Before you start
You need:- A reachable MCP server endpoint, available over HTTPS.
- Authentication details for the MCP server.
- A list of tools Fini is allowed to call.
- Accurate input and output schemas for each tool.
- At least one Fini bot that should use the tools.
Design tools for automatic binding
Fini derives its configuration from your schemas, so schema quality directly determines agent quality. Good MCP tools:- Have a single responsibility.
- Use explicit, well-named input fields. Fini binds inputs by name and format: a field named
emailbinds to the verified session email, andcustomer_idbinds to a customer ID returned by an earlier tool call. - Write descriptions for a reader who has never seen your system. The agent uses the description to decide when to call the tool.
- Declare an
outputSchema. Fini derives attributes and Action outputs from it. Tools without one still work: Fini infers the shape from the first successful responses and treats that as the schema until your server declares one. - Declare tool annotations. Fini reads
readOnlyHint,destructiveHint, andidempotentHintto classify tools and set safe defaults. - Return only the fields the agent needs, in structured JSON, instead of full internal records.
- Return predictable error fields when a request cannot be completed.
Connect your MCP server
Share the following with your Fini contact:- A connection name.
- The MCP server URL.
- The authentication method and the required credentials. Share credentials through a secure channel, not in plain email or chat.
- The list of tools Fini is allowed to call.
How Fini uses your tools
Read tools become context automatically
When a read tool is enabled, its output schema is registered immediately. Every response field becomes an attribute namedconnection.tool.field, for example billing.get_customer_context.plan. There is no Attribute to create and no response mapping to maintain.
At runtime, the agent decides which enabled read tools to call based on their descriptions and the conversation. Inputs resolve automatically from verified session data (a signed widget token, integration metadata) and from fields already collected in the conversation. If a required input is unavailable, the tool is skipped and the agent works without it, or asks the customer when the field is something a customer can reasonably provide. Skipped tools and their missing inputs appear in the AI Steps trace in Inbox.
Write tools become Actions automatically
Every enabled write tool appears as an Action in Rulebook, grouped under its connection. The tool’s input schema defines the Action inputs and its output schema defines the Action outputs. There is nothing to author. Write tools never run on their own. By default a write tool executes only inside a Rulebook Tool node, after any Check nodes you place before it:Create or edit the rule
Add the guards
Add a Tool node
Add a Reply node
Test and publish
Field visibility
Rulebook can use every returned field. What the AI sees follows policy defaults:is_vip from generated replies while keeping it available to Rulebook checks.
Automatic schema sync
Fini keeps every connection’s tool catalog current. When your server supports it and a session is live, Fini subscribes totools/list_changed notifications and re-syncs immediately. Otherwise Fini polls tools/list on a short interval and diffs the result against the stored snapshot.
Every detected change is classified and handled automatically:
- Additive changes, such as a new optional input, a new output field, or an updated description, apply silently. New output fields become attributes as soon as the sync lands.
- New tools appear in the catalog as Discovered and stay disabled until enabled. Nothing your server adds becomes callable on its own.
- Breaking changes, such as a renamed or removed required input, a removed output field that a rule references, or a deleted tool, mark the tool Degraded. Fini lists every rule and bot that references it, notifies workspace admins, and routes affected Tool nodes to their Fallback path until the change is resolved. A Degraded tool returns to Enabled once a sync validates cleanly against every rule that uses it.
Add the versioned tool
cancel_subscription_v2 to your server. It appears as Discovered on the next sync.Repoint the rule
Remove the old tool
Testing
Test each layer before publishing:Connection test
Sync check
Tool dry run
Rulebook test
Inbox review
Security recommendations
- Enable only the tools Fini needs. Everything else stays Discovered and is never callable.
- Never return secrets or access tokens. Fini’s redaction of secret-patterned fields is a backstop, not a substitute.
- Use least-privilege credentials for the MCP connection.
- Declare an
idempotency_keyinput on every write tool so Fini can inject one. - Review AI Steps after testing to confirm sensitive values are redacted.
Example workflow
A cancellation workflow with this model:- A customer asks to cancel their subscription.
- The agent calls
get_customer_context. Theemailinput resolves from the signed widget token. customer_id,plan, andsubscription_statusare available as attributes the moment the response lands.- Rulebook matches the cancellation intent.
- A Check confirms
billing.get_customer_context.customer_idis present. - A Read node captures the cancellation reason.
- The Tool node runs
cancel_subscription.customer_idresolves from the attribute,reasonfrom the Read node, andidempotency_keyis injected by Fini. - A Reply node confirms the cancellation using
confirmation_id,refund_amount, andeffective_date.
Why your MCP tools aren’t working
A tool doesn't appear in the catalog
A tool doesn't appear in the catalog
tools/list, and that it has a valid input schema. Then check the connection’s last-synced time to confirm a sync has run since the tool was added.A read tool isn't being called
A read tool isn't being called
An attribute has no value
An attribute has no value
A write tool doesn't run
A write tool doesn't run
The reply is missing values
The reply is missing values
A tool is marked Degraded
A tool is marked Degraded
The connection test fails
The connection test fails

