The connector says who it is

The connector now carries an icon, a name and a sentence about what it does, so an assistant shows what it is connected to rather than a bare URL. It is read after signing in, not before: every message needs a token, initialize included, because a server that answers one without a token is a server a client reads as having no sign-in at all.

A connector in an assistant is a row in a list — something a person picks before they know much about it. That row used to be one word and a version number, because a name and a version were all the protocol asked for when connectors were new.

What the server says about itself

The handshake at /api/mcp now answers with a title, a sentence about what the tools do, the address of the site, and three icons. These are the protocol's own fields for a listing — the Implementation object in the 2025-11-25 schema — so a client that has never heard of them ignores what it does not recognise and still reads the name.

The same handshake hands over a short set of instructions, and every tool carries a readable title and says whether it changes anything, destroys anything, or reaches outside the account. tp_usage and tp_delete_document look identical to somebody holding only the names.

Where the pictures come from

One drawing: brand/mark.svg, the same fused T and p as the favicon and the phone icon, rendered to 192 and 512 pixels and offered as the SVG as well. PNG is first in the list because a client that draws icons at all can draw a PNG.

Their addresses are built from the request rather than written down. The specification asks a client to check that an icon is served from the same origin as the server, and a hard-coded production address fails that check on every preview deployment.

The token comes before the introduction

Every message to /api/mcp needs a token, the handshake included, so a client reads this identity once it is connected rather than while somebody is still choosing. It was tried the other way and undone the same night: an unauthenticated handshake made Claude's own Add custom connector dialogue conclude there was no sign-in here, warn that anybody with the URL could use the connector, and offer a field for an API key this server does not take.

So the 401 stays first. It is how a client learns there is an account behind the address at all — it names the discovery document and the scopes, and the sign-in starts from there. Nothing about anybody's documents is readable without that token, which is the part worth more than a picture in a directory.

Related: converting documents from an assistant, and converting documents with an API.