Cato Networks is a cloud-native SASE platform that combines SD-WAN and network security services, managed through the Cato Management Application (CMA).
Agen.co connects to Cato through Cato's own hosted remote MCP server as an Official connector. The server authenticates with a Cato API key, not OAuth, so there is no sign-in screen or callback URL — you create a key in the CMA and paste it into Agen.co. What agents can see and do is limited by the permissions of that key.
Prerequisites
Prerequisites
- A Cato account with access to the Cato Management Application (CMA).
- An administrator who can create an API key. Creating a service API key requires an admin with the Editor role.
Cato offers two key types. Either works with the MCP server:
- Admin API key — a personal key tied to your own CMA admin account, for personal or interactive use. It inherits your permissions, and it stops working if your admin account is disabled or deleted.
- Service API key — a shared key tied to a Service Principal, for automation and production use. It is not tied to a person and cannot be used to sign in to the CMA.
Cato recommends a dedicated key for MCP, rotated regularly. For a connector that agents use continuously, a service API key is the better fit.
To create a service API key:
- In the CMA, go to Account → Administrators, click New, select Create New → Create as Service Principal, choose a Role and any specific sites and users, and click Apply. Skip this step if you already have a Service Principal.
- Go to Resources → Service API Keys and click New.
- Select the Service Principal, and enter a Key Name.
- To make the key read-only, select Downgrade to View. Leave it off only if agents must be able to change configuration.
- Optionally, set an expiry date in Expires at. Cato recommends one for keys with Edit permissions.
- Click Apply, then copy the key from the pop-up window.
To create an admin API key instead, go to Resources → Admin API Keys and follow the same steps from step 2, without selecting a Service Principal.
The key is shown only once
The key is shown only once
Copy the API key from the pop-up before you close it. Once the window is closed, the key value cannot be retrieved again. If you lose it, create a new key.
IP restrictions
IP restrictions
Allow access from IPs defaults to Any IP address. If you restrict the key to specific IP addresses, Cato rejects calls from any other address, including Agen.co's, and the connector will fail. Leave the default unless you can allow Agen.co's outbound addresses.
In the Agen.co portal, go to Connectors → My connectors and click Add connector.
In the Select connector drawer, search for
Cato Networksand select it. The Add Cato Networks panel opens.Fill in the fields:
Field Required Description Instance Slug Yes Namespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled withcato-networks. Use lowercase kebab-case. You can change it later from the connector's settings.API key Yes A Cato Networks API key with the required permissions. Agen.co sends it in the x-api-keyheader.Click Connect. Agen.co connects to Cato's MCP server with the key, and the panel switches to Select the tools to import from Cato Networks. Every tool is toggled on; turn off any you don't want to import, then click Add.
The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved.
The same Cato endpoint, https://api.catonetworks.com/api/v1/rest/mcp, serves every CMA instance, so there is no region or account field. One key belongs to one Cato account. To connect a second account, add the Cato Networks connector again with a different Instance Slug and that account's key.
Cato's MCP server exposes structured Cato tools that follow the same role-based access as the Cato API, and its tool list is updated by Cato without any change on your side. Tool lists need an API key, so none is reproduced here — the tool selection screen after Connect shows exactly what your key serves.
| Area | What it covers |
|---|---|
| Query | Read security events, site operations, WAN link health, and application performance, for as far back as your account's data retention allows |
| Configuration | Change configuration, only when the key has Edit permissions |
A key with Downgrade to View can run only read-only queries. Whatever the key is not permitted to do, agents cannot do either.
Enabling the Cato Networks connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.