Connect an Agent
An agent is an AI application outside the Panel that reads the site's content and prepares changes to it – Claude Code, claude.ai, ChatGPT, Cursor, or any other agent that supports remote MCP servers. It works as the Kirby user who connected it, within that user's role, and by default its edits wait in the Panel until an editor publishes them.
The agent brings its own AI model, so the site needs no AI provider for it.
Step 1: Turn On Agents
Set the agents option:
return [
'johannschopplich.copilot' => [
'agents' => true
]
];
The Panel menu then has an Agents entry. Its view shows the MCP URL, which you add to your agent, and checks whether agents can reach it. By default, the MCP URL is your site's URL followed by /api/copilot/mcp:
https://example.com/api/copilot/mcp
Step 2: Add the MCP URL to Your Agent
Claude Code
Add the MCP URL as an HTTP server:
claude mcp add --transport http kirby https://example.com/api/copilot/mcp
Then run /mcp in Claude Code, or claude mcp login kirby in the terminal, to connect. Your browser opens the Panel's login.
Cursor
Add the MCP URL to .cursor/mcp.json in your project, or to ~/.cursor/mcp.json for all projects:
{
"mcpServers": {
"kirby": {
"url": "https://example.com/api/copilot/mcp"
}
}
}
Cursor then takes you through the same Panel login.
Other Agents
Any agent that supports remote MCP servers over HTTP with OAuth connects the same way: add the MCP URL where the agent takes remote MCP servers, and it sends you to the Panel's login. Where that setting sits, and which plans include it, differs per agent – claude.ai and Claude Desktop take the URL as a custom connector, ChatGPT as an app in developer mode.
claude.ai, Claude Desktop, and ChatGPT reach the MCP URL from their own servers, so they need a site that's reachable from the internet.
Step 3: Approve the Connection
After you log in to the Panel, the consent view names the agent, the site, and the account the agent will work as:
It lists four permissions:
| Permission | Preselected | Lets the agent |
|---|---|---|
| Read content | Always | Read the pages, files, and fields your role can access |
| Prepare changes | Yes | Write unsaved changes and create drafts |
| Publish changes | No | Publish or discard changes, change a page's status, slug, or parent, and upload files |
| Delete content | No | Delete pages and files |
A permission is disabled when your role has none of the Kirby permissions behind it – Delete content, for example, without pages.delete and files.delete. Click Connect, and the browser returns to the agent.
Limit Agents by Role
Every user who can access the Panel can connect agents. To keep a role out, take away its access to the Agents view in the role's blueprint:
title: Client
permissions:
access:
copilot-agents: false
Agents that the role's users already connected stop working too.
A role can also withhold Publish changes or Delete content from agents while its users still publish and delete in the Panel:
title: Editor
permissions:
johannschopplich.copilot:
agentsPublish: false
agentsDelete: false
Connections that already have the permission lose it on their next request.
Manage Connections
The Agents view lists your connections: the agent, the permissions you gave it, and when it was last active. Next to the agent's name is the domain it identified with, or Unverified when the agent chose its name itself, plus local app when it runs on your computer. Admins see every user's connections, with the account each one works as, and can revoke any of them.
Revoke in a connection's menu ends it at once.
A connection also ends when:
- the agent goes unused for 30 days
- you change your password
- your account is deleted
To connect the agent again, start its login again – in Claude Code through /mcp – and approve the connection in the Panel.
When the site's URL changes, for example from http:// to https://, agents have to connect again – revoke their old connections in the Agents view.
To give a connection other permissions, choose Change permissions in its menu. Only the user who connected it can, within what their role allows. Agents keep the tools they loaded when they connected. In ChatGPT, refresh the app in its settings and start a new chat. In claude.ai, disconnect the connector and connect it again, which asks for the permissions anew.
Troubleshooting
Fix generation timeouts, API key errors, malformed blocks output, and missing inline suggestions in local and production setups.
Permissions & Review
What each connection permission allows, how an agent's changes wait for review, and what to expect while you and an agent work on the same page.