ConfigCat for AI agents
ConfigCat manages feature flags, letting a team control feature rollouts and configuration values across environments without redeploying code each time. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in ConfigCat.
Check a flag's current value
Check a feature flag's current value in an environment before deciding to change it.
Turn on a flag in an environment
Update a flag's value in a specific environment to roll out a feature to users.
Confirm before deleting a flag
Confirm before deleting a flag, since any code still checking it would default to off.
10 ConfigCat actions, graded by risk.
Every ConfigCat action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
5Look things up. Allowed by default.
- configcat.list_settingsList Flags and Settings
- configcat.get_product_contextGet Product Context
- configcat.get_setting_value_v2Get Environment Setting Value V2
- configcat.list_account_hierarchyList Account Hierarchy
- configcat.list_environment_values_v2List Environment Values V2
write
4Create and change things. Allow, or ask the user first.
- configcat.create_settingCreate Flag or Setting
- configcat.update_setting_metadataUpdate Flag Metadata
- configcat.patch_setting_value_v2Patch Environment Setting Value V2
- configcat.replace_setting_value_v2Replace Environment Setting Value V2
destructive
1Delete, cancel or archive. Ask first, or deny outright.
- configcat.delete_settingDelete Flag or Setting
ConfigCat in three steps.
- 01Your users connect ConfigCatThey add their ConfigCat api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Flag or Setting” can wait for the user, and “delete Flag or Setting” can be denied outright.
- 03Any agent can actYour agent calls ConfigCat through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('configcat', { read: 'allow', write: 'ask', // create_setting destructive: 'deny', // delete_setting }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How ConfigCat connects.
Users add their ConfigCat api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same ConfigCat connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use ConfigCat from any agent.
ConfigCat and Arc0, answered.
Can I use ConfigCat with Claude, ChatGPT or Cursor?
Yes. Connect ConfigCat to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the ConfigCat actions you allow.
How do users connect ConfigCat?
Users add their ConfigCat api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which ConfigCat actions can my agent take?
10 in total: 5 read, 4 write and 1 destructive, such as “create Flag or Setting”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in ConfigCat?
Yes. Actions like “delete Flag or Setting” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call ConfigCat too?
Yes. The same ConfigCat connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug ConfigCat into your agent.
Your users connect ConfigCat once, under your brand. Your agent gets 10 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan