Gubbins docs Open Gubbins
The rooms

Toolbox

What your AIs work with: the servers, skills, plugins and standing instructions that make up your setup, so a new one can be brought up to it without you remembering how.

What Gubbins promises here

Gubbins remembers what your tools are and how to reach them. It never holds their keys. Where you have attached a server, Gubbins uses your key from the Vault, server side, and never shows it to anybody, including the AI that asked.

The problem it solves

Anybody using more than one assistant ends up rebuilding the same setup in each of them, from memory, badly. The list of tools you connect, the instructions you always give, the plugins you rely on: all of it lives in your head and in whichever app you configured most recently.

The Toolbox is that setup written down once, in your bank, where any assistant you connect can be pointed at it.

What you can put in it

  • Servers. The MCP servers your assistants connect to, with the address and the command to run them.
  • Skills. Named capabilities you have set up and want carried between assistants.
  • Plugins. Anything installed into an assistant that changes what it can do.
  • Standing instructions. The things you find yourself saying to every new assistant.

Each entry records what the tool is and how to reach it. None of them records a credential, which is the promise above and is the whole reason the Vault is a separate room.

Attaching a server

A server your AIs reach through Gubbins is attached from its own drawer. You pick the secret in the Vault pinned to that server's host, Gubbins completes the handshake with it, server side, and shows you the tools the server declares. You tick the ones your AIs may call, and those appear to every AI you have granted a key, named for the attachment, so an AI is never confused about whose tool it is.

A tool that changes things at the other end is offered to a key only when you allow that tool for that key under Access, one tool at a time, and the row there says what the server claims it changes. Its first call by each key is held for your look in Review, as every attached tool's is. A tool Gubbins cannot tell reads from writes is not offered until you say which.

What an AI sends through an attached tool goes to that server. Gubbins does not keep it and cannot un-send it. Every call is written on the one ledger before it leaves, with the shape of the arguments and never their words. A server that grows a tool after you looked is not offered until you read it again and accept the new tool in Review.

A server that takes sign in can be attached with no key to paste. Press Connect by sign in in its drawer: Gubbins asks the server whether it offers sign in, sends you to the service to approve, and keeps what comes back in the Vault as a secret pinned to that host. Both of its tokens sit under one wrap, Gubbins renews it itself before a call when it is about to expire, with a receipt on the ledger each time, and revoking the secret destroys both. Then you read its tools and attach it exactly as with a pasted key.

A server that runs on your own machine cannot be attached: Gubbins has no way to start it, and a key held for it would have nowhere to go. Your AIs can still be told it exists.

The catalogue

Adding a server does not have to start from a blank box. The Toolbox carries a catalogue drawn from the official MCP registry, so a well-known server can be added by choosing it rather than by finding its address and typing it correctly.

An entry that came from the catalogue is marked as such, so it is clear which details were looked up and which you supplied.

The keys stay out

A tool's address is not a secret. A tool's key is. The Toolbox holds the first and refuses the second, and the app checks what you type: a value that looks like a credential is refused here rather than quietly stored beside a server address.

If a tool needs a credential, that belongs in the Vault, where nothing can read it back out.

What each AI can do

The room also carries a list of the assistants that speak MCP and what each is known to support, so that pointing a new one at your bank is a matter of checking a list rather than trying it and seeing.

The list is data rather than opinion: it says what a client supports, and it does not rank one against another.

Finding something

Each list has a search box, over your own setup, the catalogue and the AI clients alike. The search clears when you switch between them, because words typed to find your own tool do not apply to a list of other people's servers.

Where it is

Toolbox is the third room in the app. Open Gubbins.