What the tools can do
One place to connect tools
The built-in MCP server is local to your Mac by default. Connect an AI client with a scoped API key, then grant only the operations and resources it needs. You can also disable a built-in tool for every key.
Other MCP servers
Add a remote HTTPS server, a local HTTP server, or a local stdio command. The app discovers its tools, but grants none of them to a key automatically. Free includes up to three connected servers.
REST API
Call built-in tools through REST routes under the same keys, grants, tool switches, and license rules as MCP. Open the in-app API Reference or export an OpenAPI specification.
Direct network access
The listener stays on loopback by default. Pro can admit direct connections from a private network or specified IP ranges when you explicitly turn it on.
For an upstream MCP server, cleartext HTTP on a private network needs a separate per-server opt-in. It cannot carry header or OAuth credentials. A stdio server is a command the app launches with your macOS permissions; add only commands you trust. Read the security model.
Work with the contents of files
Search text inside files with literal or regular-expression matching, within roots you have allowed. The PDF tools can render pages, merge and split documents, stamp a page, rasterize pages, and list form fields. Image text and barcode recognition run on the Mac through Apple's Vision framework.
PDF form fields can be listed for inspection; the app does not offer a form-filling tool. File writes still follow the root's access setting and the API key's grant.
Check sites and endpoints
Look up DNS and domain expiry, inspect TLS certificates, and probe HTTP(S) endpoints. A website scan checks common exposure and configuration indicators and saves a result that a later scan can be compared against. Scheduled endpoint monitors keep a history of repeated checks.
Free includes DNS and domain lookups and up to three enabled endpoint monitors. TLS inspection, endpoint probes, and website scans require Pro. Endpoint monitor definitions are currently configured without a dedicated editor in the app.
Carry state between runs
Agent State gives an assistant a place to store small facts and checkpoints between sessions. The undo history records supported changes to mail, calendar, contacts, files, and cloud storage so you can inspect and reverse them when the operation allows it.
A configured AI provider can also answer a prompt with access to granted tools, making several tool calls in one request. Its provider receives the prompt and the tool results used for that run.
Pause an outbound email for approval
An SMTP account can require your decision before each send. Review the request in the Approvals screen or from a notification. Denial or timeout sends nothing, and the decision is recorded. This approval step currently applies to outbound mail sends.
These tools also work in automations. See the account setup screens for the services they use.
Back to the overview