Many tools now offer an MCP server, the standard way AI assistants connect to a service, and many more publish a REST API with an OpenAPI description. When a tool you use is not in the list, you can connect it yourself, and your assistants use it like any other integration.
Its address, and its key (in the Authorization header or a header of its own), or a sign-in to the tool
A REST API
Its base address, its OpenAPI description (pasted, or the address it is published at), and its key
Use the address from the tool's own documentation. Never put a key in an address: it goes in the key field, where it is stored encrypted and never shown back.
Waits for your Approve, every time, when you let assistants ask
StellarFirm decides what a tool may do by itself, not by what the tool says about itself:
On an MCP server, a tool counts as reading only when its name starts with a reading word (search, get, list, read). Everything else waits for your Approve.
On a REST API, the method decides: GET reads, and POST, PUT, PATCH, and DELETE wait for your Approve.
Some tools take a sign-in instead of a key. StellarFirm signs in the standard way for MCP servers, with your browser and the tool's own page, and renews the sign-in on its own. If the tool signs in only apps registered with it, register one with the address the page shows, then paste its client id (and its secret, if it has one).