Nothing here is required to use a third-party tool. Any MCP server can be
wired to an agent by hand with
mcp_servers, and always could.
What Connected apps add is managed authorization, a catalog, and something to
run after the call.How it fits together
The two paths out of that diagram are the whole design: one is a capability the model may or may not use, the other is a guarantee that fires because an event arrived. Choosing between them is the question this feature asks you. TurnCall never holds the third party’s tokens. The builder stores one encrypted Pipedream client credential; everything a call needs is minted for that call and expires within the hour.Setup
You need a Pipedream account and a Connect project. Four values go in the builder API’s.env:
Restart the builder API. Without these, the Integrations page says so rather
than failing obscurely.
Connecting an app
On the Console’s Integrations page, an admin picks an app and is sent to Pipedream’s hosted consent screen. The builder never renders the third party’s login and never sees what is typed into it. Coming back, it asks Pipedream what now exists. Connecting is a workspace act and needs admin. Choosing which agent uses an app, and when, is a per-agent act on that agent’s Configuration tab.Choosing when it runs
The two triggers are deliberately not symmetric, because they answer different questions.- During a call
- When a call ends
The app’s tools are offered to the model, which calls them if it decides to.
A set, with the arguments supplied at runtime.Nothing guarantees it fires. If the summary has to be posted, this is the
wrong half.Each app contributes a pinned list of tools, not everything it can do —
Slack alone has 50 actions, against a cap of 50 tools per server and 100 per
agent, and every advertised tool rides in every request for the length of the
call.
What is on offer
Values you cannot check by eye are chosen from a list, not typed: a Slack
channel is picked by name and stored by id, and so is a calendar. That list is
fetched from your own connected account, so it is the real one.
Scheduling a follow-up when a call ends is not offered. A
call.ended
payload says when the call finished, not when a meeting should be — an action
that configured cleanly and failed every night would be worse than one that
isn’t there.
Why the list is short
Two apps, curated in code. Adding a third is deliberate rather than automatic, for two reasons: the pinned tool list is load-bearing against the per-agent tool cap above, and an end-of-call action needs a human decision about which of its inputs can be known before the call happens. Anything not on the list is still reachable today as a raw MCP server, with credentials you manage.What a call actually receives
Attaching an app mid-call adds anmcp_servers entry to the agent’s config for
that call, with an Authorization header minted at call time. It reaches the
call through call-init as an inline agent — the only
path that can carry a credential without storing one.
Nothing in that exchange is stored. The token outlives the call by less than an
hour, and the agent’s own config never contains one.
That has a visible consequence, which the call-init guide covers in full: such a
call has no stored agent, so every event for it carries agent_id: null.
Correlate on call_id.