Socket
Connect your AI agents to Socket through its vendor-hosted MCP server.
Generic MCP server
Socket builds and hosts this MCP server. Agent Handler proxies your agent’s calls to it, so you get the same auth, tool access controls, and audit trail you get on a Merge Connector. The tool surface itself comes from Socket.
Scan dependencies and packages for supply-chain security risk.
Authentication
Socket accepts either OAuth or an API key. Prefer OAuth when your end users can grant consent themselves; use an API key for service accounts and headless deployments. Both are collected through Magic Link.
Available tools
Tools on a generic MCP server are defined by Socket, not by Merge, so the list changes when Socket changes it. Agent Handler discovers the current tools when the connection is made and re-discovers them on each resync, which means your agent always sees what the server actually exposes today.
To see the tools available right now, connect Socket in the dashboard and open its Connector page, or read Socket’s own MCP documentation.
How this differs from a Merge Connector
Merge Connectors are written and tested by Merge against the vendor’s REST API. Merge owns the tool names, the input schemas, the error messages, and the regression tests, so the surface stays stable and the tool descriptions are tuned for agents.
A generic MCP server is the vendor’s own. You get whatever the vendor ships, on the vendor’s release schedule. Agent Handler still handles credential storage, OAuth, tool policy, and audit logging identically, so the governance story is the same either way.
See Connectors overview for the full comparison.
Next: Connect a Connector