docs(connector): name the Claude.ai auth mode and OAuth client to pick (#1914)
Claude.ai's Add custom connector dialog auto-detects Authentication
"None" for a server that answers the handshake without credentials,
which is exactly what lazy auth does; a user who accepts that default
gets an error instead of the sign-in on the first company-scoped call.
State the two correct choices ("Required when the server asks", DCR
client registration) in the bridge README and the plugin's CONNECTORS.md.
Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Jakob Wennberg
Claude Fable 5
parent
0743717033
commit
a1af9adb05
@@ -8,7 +8,8 @@ This plugin bundles exactly one connector: the Accounted MCP server, the same se
|
||||
|
||||
## How the connection works
|
||||
|
||||
- **Lazy authentication.** The server answers `initialize`, `tools/list` and the documentation tools (`accounted_search_tools`, `accounted_list_skills`, `accounted_load_skill`) without any credentials. The first company-scoped call returns an authentication challenge, which Claude Code surfaces as `/mcp` → authenticate.
|
||||
- **Lazy authentication.** The server answers `initialize`, `tools/list` and the documentation tools (`accounted_search_tools`, `accounted_list_skills`, `accounted_load_skill`) without any credentials. The first company-scoped call returns an authentication challenge, which Claude Code surfaces as `/mcp` → authenticate and Claude.ai as an inline Connect prompt.
|
||||
- **Adding it by hand in Claude.ai** (Settings → Connectors → Add custom connector): choose Authentication **"Required when the server asks"** (not the auto-detected "None") and OAuth client **"register one automatically" (DCR)**; the server does not advertise CIMD yet. No extra headers, Streamable HTTP.
|
||||
- **Account creation inside the sign-in.** A user who has no Accounted account creates one on the sign-in screen the challenge opens (BankID or e-mail + 2FA). No visit to the website first. `/accounted:setup` walks the whole flow, including creating the company from the conversation.
|
||||
- **Every write is staged.** Write tools create a pending operation with a preview; nothing is booked until the user approves, either in chat via `accounted_approve_pending_operation` or in the web app.
|
||||
- **Data stays in the user's tenant.** The connector only ever sees companies the signed-in user is a member of, enforced server-side per call.
|
||||
|
||||
@@ -63,8 +63,18 @@ codex mcp add accounted --url \
|
||||
```
|
||||
|
||||
Claude.ai and Claude Desktop: Settings > Connectors > Add custom connector,
|
||||
paste the URL. The connector works before you connect (documentation tools);
|
||||
the first company-scoped call opens the Connect prompt.
|
||||
paste the URL, then in step 2 choose:
|
||||
|
||||
- **Authentication: "Required when the server asks."** Claude auto-detects
|
||||
"None" because the server answers the handshake without credentials; with
|
||||
"None" the first company-scoped call shows an error instead of the sign-in.
|
||||
- **OAuth client: "No client ID, register one automatically" (DCR).** The
|
||||
server does not advertise Anthropic's hosted client metadata (CIMD) yet.
|
||||
- No additional headers; transport stays Streamable HTTP.
|
||||
|
||||
The connector works before you connect (documentation tools); the first
|
||||
company-scoped call opens the sign-in prompt, where a new user creates the
|
||||
account.
|
||||
|
||||
## Compatibility
|
||||
|
||||
|
||||
Reference in New Issue
Block a user