Connecting an agent.
Any MCP client connects to the platform in one of two ways: through the local server on your machine, or through the platform's MCP server over HTTPS with a key. Both serve the same tools and the same cards.
You can connect your own agent, on your machine or elsewhere. The agent uses MCP, and the platform serves MCP.
Connection options#
| connection | use it when | requirement |
|---|---|---|
| the local server | the agent runs on your machine, or it needs your files and the app’s cache | the desktop app, with the socket or a listener turned on |
| the platform’s MCP server | the agent runs elsewhere, or several people’s agents share one tenant | a key with the grants that the agent needs |
The agent gets the same tools and the same cards through either connection. A long step runs as a task that the agent can watch or stop. A host that renders cards draws each card from the address in the manifest. A host that does not render cards reads the card as text.
First calls#
si.session.whoamireturns the person or service that the agent acts for.si.session.my_grantsreturns what the agent may do in each place.si.read.cataloguereturns the sources and connectors of the tenant.si.ask.previewpreviews a definition before anything is spent.
Delegation to the platform’s agent#
An outside agent can hand a whole job to the platform’s own agent with si.harness.delegate. The platform’s agent runs the job under the caller’s grants, reports progress as a task, and returns the cards. The platform’s agent treats everything that it reads from a source as data and never as an instruction. A page, a message or a document therefore cannot steer it.
Claims#
| claim | state | route or tool |
|---|---|---|
| A connected agent reads its permissions with si.session.my_grants and hands a whole job to the platform's own agent with si.harness.delegate. | target | si.session.my_grants |