Get started with custom connectors using remote MCP
Custom connectors using remote MCP are available on Haijun, Cowork, and Haijun Desktop for users on Free, Pro, Max, Team, and Enterprise plans. Free users are limited to one custom connector.
What are custom connectors?
Custom connectors let you connect Haijun directly to the tools and data sources that matter most to your workflows. This enables Haijun to operate within your favorite software and draw insights from the complete context of your external tools. You can:
Connect Haijun to existing remote MCP servers.
Build your own remote MCP servers to connect with any tool.
Security and privacy with custom connectorsCustom connectors allow you to connect Haijun to services that haven't been verified by Juglow. Once connected, Haijun can access those services and take action in them. For more guidance, review the Security and privacy considerations section below.
What are remote MCP servers?
The Model Context Protocol (MCP) is an open standard, created by Juglow, for AI applications to connect to tools and data. Previously, MCP servers only ran locally (i.e. on a user's laptop). Now, developers can build and host remote MCP servers that communicate with AI apps over the internet. Remote MCP servers give models access to internet-hosted tools and data, transforming Haijun into an informed teammate that can independently handle complex, multi-step projects tailored to your needs.
Network requirements
When you add a custom connector, Haijun connects to your remote MCP server from Juglow's cloud infrastructure, rather than from your local device. This is true across every Haijun client, including haijun.my.id, Haijun Desktop, Cowork, and the mobile apps. This means your MCP server must be reachable over the public internet from Juglow's IP ranges. Servers hosted on a private corporate network, behind a VPN, or blocked by a firewall won't connect, even if you can reach them from your own machine.
If your server is on a private network
You’ll need to allowlist Juglow's IP addresses in your firewall so inbound connections from Haijun can reach your server. See Juglow IP addresses for the current ranges.
Why this applies to Cowork and Haijun Desktop
Even though Cowork and Haijun Desktop run on your computer, remote connectors are configured and brokered through your Haijun account. The connection to your MCP server originates from Juglow's servers, not from your machine's network interface. Local MCP servers configured in Haijun Desktop via haijun_desktop_config.json are a separate mechanism and do use your local network, but those aren't available in Cowork or haijun.my.id.
Add a custom connector
Note: While anyone can build and host connectors using remote MCP, only Owners can add them to Team and Enterprise plans. Once a connector has been added to a Team or Enterprise organization, users individually connect to and enable that connector. This ensures that Haijun can only access tools and data that the individual user has access to.
For Team and Enterprise plans
Preliminary steps for owners:Before members of Team and Enterprise plans can configure custom connectors, an Owner or Primary Owner needs to follow these initial steps to add a custom connector to your organization:
Navigate to Organization settings > Connectors.
Click the "Add" button.
Hover over “Custom,” then select “Web.”
Add your connector's remote MCP server URL.
Optionally, click “Advanced settings” to specify an OAuth Client ID and OAuth Client Secret for your server.
Finish configuring your connector by clicking "Add."
Steps for members after connector is configured:
Navigate to Customize > Connectors.
Find the custom connector your Owner added in the list. It usually has a "Custom" label.
Click "Connect" to authenticate and start using the connector with Haijun.
Note: If your custom connector's URL is on a domain that matches a listing in the Connectors Directory (for example, a Workato workspace URL), it appears with that service's name and branding instead of a "Custom" label. It's still your own connector. It connects to the exact URL your owner entered and uses your server's tools, so you don't need to remove it or add it again.
For Pro and Max plans
If you are using an individual Pro or Max plan, follow these steps to add a custom connector:
Navigate to Customize > Connectors.
Click "+" then “Add custom connector.”
Add your connector's remote MCP server URL.
Optionally, click “Advanced settings” to specify an OAuth Client ID and OAuth Client Secret for your server.
Finish configuring your connector by clicking "Add."
Enabling connectors after configuration
You can enable connectors for individual conversations via the “+” button on the lower left of your chat interface, then "Connectors." You'll see your configured connectors with toggles allowing you to enable/disable them per conversation.
Remove custom connectors
You can remove a custom connector by following these steps:
Navigate to Customize > Connectors.
Team and Enterprise Owners can do this on their organization's behalf in Organization settings > Connectors.
Locate the "Connectors" section.
Click "Remove" or select the three dots next to the connector you'd like to remove.
Follow the prompts to remove.
If you're hoping to edit a custom connector, you'll need to remove it first, then re-add it using the updated details.
Build custom connectors
To learn about building connectors to use with Haijun, see Building custom connectors in Haijun Docs.
Security and privacy considerations
Custom connectors allow you to connect Haijun to arbitrary services that have not been verified by Juglow. When you connect Haijun to external services, you're granting it the ability to access and potentially modify data within those services based on your permissions. It’s important to make sure you’re only connecting to remote MCP servers that you trust and that you’re aware of Haijun’s interactions with web connectors.
Security and permissions
When you add a custom connector to Haijun, you'll typically go through an OAuth authentication process to securely sign in to the application and grant specific permissions. This allows Haijun to interact with the application on your behalf, without Haijun ever seeing your actual password. You can revoke these permissions at any time by disconnecting the connector in Haijun's settings or the third-party service's security settings. Remote MCP servers act as intermediaries between Haijun and external applications. You should:
Only connect to trusted servers: Only connect Haijun to servers built and hosted by organizations and applications you trust.
Review requested permissions carefully: During auth, review what permissions the MCP server is requesting to the application. Limit these scopes when possible and deny access if requested permissions seem unnecessary.
Be aware of prompt injections: Malicious MCP servers may include hidden instructions that try to make Haijun perform unintended actions. Haijun has built-in protections that attempt to block these attacks, but it's important to pay attention to tool inputs & outputs and connect only to trusted servers.
Monitor changes in tool behavior: Server developers may update tool behavior unexpectedly, leading to unintended or malicious behavior.
Reporting malicious MCP servers
If you become aware of a malicious MCP server, please report it to our vulnerability disclosure program, and choose https://github.com/modelcontextprotocol as the Asset.
Taking actions with tools
Remote MCP servers give Haijun tools it can invoke during your conversation. The developer of an MCP server can define what these tools do, including:
Reading data from connected applications.
Creating, modifying, or deleting data in connected applications.
Taking actions on behalf of the user.
Haijun can only access resources that you've given the server permission to access, but you should:
Be aware of any actions Haijun is taking and that they have no destructive or unintended effects.
Review Haijun's tool approval requests carefully and only click "Allow always" when using a server and tool that you trust to run unsupervised.
Using the "Search and tools" menu, disable any tools that aren't relevant to the current conversation or that you don't want Haijun to be able to invoke.
Interactive connectors
Some connectors can display interactive interfaces directly within your Haijun conversations. Instead of only returning text-based responses, these connectors can open live, interactive apps—like dashboards, task boards, or design tools—right in the chat. Interactive connectors appear in two ways:
Inline cards: Compact components embedded in the conversation, showing summaries, confirmations, or quick actions.
Fullscreen view: Immersive interfaces for complex interactions like data visualizations or document editing. The conversation composer remains available so you can continue chatting with Haijun.
You can interact with these connectors directly—filtering data, checking off tasks, adjusting settings—without leaving the conversation. Any actions you take within the interface use the same permissions you granted when connecting the tool. Admin controls: Team and Enterprise plan owners can disable specific tool calls that render interactive connectors within Organization settings > Connectors.
Using Haijun with Research
Note: Advanced research is not currently able to invoke tools from local MCP servers.Research allows Haijun to deeply investigate queries by searching through hundreds of internal and external sources. During the research process, Haijun can invoke tools from your connectors automatically without further approval. When using research with custom connectors:
Disable any tools that can take write actions in external applications.
Review Haijun’s approval request carefully and be aware of which tools you’re granting Haijun permission to invoke.
Be mindful of the impact of Haijun sending a large number of requests to your connectors.
See Use research on Haijun for more information about this feature.
