Servers on your network
Harriet Desktop can call an MCP server that only your computers can reach, such as https://myhost.local/mcp on the office network or VPN. Harriet's own servers never open that address.
When this is the right path
By default, a connector is Proxied (via Harriet). The desktop app talks to Harriet, and Harriet forwards each tool call. That path only allows public HTTPS hosts, so a name that exists only inside your network fails there. A sandboxed connector runs inside Harriet's cloud and has the same limit.
Direct skips that hop. Harriet Desktop, and the other enrolled desktop apps on the same profile, call the MCP server URL from the computer. Use it for an internal server the laptop can already open. Keep the default when the server is on the public internet and you want the audit log and tool permissions.
The server has to accept calls with no API key and no sign-in. Harriet does not send either on a direct connection. If the server needs a token or Require per-user OAuth, Direct is not offered, and the proxy still cannot reach a private host.
Set it up
- Add a native MCP connector. From Connectors, open Add MCP in Integrations. On Connection, choose Native MCP server and set MCP server URL to the HTTPS address the computers can open, for example
https://myhost.local/mcp. On Authentication, leave Require per-user OAuth off. - Put it on a skill. In the skill editor, tick the connector under MCP integrations. If your organization reviews new connectors, approve it in the review queue first. Only approved connectors are listed for live skills.
- Include the skill on the profile. Open Manage → Profiles, select the profile those people use, and add the skill with Add skill.
- Choose Direct. On the same profile, open Desktop MCP transport, use Add integration override…, and set Transport to Direct. The section appears once the organization has a connector that qualifies. Direct is missing from the list when the connector uses a sign-in or is not a native HTTP server.
Harriet Desktop picks this up on its next sync, within about five minutes while the app is open, and also when the window is focused or the computer comes back online. The same connector can be Direct on one profile and Proxied (via Harriet) on another. A person on both gets Direct if any of their profiles says so. See Connector transport.
Sync tools runs from Harriet. If Harriet cannot open the address, sync fails, and that is expected. Harriet Desktop still asks the server for its tools from the computer. Tool permissions in Integration settings apply to calls that go through Harriet, so they do not govern this connection.
What stays on Harriet's network
Anything that runs in Harriet's cloud still cannot see myhost.local. That includes proxied tool calls, Harriet chat in the browser, and cloud workspaces. The laptop and a cloud workspace for the same person use the same choice, so a Direct override sends the cloud workspace to that private address and the call fails. Put Direct only on a profile whose members work on the network, and leave people who work in the cloud off that profile.
Calls from the computer do not appear in the audit log. For the comparison of the two transports, see Connector transport.