Connecting Haystack to Custom MCP Connectors via OAuth 2.0
Learn how to connect Haystack to third-party platforms like using the Model Context Protocol (MCP) and secure OAuth 2.0 authentication.
MCP integrations are an add-on service that are licensed separately than the core intranet platform. If you're eager to use an MCP integration, please reach out to your Customer Success Manager (CSM) or support@haystackteam.com for more details.
Overview & Value
The Model Context Protocol (MCP) acts like a universal adapter for AI applications—similar to a USB-C cable for your digital tools. It enables Haystack to query external databases, search enterprise knowledge bases, and perform actions across non-native platforms directly within your Haystack workspace.
By leveraging OAuth 2.0 authentication, Haystack connects securely to your third-party applications (such as Moveworks, Zendesk, Leena AI, or custom internal platforms). This ensures that permissions are securely delegated, scoped to individual user access, and fully compliant with enterprise identity standards—without storing raw credentials or static API keys.
⚠️ Important Support Notice: While OAuth 2.0 and MCP are standard open protocols, individual platform implementations vary significantly. Establishing a successful technical connection does not guarantee end-to-end functional compatibility out of the box. All custom MCP solutions should be explicitly vetted and validated with your Haystack Customer Success Manager (CSM).
Setup Prerequisites
Before configuring a Custom MCP Connector in Haystack, ensure you have the following administrative permissions and technical parameters ready:
- Haystack Workspace Admin Role: Required to access Admin Settings and manage workspace integrations.
- External Application Admin Access: Required to register an OAuth 2.0 app or manage API credentials within your target platform
- MCP Server HTTP Endpoint: A publicly accessible, secure HTTPS URL hosting your compatible MCP server instance.
- OAuth 2.0 Application Credentials
Step-by-Step Guide
our Haystack Customer Success manager will provide you with setup instructions! If you're unsure who that is, please don't hesitate to reach out to support@haystackteam.com.
Best Practices
- Enforce Least-Privilege Scopes: Grant only the specific scopes necessary for the workflows your Haystack users need to execute.
- Vet Solutions with Your CSM First: Always collaborate with your Haystack Customer Success Manager early in the evaluation process to confirm server compatibility and expected behavior.
- Configure Token Refresh: Ensure your external OAuth server supplies refresh tokens so user authorization remains active without requiring frequent re-authentications.
Need More Help?
If you encounter issues during setup or need assistance verifying your custom MCP server:
- Chat with us: Available via the support bubble on this page.
- Email us: Reach out to support@haystackteam.com.
Keywords
MCP, Model Context Protocol, OAuth 2.0, Custom Connector, Moveworks, Zendesk, Leena, Integrations, Haystack Admin, Authentication