tool and per bot, then evaluate arguments and results against the bot’s guardrails.

Allow

Expose the tool to the scoped bot and run it without operator review, subject to guardrails and runtime limits.

Require approval

Interactive dashboard chat creates a review request with the arguments and model rationale before execution resumes.

Deny

Hide the tool from the bot. Automated API and channel surfaces also block tools that require interactive approval.

Interactive approval path

Request

Gate

Queue

Review

Resume

Automated API and channel surfaces reject approval-required tools instead of pretending to pause.

Five authentication modes

None
API key
Bearer token
OAuth 2.1 + refresh
Custom header

Persisted secrets use AES-256-GCM and return only a masked hint to the UI.

Production operations

Catch failures and post-install changes.

Health probes, rediscovery, schema checks, rollups, and anomalies keep the connection observable after its first successful call.

30-minute health checks

Active HTTP and SSE servers receive tools/list probes. Three consecutive failures open a deduplicated outage alert.

Six-hour rediscovery

New tools appear, removed tools are retained as undiscovered, and schemas refresh without deleting policy history.

Schema-drift alerts

Breaking input-schema changes and removed tools are surfaced for operator review after installation.

Append-only call records

Filter success, failure, block, and timeout outcomes; inspect previews and export the current view as CSV.

Usage analytics

Seven- and thirty-day views cover calls, failure rate, denials, latency, and operational cost attribution.

Anomaly alerts

Hourly checks detect cost spikes, failure-rate spikes, and approval backlogs; stale approvals expire automatically.

Three MCP directions

Related concepts. Different boundaries.

Rylvo calls external servers, exposes workspace tools to authenticated editors, and composes bots internally—through distinct paths.

Rylvo bot → external MCP

Outbound: MCP Hub

Discover external tools, scope and govern them, then record each invocation outcome.

AI editor → 129 Rylvo tools

Inbound: Rylvo /mcp

OAuth-protected Streamable HTTP lets registered clients manage workspace resources.

Rylvo bot → protected Rylvo bot

Internal: bot export

Expose a bot-turn tool and optional KB search behind the production internal secret.

Availability & limits

MCP Hub starts on Lite.

Server count and attributed MCP cost are plan controls. Attribution is not a vendor invoice or wallet debit.

Free

Not included

Lite

5 servers

$25 attributed cost cap

Pro

Unlimited

$100 attributed cost cap

Team

Unlimited

$250 attributed cost cap

Enterprise

Unlimited

Unlimited cap

Free, Low, Medium, and High tools attribute $0, $0.001, $0.005, or $0.01 per successful call for MCP operations.

View full pricing

Clear expectations

What MCP Hub does—and does not do.

Direct answers about transport, approvals, credentials, bot export, and cost attribution.

What exactly does MCP Hub manage?

MCP Hub manages the outbound direction: external MCP servers that Rylvo bots call. It keeps transport, auth references, discovered tools, bot scope, permissions, health, approvals, call records, and analytics together.

Which MCP transports work?

Hosted HTTP and SSE servers run directly. stdio runs through the separately deployed MCP runner in the production engine; without that runner, hosted stdio calls return a structured error. Supported dashboard server environments also have an allowlisted stdio bridge.

Does Require approval work on every channel?

No. Interactive dashboard conversations can pause and resume after an operator decision. Public API, channel, and webhook invocations reject approval-required tools because those surfaces cannot hold an interactive approval session.

How are credentials stored?

A secret is submitted to a server route, encrypted with AES-256-GCM, and only ciphertext, IV, auth tag, metadata, and a masked last-four hint are persisted. The server decrypts it for discovery, health, OAuth refresh, or invocation; the UI cannot read the plaintext back.

Can I expose a Rylvo bot as an MCP server?

Yes, for internal composition. Bot export creates a protected internal MCP endpoint with a bot-turn tool and, when knowledge is linked, a KB-search tool. Production access requires the internal export secret, so this is not a public third-party endpoint.

How is the 129-tool Rylvo endpoint different?

Rylvo’s authenticated /mcp endpoint is the inbound direction used by Architect and AI editors to manage a workspace through 129 Rylvo tools. MCP Hub is primarily the outbound control plane for tools Rylvo bots call.

Does MCP cost attribution charge my wallet?

No. Tools are tagged Free, Low, Medium, or High for operational attribution and plan-budget enforcement. BYOK provider charges remain with your provider, and this attribution does not emit a Rylvo wallet debit.

Connect deliberately

Make every MCP tool visible, scoped, and accountable.

Register the server, discover live tools, set policy per bot, and operate the connection through schema drift.