# Rasa Configuring Mcp Server

> >

- **Type:** Skill
- **Install:** `agentstack add skill-rasahq-rasa-agent-skills-rasa-configuring-mcp-server`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [RasaHQ](https://agentstack.voostack.com/s/rasahq)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [RasaHQ](https://github.com/RasaHQ)
- **Source:** https://github.com/RasaHQ/rasa-agent-skills/tree/main/skills/rasa-configuring-mcp-server

## Install

```sh
agentstack add skill-rasahq-rasa-agent-skills-rasa-configuring-mcp-server
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Configuring MCP Servers

MCP servers expose external tools — APIs, databases, services — to a Rasa assistant. All
MCP servers are defined in `endpoints.yml` and shared across direct flow tool calls and
ReAct sub agents.

This feature is in **beta** and available starting from **Rasa 3.14.0**.

## Workflow

1. Add each MCP server to `endpoints.yml` (see "Server definition").
2. Add authentication if the server requires it (see "Authentication").
3. Validate the project.

## Server definition

Register every MCP server in `endpoints.yml`.

| Key    | Required | Description |
|--------|----------|-------------|
| `name` | yes      | Unique identifier — referenced from flows and sub agent configs. Duplicates cause a validation error at startup |
| `url`  | yes      | URL where the MCP server is running |
| `type` | yes      | `http` or `https` |

```yaml
# endpoints.yml
mcp_servers:
  - name: trade_server
    url: http://localhost:8080
    type: http
  - name: payment_server
    url: https://api.payment-service.com
    type: https
```

## Authentication

Add auth fields directly to the server entry in `endpoints.yml` when the MCP server
requires credentials. Sensitive values (`api_key`, `token`, `client_secret`) **must**
use `${ENV_VAR}` syntax — plain text is rejected by validation.

### API key

Sent as `Authorization: Bearer ` by default. Add `header_name` and
`header_format` to override the header.

```yaml
mcp_servers:
  - name: secure_api_server
    url: https://api.example.com
    type: https
    api_key: "${API_KEY}"
    header_name: "X-API-Key"       # optional, default: Authorization
    header_format: "{key}"          # optional, default: Bearer {key}
```

### OAuth 2.0 (client credentials)

```yaml
mcp_servers:
  - name: oauth_server
    url: https://api.example.com
    type: https
    oauth:
      client_id: "${CLIENT_ID}"
      client_secret: "${CLIENT_SECRET}"
      token_url: "https://auth.example.com/oauth/token"
      scope: "read:data write:data"    # optional
      audience: "https://api.example.com"  # optional
      timeout: 10                      # optional
```

### Pre-issued token

```yaml
mcp_servers:
  - name: token_server
    url: https://api.example.com
    type: https
    token: "${ACCESS_TOKEN}"
```

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [RasaHQ](https://github.com/RasaHQ)
- **Source:** [RasaHQ/rasa-agent-skills](https://github.com/RasaHQ/rasa-agent-skills)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-rasahq-rasa-agent-skills-rasa-configuring-mcp-server
- Seller: https://agentstack.voostack.com/s/rasahq
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
