The connector has its own dialogue
Adding TransformPipe to an assistant used to open the API keys dialogue — a screen headed "API keys" with a key generator at the top, so a person who chose "MCP connector" had to work out they were in the right place. It is its own dialogue now, with the address, the one-line command and the assistants already connected.
Open the account menu, choose the connector, and the screen is about one thing: connecting an assistant. It used to be the API keys dialogue, on the argument that both are ways into the same account — and that was the wrong argument, because somebody who had just chosen "MCP connector" landed on a screen headed "API keys" with a key generator at the top, and had to work out whether they were in the right place.
The dialogue
The address to add, which is /api/mcp on whatever origin you are actually on rather than a hostname written down somewhere — a preview deployment hands out its own. The one-line command, for a client that takes one. And the assistants currently connected, each with when it was, and a way to cut it off. Nothing here makes a key, and connecting an assistant no longer involves pasting one.
The page the assistant sends you to
A client that supports OAuth sends you here to approve it, and what arrives is a page rendered by the server with no scripts in it at all. It names the account it would act as, and then says, in plain sentences: that it can read the documents on this account and their share links; whether it can save, share and delete, or cannot; that sharing publishes a page anybody holding the link can open; and that it cannot reach your account, your sign-in or your API keys. The address it will send you back to is printed. If the client published its own metadata, where that was read from is printed too.
If every address it wants to be sent back to is on this machine, the page says so and says why it matters: any program on your computer can ask to be sent there, and no server can tell them apart. That is the one thing on the page only the person at the keyboard can judge.
Read-only is read-only
A connection granted documents:read without documents:write is refused on anything that changes something — a 403, with an insufficient_scope header saying what it would have needed. The check sits on the credential rather than on individual routes, and it works from a list of safe methods rather than a list of unsafe ones, so a route added later is covered by default. The first version had that the other way round.
An approval also cannot be driven from somewhere else. A pending request is recorded against the browser session it was shown to and can only be approved from that one; the approving endpoint checks Origin and Sec-Fetch-Site; and a request nobody approved goes stale after half an hour. Any grant can be taken back from the account menu.
Related: converting documents from an assistant, and converting documents with an API.