Start with a clear read-only task

Ask your agent to inspect the tools, then describe the exact goal and data scope. For example: “Use the authorized query tool to find this week's tasks in project A. Only read information.” Use tool names from the client's actual catalog.

  1. Confirm the service and tool.
  2. Specify the project, resource identifier, or query scope.
  3. Read the result and confirm that it belongs to your task.
  4. Confirm data changes separately through write approval.

Why only some tools are visible

The catalog is limited by company publication policy, identity permissions, and your client grant. Setup shows what you may request; the client shows what is actually authorized. Newly added tools do not expand existing grants automatically. Confirm them again.

Passing MCPHub access checks does not guarantee that the business system permits the operation. Your upstream account's roles, resource permissions, and status still matter.

Tools, prompts, resources, and subscriptions

CapabilityPurpose and requirements
ToolsQueries or business operations; the wizard mainly configures this capability.
PromptsService prompt templates; both the service and client must support them, and access must be explicitly granted.
ResourcesRead information or context exposed by the service; enable access separately.
SubscriptionsReceive resource-change notifications; enable both resources and subscriptions.

See the CLI reference for additional capabilities. Resource conditions on tool arguments do not restrict resource URIs or prompts.

Failures and uncertain results

The connector does not automatically replay operations after a network failure. Retry a query after confirming the cause. For a write, check approval and business status first to avoid duplicates. After a 429 response, wait for capacity to recover and still confirm whether a write was already accepted.

Approval, execution, and success are separate stagesBrowser approval permits continuation. The original client must resume the call, the upstream service must accept it, and you must confirm the business result.

Investigate a call

Keep the request ID, time, service, and tool name. If no ID is shown, give your administrator a time range and task description for diagnostics. Do not send credential files.