TroubleshootingIn-depth scenario content20 min readDecision matrix

Choosing an Integration Channel: API, Share Link, Embed or MCP

Compare API access, share links, embedded chat, and MCP for FastGPT using authentication, user experience, and integration requirements.

When this decision has to be made

You must make this decision when you need to expose the capabilities of FastGPT-built applications to external users, or expose internal tools to external users via FastGPT. If you select an integration method before clarifying external scenario details like user scale, permission requirements and security standards, you will need to refactor your access link later. This increases development costs, requires reconfiguring permission systems and disrupts existing business stability. Delaying selection until external collaboration projects launch will cause project delays, missed service delivery timelines and lost business opportunities. You also need to make this decision when integrating multiple external tools, or enabling cross-team or cross-organization application calls. Clarifying access channel boundaries avoids permission chaos and call failures. Additionally, if your enterprise needs to meet compliance requirements such as data privacy and access auditing, different integration channels carry different compliance costs. You must select a channel in advance to align with these requirements. Per FastGPT’s MCP tool access requirements, if you need to call internal or local tools, you must confirm the appropriate access plan in advance. Without this, you cannot achieve secure internal tool calls, limiting your application’s deployment scenarios.

Criteria matrix

CandidateAPI Documentation SupportAuthentication MethodNetwork Reachability RequirementIntegration ScenariosDevelopment CostSecurity Protection Capabilities
API CallDevAPI and System OpenAPI documentationConfigure the appropriate API Key and required application contextThe caller can reach the FastGPT serviceAPI integration with systems and workflowsVaries with integration scopeValidate authentication, request restrictions, and access boundaries for each endpoint
Share LinkShare integration instructionsCustom share identity verification is a commercial-edition feature; uid must be at most 255 UTF-8 bytes and exclude pipe, slash, and backslash charactersUser browsers can reach the share page and required servicesChat interactions with a specified applicationLow for basic sharingValidate identity restrictions and chat file allowlists for the application
EmbedEmbedding instructionsExplicitly integrate share-link authentication; custom share identity verification is a commercial-edition featureUser browsers can load FastGPT pages and resourcesAdd chat capabilities to existing webpagesDepends on page and identity integrationValidate share authentication, CSP, and iframe policies; handle cross-origin API requests according to configuration
MCPMCP publishing and tool integration instructionsConfigure an app publishing key or remote tool authentication headers according to call directionClients can reach published app endpoints; FastGPT can reach remote tools it callsPublish apps to MCP clients or integrate MCP tools into workflowsDepends on client compatibility and tool integrationValidate app-publishing and remote-tool permission boundaries separately

Why each criterion matters

Each criterion directly impacts your integration efficiency, security, deployment complexity and business alignment.

API Documentation Support

API documentation affects integration efficiency. API Call provides DevAPI and System OpenAPI documentation for deep system integration. Share Link and Embed have their own integration instructions for quickly adding chat entry points. Use a compatible MCP client; custom adapters are needed only for unsupported integration requirements.

Authentication Method

Configure authentication explicitly throughout the call chain. Use the appropriate API Key for API access. Share Link and Embed use share-link authentication, and custom share identity verification is a commercial-edition feature. Configure keys or authentication headers separately for MCP app publishing and remote tool calls, then validate the resulting resource permissions.

Network Reachability Requirement

The caller or user browser must be able to reach the required service. Choose private-network or public deployment according to the business scenario, and configure appropriate TLS and access controls for public services. For app publishing through the independent SSE MCP service, SSE_MCP_SERVER_PROXY_ENDPOINT sets the client-facing address. For remote tool calls, validate reachability from FastGPT to the tool service.

Integration Scenarios

Integration scenarios determine the applicable scope of each access channel. API Call supports integration into any system or workflow, enabling complex business logic, ideal for enterprise-grade deep integration. Share Link only supports direct chat access, suitable for quickly building external chat services. Embed supports embedding into webpages, ideal for adding FastGPT chat capabilities to existing websites. MCP supports integrating tools into workflows and exposing application calls externally, ideal for consolidating multiple internal tools.

Development Cost

Development costs depend on business logic, identity integration, and client compatibility. Basic Share Link publishing can provide a quick validation path. API integration requires adapting application logic, Embed requires page and identity integration, and MCP requires configuring a compatible client or tool server and its authentication.

Security Protection Capabilities

Security validation should cover API permissions, share identity checks and upload-type restrictions, embedded-page policies, and the actual resource permissions throughout MCP calls. Verify these controls against the application and deployment configuration.

The cost of switching later

Once you have selected an integration channel, switching will incur multiple types of costs. First, identity and conversation continuity: API and Share Link conversations are persisted on the server. Validate appId, chatId, user identifiers, and read authorization, and migrate or map identities and conversations where needed. Second, permission and call-record changes depend on the actual integration. Review API Keys, share authentication, MCP addresses, and tool permissions for the new channel. Third, cutover and validation: test through a validation environment or parallel entry point, then schedule a switching window according to identity and data-continuity requirements. Cover functionality, performance, access controls, and existing call scenarios. Additionally, you will face user adaptation costs: existing users familiar with Share Link will need guidance to adopt the new access method, increasing operational overhead.

When this decision can wait

You can delay this decision in the following scenarios:

  1. If your enterprise only uses FastGPT’s application capabilities internally, with no need to expose services or integrate externally.
  2. If your external service scenarios are unclear, such as undetermined user scale, permission requirements or security standards. You can use a temporary access method like FastGPT’s internal chat interface first, and finalize selection once scenarios are clarified.
  3. If your project timeline is tight and you do not have time to select an integration channel, you can use a default option like Share Link first, and optimize after the project launches.
  4. If your external service is only temporary, such as short-term external demos or testing, with no need for long-term maintenance of the access channel, you can delay formal selection.

Note that if you plan to launch external services later, you still need to plan integration channel selection in advance to avoid compatibility issues later.

Keep reading

References

Next steps

The criteria above can be checked against public documentation and a test deployment. To decide against a specific workload, data boundary and operations setup, contact sales for an assessment; the cloud service can be used first to validate feasibility before choosing a deployment form.