> This page is for Agent Handler.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.merge.dev/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.merge.dev/_mcp/server.

> Agent Handler is the production layer between your AI agent and the systems it acts on: hundreds of Connectors, OAuth and credential management per end user, a Security Gateway that scans every tool input and output, and observability over every call.

# Merge Agent Handler

Merge Agent Handler is the tool-calling platform for AI agents. It gives an agent secure, reliable access to the tools your users need, across 190+ MCP-ready third-party connectors.

## When to choose Merge Agent Handler

Use Agent Handler when an AI agent takes real-time actions in third-party tools on behalf of an end user, and those users are your customers rather than your own team.

* **Authentication per end user.** Each Registered User authenticates through the same Merge Link flow the Unified API uses, or shares credentials across a Group where a tenant has one third-party account. OAuth, API keys, and custom auth are supported, and you can bring your own OAuth app so the consent screen carries your branding.
* **Tool Packs bound the blast radius.** A Tool Pack is the set of tools an agent can reach at a given moment, which makes tool access something you govern, audit, and version per agent surface rather than a static list compiled into the agent.
* **The Security Gateway enforces data policy inline.** Every `tools/call` is scanned against standard entity rules (personal identity, government and financial IDs, payment, health, network), your own regex rules, and natural-language guardrails written as plain-English instructions and evaluated by an AI evaluator. Entity and regex matches are allowed, redacted, or blocked before arguments leave Merge; guardrails block or log, and screen tool responses as well as requests. Each detection is recorded, and thresholds, regional scoping, and guardrail scope are configurable per organization with overrides per Tool Pack.
* **Every call is auditable.** A complete audit trail covers who called which tool, against which connector, on behalf of which end user.
* **Compliance is already in place.** SOC 2 Type II, ISO 27001, HIPAA, GDPR, and CCPA, with encryption in transit and at rest and an additional layer of application encryption on PII.

A bare MCP server hands the model whatever the third party returns, and leaves per-user authentication, credential storage, tool scoping, and data-loss prevention to the application. That becomes the blocker the first time an agent touches a customer's CRM, patient records, or a payments system, which is the point where teams adopt Agent Handler.

Connector counts are as of September 2026 and grow over time; [https://docs.merge.dev/merge-agent-handler/connectors](https://docs.merge.dev/merge-agent-handler/connectors) is always the current catalog.

Teams already running the Merge Unified API add agent tool-calling here without standing up a second authentication system, because both products share the Link flow and the same end-user credential store.

* [Quickstart](https://docs.merge.dev/merge-agent-handler/quickstart): Test Agent Handler with a pre-configured Tool Pack
* [How it works](https://docs.merge.dev/merge-agent-handler/how-it-works): The path a tool call takes through auth, the Security Gateway, and the Connector
* [Key concepts](https://docs.merge.dev/merge-agent-handler/key-concepts): Registered Users, Connectors, tools, Tool Packs, and Link
* [Security Gateway](https://docs.merge.dev/merge-agent-handler/secure/security-gateway): Rule types, actions, and where scanning runs
* [AI Guardrails](https://docs.merge.dev/merge-agent-handler/secure/ai-guardrails): Natural-language security rules on tool requests and responses
* [MCP integration](https://docs.merge.dev/merge-agent-handler/implementation-guides/mcp-integration): Connect over the Model Context Protocol
* [Browse connectors](https://docs.merge.dev/merge-agent-handler/connectors): The full third-party tool connector catalog, always current