Tools & Skills

Tools and skills are how agents act. Tools give an agent the ability to take actions — search the web, generate files, call external services. Skills package higher-level capabilities the agent can recall when relevant.

Tools

Tools are grouped into categories. When you build an agent you grant it specific tool_categories, and the planner chooses which tool to invoke at each step. Tools can be enabled or disabled per team.

GET /api/tools                                 # list tools
GET /api/teams/{team_id}/tools                 # team tool config
GET /api/teams/{team_id}/tools/available
PUT /api/teams/{team_id}/tools/{tool_name}/enabled

Skills

Skills are reusable, packaged capabilities. Xagent ships with a library of built-in skills:

SkillWhat it does
agent-builderHelps design and configure new agents.
evidence-based-ragRetrieval with citations back to source documents.
presentation-generatorBuilds slide presentations.
pptx-editorial / html-deck-editorialEditorial-quality decks in PPTX or HTML.
pdf-report-editorialLong-form, formatted PDF reports.
xlsx-financial-reportStructured financial spreadsheets.
poster-designMarketing posters and visual assets.
GET  /api/skills                 # list skills
GET  /api/skills/{skill_name}    # skill detail
POST /api/skills/recall          # recall a skill for a task
POST /api/skills/reload

Built-in Connectors

Connectors link an agent to an outside service you already use. Sign in once and the agent can act in that service on your behalf — no configuration files, no code.

CategoryConnectors
ProductivityNotion, Google Sheets, Google Docs, Google Slides, Google Drive, Google Calendar, Google Maps, Granola, OneDrive, SharePoint, Excel, PowerPoint, Word, Planner, Atlassian (Jira, Confluence, Bitbucket), Miro, Rocketlane, Fireflies, Jira, Linear
CommunicationGmail, Outlook, Slack, Microsoft Teams, WhatsApp Business
MarketingGoogle Analytics, Google Ads, LinkedIn, Facebook, Instagram, Meta Ads
CRMHubSpot, Salesforce, ChartMogul
SchedulingZoom, Deputy
OperationsAWS, MYOB
DevelopmentGitHub
AnalyticsPostHog, Google Search Console
PaymentsStripe
HREmployment Hero
CommerceMagento, Shopify

MCP stands for Model Context Protocol — an open standard that lets Xagent plug into an outside service and use its features as tools. See MCP Providers for the sign-in steps on the connectors that need their own app credentials.

Connector authentication varies

Most connectors above sign in through OAuth. A few use a different credential type instead: PostHog connects with a personal API key plus your PostHog host (US or EU cloud), Stripe connects with a Restricted API Key you create in your Stripe dashboard, with permissions matching the actions you want the agent to take (reading balances/customers/charges, or also creating refunds and payment intents), ChartMogul connects with a per-user API key from your ChartMogul account's Profile → API keys page, and Magento connects with an Integration access token generated in your own Magento/Adobe Commerce store admin.

Salesforce and Employment Hero: PKCE required

Salesforce and Employment Hero connect through OAuth like most connectors above, but both enforce PKCE on the authorization flow with no per-app way to disable it — this is handled automatically. Salesforce tools cover SOQL query, SOSL search, and listing/describing/creating/reading/updating/deleting records for any standard or custom object in your org, since Salesforce orgs are highly customizable. Employment Hero tools are read-only, covering organisations, employees, teams, and timesheet entries.

Deputy: no granular OAuth scopes

Deputy tools cover looking up employees, viewing rosters/shifts, reading timesheets, and creating or updating records such as employees, rosters, timesheets, and leave. Deputy’s OAuth flow defines no per-resource read/write scopes, so once connected, reads and writes run at whatever permission level the connected account already has in Deputy — there is no way to grant read-only or narrower access through the connector itself.

Magento: self-hosted stores

Magento connects to a self-hosted Magento or Adobe Commerce store using an Integration access token, rather than through Xagent's own OAuth flow. Tools cover product search/get/create/update, order search/get/add-comment, customer lookup, and category browsing. On Magento 2.4.4 and later, enable Stores → Configuration → Services → OAuth → Consumer Settings → "Allow OAuth Access Tokens to be used as standalone Bearer tokens" before connecting.

Shopify: custom app credentials

Shopify connects with a custom app you create in your own store, using a store label (for example, acme for acme.myshopify.com) plus an Admin API access token — rather than through Xagent's own OAuth flow. Grant the app write_products, write_orders, and read_customers scopes; read_all_orders is optional and only needed for orders older than 60 days. Tools cover product list/get/create/update, order list/get/update, and customer/collection lookups.

Slack connector: reconnect required

The Slack connector's tool surface was expanded to add channel/thread history search, direct-message listing, message search, reactions, and file upload, backed by additional Slack bot scopes. Existing Slack connections were invalidated by this change and must be reconnected — if an agent's Slack connector stops working, reconnect it from the connector's settings to re-authorize the new scopes.

Sharing Connectors with Your Team

Sharing a connector lets your teammates' agents use that integration, so not everyone has to connect the same account separately. A connector shared with your team now appears in the "+ Connector" picker for every team member, not only the person who shared it.

ActionWho can do it
Share a connector with the teamThe person who owns the connection
Stop sharing itTeam admins only

A shared connector cannot be un-shared while a team agent still uses it — remove it from that agent first.

When a shared connector needs your sign-in

Some services still require each person to sign in with their own account. When a teammate shares one of those, it appears in your list marked as needing setup — the connector is available to you, but you have to authorise it with your own credentials before an agent can use it.

Each connector the picker returns (GET /api/mcp/apps) carries flags an integration can use to decide what to offer: can_attach (true only once credentials for that connector actually resolve — an active grant, or a deployment-supplied credential), can_authorize (true only when connecting your own account through it would do something — false if a deployment-level credential already supplies access), and can_configure (true only when you hold a personal association for that connector — a local MCP server or custom API you own, or an existing connection to a catalog entry). A connector shared with you but not yet authorized shows can_attach: false until you connect it yourself, and the Configure button now follows can_configure rather than connection state, so a connector whose credentials come from a deployment-installed resolver still shows Configure to its owner even though it never reads as "connected."

Computer Use (Browser & Desktop Relay)

Computer Use lets an agent act on a computer you control, instead of only in a sandboxed environment. It has two independent modes, both configured from your account's Settings → Computer use tab:

ModeWhat it controlsHow you connect it
My browser (Browser Relay)One signed-in tab in your own Chrome browser.Install the Xagent Browser Relay Chrome extension, then create a one-time pairing setup in Settings and paste it into the extension. You then approve the specific tab the agent may act in.
My computer (Desktop Relay)One authorized window, or an entire display, on your Mac.Build/install the macOS companion app, create a one-time pairing setup in Settings (POST /api/desktop-relay/pairings), and run the companion with it. You then choose to authorize either one window or one whole display.

Desktop Relay is macOS-only at this commit and requires the companion to be granted macOS Screen Recording and Accessibility permissions, both shown as status badges in Settings. A visible emergency stop exists on the Mac side: pressing Command-Option-P pauses desktop control; an emergency stop clears the authorization entirely and requires re-choosing a target. Revoking either connection from Settings (DELETE /api/desktop-relay/session for Desktop Relay) immediately ends the agent's access.

Independent of the built-in connectors table above

Computer Use is a per-person pairing to your own browser tab or Mac, not a connector any team member can share — it does not appear in the connector picker and is not affected by the Sharing Connectors mechanics on this page.

Extending the Toolset

Beyond the built-ins you can connect external capabilities: