Muetext logo Muetext

Tools for hosted bots

Attach MCP servers to a hosted bot, connect Google Calendar and Gmail, and how approval works for actions.

MCP servers

In Bots, open a bot with a hosted brain and add an MCP server under Tools: a name, its Streamable HTTP address (https only, public hosts only) and, if it needs one, a bearer token or a custom header. The credential is encrypted on the server, only ever sent to that address, never shown again and never given to the model. Muetext reads the server's tool list when you save, when you press refresh and once a day.

Every tool is either read (runs straight away), write (a person approves every call) or off. A tool starts as write unless the server marks it read-only; you can change that per tool.

How a reply uses tools

While answering, the bot may make up to 4 tool calls within 60 seconds. Each call shows in the chat as a status line that updates when it finishes. A write call never runs directly: it becomes an approval draft in the chat and in Approvals, which can be approved or rejected but not edited. It runs once, right after a member approves it, and its status line shows the result. Approvals older than a day expire.

Tool results are treated as data, never as instructions, and every message still passes the same policy checks, consent rules and STOP.

Google Calendar and Gmail

Each person connects their own Google account in Settings. Their own hosted bots can then use three built-in tools, once switched on per bot: calendar.free_busy (read: busy times and free slots), calendar.create_event (write: needs approval; invitations go out only after it) and gmail.create_draft (write: needs approval; it only creates a draft and never sends). They act on the bot owner's account, and only in chats where the owner is a member.

Tokens are encrypted on the server and refreshed automatically. Disconnecting in Settings revokes access at Google.

Turning on Google (for the Muetext owner)

Create an OAuth client (type Web application) in Google Cloud, enable the Google Calendar API and Gmail API, add the three scopes below to the consent screen, and register the redirect URI for each address the app is served from. Until both settings are present the Connect Google button stays off and the tools aren't offered.

GOOGLE_CLIENT_ID=...apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=...

# authorized redirect URI
https://<your-app>/api/oauth/google/callback

# scopes
https://www.googleapis.com/auth/calendar.readonly
https://www.googleapis.com/auth/calendar.events
https://www.googleapis.com/auth/gmail.compose