





The most complete tool-calling platform for AI agents
We’ve solved the hardest part of agents: secure and reliable access to the tools your users need
Thousands of pre-built tools

Built-in authentication
Scoped access for every agent

Enterprise-grade security controls
How Perplexity uses Agent Handler in their product
“Accurate AI is Perplexity’s core differentiator, and our users increasingly expect it in all of their apps and tools. Merge allows us to meet that ballooning demand while still maintaining our strict standards of data security. With Agent Handler, we can bring a broader set of data connectors to our users faster and constantly expand what our customers can do with Perplexity Enterprise Pro.”

Ready to try it out?
Whether you’re an engineer experimenting with agents or a product manager looking to add tools, you can get started for free now
FAQ
Merge Agent Handler is a platform for securely connecting AI agents to enterprise tools at scale.
Teams building AI agent products get production-grade connectors to hundreds of enterprise systems, built-in authentication, and observability tooling without needing to build and maintain on their own.
IT and security teams get a context and governance layer for employee AI: SCIM-based provisioning through their existing IdP, policy guardrails and DLP on every tool call, and a searchable audit trail of every action taken by employee-facing AI tools.
Individuals can install Agent Handler as an MCP server for Claude, Cursor, ChatGPT, or any tool that supports remote MCP servers. From there, they create Tool Packs and authenticate connectors to the personal systems they want their agents to access.
Agent Handler is built on MCP and works with any agent framework.
Yes. Security is built into every facet of Agent Handler. This includes built-in authentication for reliable connections, DLP (data loss prevention) scanning on tool-call inputs and outputs, and policy-based guardrails that block, redact, or mask sensitive data before it reaches a model or third-party system. Merge runs regular penetration tests, weekly automated security scans, and maintains SOC 2 compliance. Full audit logs are available on all plans. You can learn more about our security practices here.
Agent Handler is free to start. Pricing plans are usage-based. Users receive credits each month, which are consumed as your agents make tool calls. Enterprise plans include custom pricing for higher volume, or user seats. You can learn more on our pricing page.
Three audiences use Agent Handler:
- Engineering and product teams building agent-powered products. They need reliable, maintained connectors to enterprise systems and don't want to build or maintain integration infrastructure.
- IT and security teams at organizations where employees use AI tools to access internal systems. They need centralized access control, DLP enforcement, and an audit trail.
- Individual users and developers who want to connect tools like Claude, Claude Code, Cursor, or ChatGPT to the systems they work in every day. They install Agent Handler as a remote MCP server, create Tool Packs, and authenticate connectors to their personal systems.
MCP is the protocol that lets agents call tools. Agent Handler is the platform that makes MCP production-ready.
Raw MCP servers are typically built to ship quickly. They are often unmaintained, lack production-grade error handling, and provide no authentication, DLP, or observability out of the box. Agent Handler adds the enterprise layer on top: maintained connectors with detailed error handling, built-in authentication and credential management, DLP scanning on every tool call, scoped access control via Tool Packs, and searchable audit logs.
Rather than sourcing and maintaining a separate MCP server for every tool, you get one connection point for everything your agents need, with the governance infrastructure to run it safely in production.
Agent Handler serves three use cases:
Building agent products: Production-ready connectors to Salesforce, Jira, Slack, GitHub, Hubspot, and hundreds more. Authentication, permissions, and observability handled in one platform.
Governing employee AI: Centralized access control and provisioning, DLP enforcement on every tool call, and a full audit trail for compliance and incident response.
Personal AI setup: Install as an MCP server for Claude, Cursor, ChatGPT, or any tool that imports MCP servers. Authenticate the connectors you want and let agents take real actions on your behalf.
Agent Handler sits between employees’ AI tools and the enterprise systems they connect to. Governance is enforced at the tool call layer with no changes to how employees work.
Provisioning: Connect to Okta, Azure AD, or any SCIM-compatible identity provider, then provision tool access for employee AI.
DLP and guardrails: Every tool call input and output is scanned for sensitive data before it reaches a model or external system. Block, redact, or log calls based on rules your organization defines.
Audit trail: Every action is logged with identity, arguments, downstream API calls, and outcome. Searchable and filterable for compliance reviews and incident response.
Learn more about Agent Handler for employees here.
Yes. Install Agent Handler as a remote MCP server for Claude, Claude Code, Cursor, ChatGPT, or any other interface that allows you to import remote MCP servers. From there, create registered users and Tool Packs, then authenticate the connectors you want your agent to access. Personal use follows the same free and pro tiers as any other user. No separate signup or pricing tier required. You can get started at merge.dev/agent-handler.
Yes. Along with the many out-of-the-box connectors we offer, you can easily import any public MCP server into Agent Handler.


























