Connector transport

The Desktop MCP transport section of a profile controls how Harriet Desktop reaches each eligible MCP connector: Proxied (via Harriet) routes traffic through Harriet, while Direct lets the device call the MCP URL itself.

The two transports

By default, connector traffic is proxied: the desktop talks to Harriet's per-user MCP endpoint, and Harriet forwards each tool call to the underlying integration. Direct is an opt-in override, available only where Harriet marks the integration as safe for direct access.

Proxied (via Harriet)Direct
Who talks to the MCP serverHarriet, on the device's behalfThe device itself
CredentialsHeld by Harriet (the org-level secret key or the person's OAuth connection); the device carries only a proxy tokenNone — only unauthenticated servers qualify
Audit trailEvery tool call is logged in the audit logCalls do not pass through Harriet, so they are not audited
AvailabilityEvery MCP connectorUnauthenticated native HTTP MCP integrations only

What proxying adds

Proxied is the governed path. Harriet resolves the right credentials for each call — the organization's secret key, or per-user OAuth tokens for connectors that require an individual sign-in — so secrets never live on the device. The desktop configuration carries only a per-user, per-server, per-device proxy token, which Harriet uses to resolve the integration and credentials on each call.

Because every call passes through Harriet, each one lands in the audit log: who called which tool, from which device, and whether it worked. Proxying is also where tool permissions take effect, since Harriet sees the call before the integration does.

What direct means

With Direct, Harriet Desktop calls the MCP server's URL itself, with no Harriet hop in between. Only unauthenticated native HTTP MCP integrations can offer this option; OAuth and other authenticated integrations always use the proxy, because their credentials live in Harriet, not on the device. Choose Direct for a server your computers can open and Harriet cannot, such as a host on the office network. The steps are in Servers on your network. Keep Proxied wherever you want the audit trail.

Setting an override

  1. Open the profile. Go to Manage → Profiles and select the profile, then scroll to Desktop MCP transport.
  2. Add the connector. Use Add integration override… and pick an eligible integration. New overrides start as Proxied (via Harriet).
  3. Choose the transport. In the row's Transport select, switch between Proxied (via Harriet) and Direct. Direct only appears for integrations that allow it.

Overrides are per profile, so the same connector can be Direct for one team's profile and Proxied for another's. A person still gets one connection. If any profile assigned to them, or to one of their teams, is set to Direct, Harriet Desktop uses Direct. Otherwise the connector stays Proxied (via Harriet), including when the default profile is explicitly proxied. Remove an override to drop that profile out of the choice.

💡

Desktop MCP transport appears once the organization has a native MCP connector with no sign-in. Until then the profile has nothing to override. See Servers on your network.