How it works
Your assistant reads them, step by step
One line of configuration, your own key
The address and the key you already made for the API. There is no second credential and no account to connect.
It reads only what you may publish
The same permission the widget and the wall obey: a testimonial whose writer did not agree to a website is not reachable from here at all, by search or by id.
It is told how to quote
Every answer carries the instruction with it: quote the published words exactly, never shorten or correct them, never merge two testimonials into one sentence.
It can ask for one, too
Name a customer and it sends your own invitation, in your name, with your own wording — which is fixed, and not something an assistant may rewrite.
Safe by design
The rule that makes it safe to have
Clear boundaries
What it will not do
Every capability page ends with this list. It is the part that says what you are actually buying.
- It will not write a testimonial, improve one, or produce a shorter version of somebody's sentence.
- It will not reach a testimonial whose writer kept it off websites, by any route.
- It will not change, approve, reject or delete anything. The only thing it can do besides read is send one invitation.
- It does not give an assistant your dashboard. A key is a key, and it can be revoked in one press.
Where it lives in the code: app/api/mcp/route.ts · lib/api-auth.ts · lib/consent.ts
This is running now
Open a project and use it. Nothing on this page is a roadmap.