The Qoren platform MCP

Every Qoren agent gets a tool server for the platform itself. See the tool groups, what is on by default, which tools ask for approval, and how to switch them.

On this page

Every agent Qoren deploys gets one extra tool server: Qoren itself. Through it an agent can look itself up, message the agents beside it, hand you a file as a link, read your usage, and even operate your environments and agents. Only looking at itself is on until you switch more on, and the environment an agent runs on sets the most it can ever be given.

What the platform MCP is#

MCP (Model Context Protocol) is the standard way AI agents discover and call tools. The platform MCP is an MCP server that Qoren runs for you. It is not something installed on your environment, and it is the same server for every runtime: OpenClaw, Hermes and Codex agents all reach it the same way.

  • Each agent has its own credential. Qoren gives every agent a token for this server when it sets the agent up, and writes it into the agent's configuration by reference, so the value does not sit in a config file you might share.
  • An agent only sees the tools you allowed. A tool you switched off is not refused, it is not offered at all, so the agent never plans around something it cannot do.
  • Changes apply at once. The server checks your settings on every call, so a switch you flip takes effect on the agent's next tool call, and a tool you switch on is offered the next time the agent refreshes its tool list. Nothing needs to restart. The one exception is Mail: switching it reconfigures the agent to attach or detach its mailbox.
  • Secret values never come back. Tools that touch configuration or the vault return secret names only.

The tool groups#

Tools come in groups. Switching a group on turns on all its tools; you can then switch single tools off inside it.

GroupWhat the agent can doOn by default
ItselfRead its own identity, environment, configuration, logs and telemetry, post a status line, and read the platform guides for the groups it hasAlways on
TeammatesDiscover the other agents on the same environment and send them messagesOff
MailAdds no tools. Attaches the agent's mailbox so it can read and send emailOff (see below)
FleetInspect and operate your environments, agents, jobs and templates. Destructive actions ask a person firstOff
AccountRead usage, spending and plan limits. Never billing details or secret valuesOff
Public linksPublish a file from its own workspace as an expiring link, instead of pasting the contentsOff
ProposalsRead and write your client proposals, with live pricing. Deleting one asks a person firstOff

Mail only matters for an agent that has its own mailbox; see agent email for how an agent gets one.

A new environment allows only Itself. A new agent starts with what its template allows, or only Itself when the template sets nothing. The Work with teammates switch in an agent's permissions is the same thing as the Teammates group on its environment: see agents working together.

Itself#

ToolWhat it does
Who am IReturn this agent's name, runtime, model, template and current state
My environmentReturn the environment it runs on: size, region, status and the peers on it
My configurationReturn its scheduled tasks, MCP servers, chat channels and the names of its secrets. Values are never returned
My logsRead a slice of its recent runtime log
My telemetryRead its recent activity and resource telemetry
Report my statusPost a short status line, with optional progress, that the console shows on the agent
Read a platform guideRead the detailed guide for a group it has, or list the guides it may read

When your account uses Qoren's scheduler for scheduled tasks, Itself also holds five scheduling tools: My scheduled tasks, My scheduled task runs, Schedule a task, Change a scheduled task and Delete a scheduled task. They let the agent manage its own scheduled tasks when you ask it to do something regularly.

Teammates#

ToolWhat it does
List teammatesList the other agents on this environment that can be messaged
Message a teammateSend a message to another agent on the same environment

Fleet#

ToolWhat it doesAsks for approval
List environmentsList your environments with their size, region and statusNo
Get an environmentRead one environment in detail, including the agents on itNo
List agentsList your agents across every environmentNo
Get an agentRead one agent in detail: runtime, model, template, state and configurationNo
List jobsList recent jobs and their statusNo
Get a jobRead one job in detail, including its events and any failure reasonNo
List secret namesList the names of your vault secrets. Values are never returnedNo
List templatesList your agent templatesNo
Get a templateRead one agent template in detailNo
Create an environmentCreate a new environment on your planNo
Create an agentDeploy a new agent from a template onto an environmentNo
Configure an agentChange another agent's modelNo
Message an agentSend a message to another agent on its own environment. Agents on other environments are refused. A Custom agent, which has no environment, may message any agent on your accountNo
Cancel a jobCancel a queued or running jobNo
Destroy an environmentTear down an environment and everything on itYes
Destroy an agentRemove an agent from its environmentYes
Resize an environmentMove an environment to a different size, which restarts itYes
Reprovision an agentRebuild an agent from its template on the same environmentYes
Move an agentMove an agent to a different environmentYes

Anything the agent creates counts against your plan exactly as if you had created it, and uses your credits the same way.

Account#

ToolWhat it does
Account usageRead the account's usage for the current period
Account spendingRead the account's recorded spending for the current period
Plan entitlementsRead what your plan allows, such as environment and agent limits
ToolWhat it does
Share a file publiclyPublish one file from its workspace as an expiring public link
List shared filesList the links it has published, with their status and how often they were opened
Revoke a shared linkSwitch off a link so it stops working immediately

A link opens a page that shows the file and offers a download, to anyone who has it, until it expires or is revoked. Only files in the agent's workspace/ folder can be shared, up to 4 MB each, for at most 30 days. You can publish and revoke the same links from a terminal with qoren agent share (see the CLI command reference).

Proposals#

ToolWhat it does
List proposalsList your proposals with their client, status and monthly price
Read a proposalRead one proposal in full: its agents, pricing settings and document text, with its live quote
Price a changePrice a change to a proposal, or a new one, without saving it
Create a proposalStart a draft proposal, optionally for one of your clients
Change a proposalChange a proposal's agents, pricing settings or document text
Set a proposal's statusMark a proposal as draft, sent, accepted or declined
Assign a proposal to a clientAssign a proposal to one of your clients, or to none
Delete a proposalDelete a proposal for good. Asks for approval

The agent works on the same proposals you see on the Proposals page, priced the same way: from the live rate card, at your margin, with model spend ranges quoted as ranges. The prices follow from the agents, their usage and your pricing settings; like you, the agent can also type an agent's monthly price by hand. A proposal an agent creates is a draft on your list like any other; the account log records which agent made each change.

The group only works on an account that has proposals. On an account without it, the tools are not offered even when the group is on.

Set the ceiling on an environment#

The environment decides the most any agent on it may do. An agent's own settings can only narrow that, never widen it.

  1. In the sidebar, click Environments and open the environment.
  2. Open the Settings tab. The Platform access card lists every group.
  3. Switch a group on to allow all its tools, or open it with the arrow and switch single tools off (1).
The Fleet group expanded in an environment's Platform access card: every fleet tool has its own switch, and the destructive ones carry an Asks for approval tag.12
The Fleet group opened in an environment's Platform access card. Tools that ask a person first are tagged.

Tools tagged Asks for approval (2) never act on their own; see below.

Choose the Qoren tools for one agent#

  1. Open the agent and click Settings, then Permissions.
  2. Under Qoren tools, Itself is marked Always on (1).
  3. Switch a group off to take it away from this agent (2), or open the group and switch single tools off.
  4. A group marked Disabled by environment (3) is closed on the environment, so it cannot be switched on here. Change it on the environment first.
The Permissions section of an agent's settings: Work with teammates, the Qoren tools list of capability groups with their switches, and the Access token row with Rotate platform token.1234
The Permissions section of an agent's settings, with its Qoren tools and access token.

For everything else in this section, see agent permissions.

Set the starting tools in a template#

A template carries a default that new agents start with. In the template editor, open MCP servers and use Qoren platform access. It is a starting point, not a ceiling: the environment still decides the maximum, and you can narrow each agent afterwards. An agent that creates another agent with Create an agent cannot choose its access; the new agent gets the template's default.

Replace an agent's token#

Under Access token, click Rotate platform token (4), then Rotate. The old token stops working at once, and the agent picks up the new one when its configuration is rewritten. Use this if you think the token leaked, or to cut an agent off immediately.

Approvals, logs and limits#

  • Destructive tools ask a person. When an agent calls a tool tagged Asks for approval, nothing happens yet: the request goes onto the Approvals page and the agent is told it is waiting. Approving runs the action as you, with your plan checked at that moment; a request nobody decides expires after 24 hours.
  • Every change is logged. Each tool call that changes something is recorded in your account log as done by that agent. Reads are not recorded.
  • Calls are rate limited. Each agent can make 60 platform calls a minute. Past that, calls are refused until the minute is up.
  • A refused call says why. When a call is refused, for the rate limit, a missing permission or a bad argument, the agent gets the reason as the tool's answer, so it can correct itself or tell you.
  • Agents cannot change access. No tool reads or changes these settings, so an agent can neither widen its own access nor see what another agent may do.

The platform guides (qoren-* skills)#

The detailed "how to use these tools" guidance is not stuffed into every prompt. It ships as one guide per group, read only when needed: qoren-self, qoren-teammates, qoren-mail, qoren-fleet, qoren-account, qoren-public-links and qoren-proposals.

  • On a runtime that reads a skills folder (Hermes today), the guides for the groups the agent has are placed there as skills, and removed again when you switch a group off.
  • On every runtime, the agent can read the same guides with the Read a platform guide tool.

An agent only ever sees guides for groups it can use. The qoren- name prefix is reserved, so your own skills cannot use it.

Frequently asked questions#

What can a brand new agent do?

Read itself, and nothing more, unless its template or its environment says otherwise. Teammates, Mail, Fleet, Account and Public links are all off until you switch them on for the environment.

Can an agent give itself more access?

No. No tool reads or changes access settings, so an agent cannot widen or even inspect its own access. Only a person in the console can change it.

Can an agent read my secrets?

No. Tools that touch configuration or the vault return secret names only. No tool returns a secret value, on any plan, at any setting.

What happens when an agent asks to destroy something?

The call is parked as a request on the Approvals page, and the tool tells the agent that nothing has changed yet. If a person approves, the action runs as them. A request nobody decides expires after 24 hours.

How do I cut an agent off right now?

Switch its groups off, which applies on its next call, or click Rotate platform token so the token it holds stops working at once.

Was this page helpful?

Last updated