Internal agent-runner MCP setup ​
Internal runner sessions should use the in-cluster workflow MCP endpoint and a scoped per-agent bearer token.
Config ​
Set LTINTEG_MCP_SERVERS to include the workflow MCP server:
json
[
{
"name": "ltinteg-workflow",
"server_url": "http://ltinteg-workflow-mcp.ltinteg-product:8000/mcp",
"transport": "streamable_http",
"headers": {
"Authorization": "Bearer AGENT_TOKEN"
}
}
]Inject AGENT_TOKEN from a Secret or token broker. Do not commit it in workflow config.
Why internal URL ​
Use the service URL to avoid public ingress, public DNS, and hosted-user OAuth for in-cluster traffic. This also makes token ownership explicit per agent.
Smoke test ​
- Launch a runner session with the MCP config.
- Confirm the runner opens a Streamable HTTP session.
- Confirm
whoamireturns the agent identity. - Confirm
list_workflow_typesand a harmless workflow run work.
Related workflows ​
agents.session-launchagents._session-launch.load-mcpagents.mcp-server-call-toolagents.mcp-server-refresh
