Adding Connect to Claude
Connect is a remote MCP server at https://connectbyjbrh.com/mcp. Public documentation tools are anonymous; protected business tools use Connect OAuth when the Claude host supports delegated MCP authorization.
Connection#
Configure
https://connectbyjbrh.com/mcpas the remote MCP endpoint.Result The client discovers the current production registry.
Use a protected business tool.
Result The host follows Connect OAuth metadata and PKCE when authorization is required.
Consent only to the intended business and scopes.
Result Protected calls stay inside that authorization and normal Connect rules.
Portable bundle#
The portable Agent Plugins bundle includes plugin.json, mcp.json and reusable Agent Skills. It connects to the same canonical MCP endpoint and embeds no credential.
Use the tools in business order#
- Confirm the business profile before interpreting a name, channel or readiness state.
- Read readiness and runtime before saying Connect is live; configured credentials alone are not operational proof.
- Search the person or record before creating related work, so a follow-up, case or opportunity is not duplicated.
- For a requested state change, call the narrow tool and report the returned stored state rather than the requested state.
- When a tool says held or refused, keep that outcome. Do not retry through another tool to manufacture approval.
Skills in the bundle describe these sequences, but skills do not add authority. The MCP registry remains the executable contract. If a skill mentions a capability that the deployed server does not enumerate, the correct result is a release mismatch, not an invented tool call.
Boundaries to test before publishing#
- A read-only authorization can inspect business state but cannot make a protected write.
- A protected call cannot name a sibling business through an extra argument.
- An identity already belonging outside the authorized business cannot be silently adopted by the create-person tool.
- No production diagnostic Owner tool appears in discovery.
- No direct outbound email, messaging, call, payment or approval action appears in the marketplace v1 tool set.
Those checks matter more than whether the client renders the plugin name and icon. The package is ready for directory review only when the deployed endpoint matches the same versioned contract and the positive and negative reviewer cases pass against that live runtime.
Questions#
Does Claude need a Connect API key in the package?
No. Delegated protected access uses OAuth.
Do public docs and private data share authority?
No. Public tools are anonymous; protected tools verify scope and business binding.
Are owner diagnostics exposed?
No. Production registry construction excludes them.