Agents and AI clients: which one you need
There are two ways to reach Floxar's MCP tools: a person connects an AI client they use, or an account admin registers an agent that acts on its own. Both reach the same account URL, https://mcp.floxar.com/a/<account_id>, and the same tools, and both are limited by a role. The rest differs.
When to use whichโ
- Connect an AI client when you want to work in Floxar yourself from an AI app such as Claude, ChatGPT or Cursor. You sign in from the app with your own login, and everything the app does is recorded as yours. You need no registration. See Connecting an AI client.
- Register an agent when software acts on its own, under an identity of its own: an AI worker, an integration or a scheduled job that runs without a person signing in. See Registering an agent.
If you are unsure, ask who should be accountable for the work in the audit trail. If it is you, connect a client. If it is the software, register an agent.
How they differโ
| What differs | A person's AI client | An agent |
|---|---|---|
| Who acts | The person, through the client | The agent, under its own identity |
| How it gets in | Sign-in in a browser, then consent | Client ID and secret, exchanged for a token at tokens.floxar.com |
| Set up by | The person, in their client | An account admin, in the Agent Registry |
| What limits it | The person's role, narrowed by what the person allowed and what the account lets clients have | The agent's role, and the level of its organization or group assignments inside them |
| Account switch | MCP connections must be on for the account | None; the registration is the switch |
| Staying connected | Renews on its own; signs in again after 7 days unused or 30 days | Requests a new token before each hour is up |
| Ending it | The person disconnects their applications from their profile's Security page, or an admin revokes the connection under MCP Connections | An admin rotates, deactivates or deletes the agent |
| Recorded as | The person, marked as made through MCP with the client's name | The agent, marked as made through MCP |
What stays the sameโ
- The URL. One account URL per account, for both. A connection or a token for one account's URL does not work at another's.
- The tools and the checks. The same tools, and the same permission checks on every call. Neither a client nor an agent gets more than its role allows, and a tool the role does not allow answers
PERMISSION_DENIED. - The audit trail. Every change made through MCP is recorded as made through MCP, under whoever made it.
Last reviewed: 2026-09-30