claude.ai's two-step "Add custom connector" dialog probes the server URL
without credentials and pre-fills the Authentication choice from the
answer. Our lazy-auth endpoint (issue #1814) answers 200 on an anonymous
initialize, which the dialog reads as an authless server: it suggests
"None", and a connector added with that default never opens the sign-in
when the challenge arrives later. Per Anthropic's connector docs a 401 is
the only answer it reads as OAuth ("Claude does not honor a
WWW-Authenticate header on a 200 response").
- `auth=required` on the endpoint URL (extensions/general/mcp-server/
auth-mode.ts) turns lazy auth off for that URL: every tokenless
request, initialize included, answers the 401 + WWW-Authenticate
challenge. Callers with a token are unaffected; the bare URL keeps
lazy auth for Claude Code, the plugin, Cursor and ChatGPT, and existing
connector records are untouched.
- The links we control carry the flag: Settings -> API & MCP (install
link and copy block), the onboarding checklist, both docs pages and
claude-plugin/CONNECTORS.md (plugin 1.2.3). The docs' Path A now
describes the eager flow (sign-in opens on Add) instead of telling
users to override the dialog's "None".
- Tests: eager-auth.test.ts (401 on initialize/tools/list/public tools,
namespaced metadata pointer, token no-op, exact-flag only); checklist
link shape updated.
Companion: gnubok-website PR (Kom igång connector link + regenerated
connect-claude / anslut-claude pages).
Claude-Session: https://claude.ai/code/session_013yw62FMXGSzo6icFDiBwP3
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Several E2E runs composed the first reply from tool descriptions before
the skill loaded (questionnaire instead of the guided round). Four words
in the published prompt point the agent at the guide from message one;
the rest of the prompt stays memory-first and universal.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
From the fourth E2E run: the agent correctly refused to reproduce a
104 KB SIE file token by token (silent mid-verifikat truncation) and
dead-ended to the web wizard, and its replies were walls of compliance
prose.
1. gnubok_create_sie_upload: signed same-origin upload URL (reuses the
pending-document infra; .se/.sie/.si only, 50 MB HTTP cap).
gnubok_sie_preflight and gnubok_import_sie accept upload_id as the
byte-exact source, plus optional sha256 (hex of the raw bytes)
verified on the upload_id/base64 paths so truncation is DETECTED,
never silent. Inline content above 120k chars is refused with a
pointer to the upload flow. Scope bookkeeping:write (same intent as
import_sie).
2. Skill: brevity rule (max ~8 short lines per reply, one warning per
step, no legal essays), memory-first rule (check what is already
known before asking the opening questions), the upload-first SIE
step, and gnubok_explain_voucher_gap after import for skipped
voucher numbers.
3. CONNECTORS.md starter prompt rewritten memory-first so it stays
copy-paste ready without the user's own data in it. Plugin v1.2.2.
tools/list ceiling 62K to 62.4K documented in the bench.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
The read-only default forced every agent-first user to scroll a scope
list and hand-tick write rows before the flow could work. Founder call
2026-08-26: pre-check ALL scopes when the client requests none (Claude's
connector case), collapse the scope list into an expandable details fold
('Alla förvalda, visa och justera'), and keep the Allow button visible
without scrolling.
Why this is defensible: every write is STAGED for explicit approval
before anything touches the ledger, each scope row stays individually
untickable inside the fold, the warn line states the staging rule right
above the button, and the grant is revocable under Inställningar >
API-nycklar. A client that requests explicit scopes still gets exactly
that set (RFC 6749 3.3 least-privilege unchanged), and the tampered/empty
POST fallback stays read-only.
CONNECTORS.md gains the share link (connectorName/connectorUrl params)
plus the starter prompt to pair with it.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Claude.ai's Add custom connector dialog auto-detects Authentication
"None" for a server that answers the handshake without credentials,
which is exactly what lazy auth does; a user who accepts that default
gets an error instead of the sign-in on the first company-scoped call.
State the two correct choices ("Required when the server asks", DCR
client registration) in the bridge README and the plugin's CONNECTORS.md.
Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
The Claude plugin is the one-click install for Cowork and Claude Code,
so it should also be the entry to agent-first onboarding (#1814).
/accounted:setup connects the bundled connector (creating the account on
the sign-in screen if needed), hands off to the server-side onboarding
skill when the account has no company, then the bank and Skatteverket
links. CONNECTORS.md documents the single bundled connector the way
Anthropic's own plugins do. Version 1.1.0 so marketplaces that sync on
version bumps pick it up. The plugin-refs guard now also validates
commands/*.md against the server.
Claude-Session: https://claude.ai/code/session_018wCdzRTatKiDByKB8hCNT6
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>