# Retool + SFTP (password-based auth) — Pipedream Connect

> Connect a user's Retool and SFTP (password-based auth) accounts and expose tools for both apps directly in your product or your agent.

- Apps: Retool (`retool`) + SFTP (password-based auth) (`sftp_password_based_auth`)
- This page (HTML): https://pipedream.com/apps/retool/integrations/sftp-password-based-auth
- One `external_user_id` owns both connected accounts, and each account stays independently revocable.

## One session, both toolsets (recommended)

- Endpoint: `https://remote.mcp.pipedream.net/v3`
- Headers: `Authorization: Bearer <token>` · `x-pd-project-id` · `x-pd-environment` · `x-pd-external-user-id` · `x-pd-app-slug: retool,sftp_password_based_auth`
- `x-pd-app-slug` takes a comma-separated list, so `retool,sftp_password_based_auth` is one session on one transport. Both toolsets arrive from a single `listTools()`, and a tool is called exactly as it would be in a single-app session.

```ts
import { Client } from "@modelcontextprotocol/sdk/client/index.js"
import { StreamableHTTPClientTransport } from "@modelcontextprotocol/sdk/client/streamableHttp.js"
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const accessToken = await pd.rawAccessToken

const transport = new StreamableHTTPClientTransport(
  new URL("https://remote.mcp.pipedream.net/v3"),
  {
    requestInit: {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "x-pd-project-id": process.env.PIPEDREAM_PROJECT_ID!,
        "x-pd-environment": "production",
        "x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
        "x-pd-app-slug": "retool,sftp_password_based_auth",
      },
    },
  },
)

const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)

const { tools } = await mcp.listTools()

// One list, both toolsets: Retool and SFTP (password-based auth) tools arrive
// together, each keyed by its own app's slug.

// e.g. run Create Organization User Attribute:
const result = await mcp.callTool({
  name: "retool-create-organization-user-attribute",
  arguments: {
    name: "Attribute Name",
    label: "Attribute Label",
  },
})
```

Docs: [MCP guide](https://pipedream.com/docs/connect/mcp/developers.md)

## Both apps from your backend

```ts
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const externalUserId = "{external_user_id}" // any stable ID for this user in your system

const [retoolTools, sftpPasswordBasedAuthTools] =
  await Promise.all([
    pd.components.list({ app: "retool" }),
    pd.components.list({ app: "sftp_password_based_auth" }),
  ])

// One external user owns both connected accounts, so either app's tools
// run on their behalf with the same externalUserId.
```

Docs: [Managed auth guide](https://pipedream.com/docs/connect/managed-auth/quickstart.md) · [Tools guide](https://pipedream.com/docs/connect/components.md)

## Retool

- API slug: `retool` (use in MCP headers and tool keys)
- Auth: API key (Pipedream-managed)
- Categories: Web & App Development
- Website: https://retool.com/
- App page (HTML): https://pipedream.com/apps/retool
- Tools: 3 actions · 0 triggers

Full tool list, API proxy, and SDK quickstart: https://pipedream.com/apps/retool.md

### Actions (3)

- [Create Organization User Attribute](https://pipedream.com/apps/retool/actions/create-organization-user-attribute.md) — `retool-create-organization-user-attribute`
- [Create User](https://pipedream.com/apps/retool/actions/create-user.md) — `retool-create-user`
- [Trigger Workflow](https://pipedream.com/apps/retool/actions/trigger-workflow.md) — `retool-trigger-workflow`

## SFTP (password-based auth)

- API slug: `sftp_password_based_auth` (use in MCP headers and tool keys)
- Auth: API key (Pipedream-managed)
- Categories: File Storage
- Website: https://en.wikipedia.org/wiki/SSH_File_Transfer_Protocol
- App page (HTML): https://pipedream.com/apps/sftp-password-based-auth
- Tools: 1 action · 1 trigger

Full tool list, API proxy, and SDK quickstart: https://pipedream.com/apps/sftp-password-based-auth.md

### Actions (1)

- [Upload File (Password Auth)](https://pipedream.com/apps/sftp-password-based-auth/actions/upload-file.md) — `sftp_password_based_auth-upload-file`

### Triggers (1)

- [New Remote Directory Watcher (Password Auth)](https://pipedream.com/apps/sftp-password-based-auth/triggers/watch-remote-directory.md) — `sftp_password_based_auth-watch-remote-directory`

---

- Retool: https://pipedream.com/apps/retool.md · SFTP (password-based auth): https://pipedream.com/apps/sftp-password-based-auth.md
- All apps: https://pipedream.com/apps — index: https://pipedream.com/llms.txt
- Pipedream docs for agents: https://pipedream.com/docs/llms.txt
