AI agent/Connecting your assistant
updated 2026-10-07
AI agent

Connecting your assistant

Connect Claude or ChatGPT to Protocol by adding one connector URL - then sign in and approve in your browser. Choose how much access to grant, and disconnect anytime. No keys to copy.

Basic  Connecting takes a couple of minutes and you only do it once per app. It’s the same shape in every AI app: you add Protocol as a custom MCP connector with one connector URL, your browser opens Protocol to sign in and approve, and you’re connected. There’s no key to copy.

How connecting works

Protocol speaks the open MCP standard, so any MCP-capable AI app can connect. You need just one thing from Protocol: the connector URL. Open your profile menu (your avatar, top-right) and choose AI agent; the URL sits in the first card, Connect Protocol to your AI agent, with a Copy URL button beside it.

What What it is
Connector URL your Protocol MCP address; it ends in /mcp

Paste that into your AI app and the app sends you to Protocol in your browser, where you sign in and approve the connection. On the approval screen you also choose how much access to grant - its scope - so you hand an assistant exactly as much power as you’re comfortable with:

Access level What an assistant with this access can do
Read only look things up across your account - never changes anything
Read + write (default) the above, plus build & assign programs and make everyday changes directly & live (tasks, scheduling, forms, automations, and more)
Read + write + send the above, plus the outward actions: fire an appointment reminder now, arm a recurring client reminder (it fires within minutes if the start time is now or past), manually run an automation, record a sale to a client in your shop, and - when you ask for it - email your guests an appointment invite, update or cancellation, push a client when their report is approved, or email a new client their login code

Most coaches use read + write (the default). Pick read only if you just want a research assistant; pick read + write + send only when you specifically want the assistant to be able to reach a client (reminders, guest invites, report notifications), fire an automation on demand, or record a sale to a client. You can connect different apps at different access levels and disconnect any of them anytime.

Your app How it connects
Claude Code (recommended: the Protocol CRM plugin) two slash commands install it, no connector URL to copy. You still pick an access level at sign-in, the same as any other route, with read + write preselected. See Installing the Claude plugin
ChatGPT (recommended: the Protocol CRM plugin in the ChatGPT desktop app) add our marketplace once, install the plugin, then sign in and pick an access level. See Installing the ChatGPT plugin
Claude (web & desktop) add a custom connector, paste the connector URL - you’ll sign in and approve in your browser
Claude Desktop, Claude Code, Cursor (developer apps, manual connector) add the connector URL in the app’s MCP settings; they open the same browser sign-in (or use a manual key)
Gemini the consumer Gemini app has no one-click connector yet - use the Gemini CLI / API or any generic MCP client with the same URL

You sign in and approve - no key to copy. When you add Protocol, your AI app opens Protocol in your browser; you sign in and approve the connection, choosing how much access to grant. This is the standard connector flow, the same way you’d link a calendar.

Once connected, your agent acts with your coach permissions, bounded by the access you granted - it can read across your account, and (at read+write or higher) build, edit and assign programs and make everyday changes directly & live (see What your agent can do below). You stay in control: you choose the access level when you approve, and you can disconnect any app anytime from the AI agent page, and it stops working immediately.

Add the connector

1 · Add the connector
Protocol  https://…/mcp  + Add
→
2 · Sign in & approve
Sign in to Protocol
Allow  ·  read + write
→
3 · Connected
✓ Protocol connected
In your AI app, add a custom connector and paste your connector URL. Your browser opens Protocol to sign in and approve - pick how much access to grant - and you're connected. No key to copy.

In your AI app, add a custom / remote MCP connector and paste your Protocol connector URL as the address (Claude and ChatGPT both support this). When you save, the app opens Protocol in your browser: sign in, choose an access level, and click Allow. The app is now connected and can read your Protocol account and make changes for you, within the access you granted.

Faster in Claude Code: the plugin

If you use Claude Code, you can skip the connector URL entirely. The official Protocol CRM plugin installs the connection for you with two commands:

/plugin marketplace add protocolcrm/protocol-plugins
/plugin install protocol-crm@protocol

The plugin’s connection asks you to pick an access level exactly like any other route, and read + write is preselected. Choose read + write + send if you want the agent firing reminders or running automations. See Installing the Claude plugin for what the consent screen asks, how to turn on auto-update, and when you’d want a REST key on top of it.

The one thing to understand before you connect

The sign-in is quick - but understand this one thing first, because it’s the heart of how the feature works:

Connecting an assistant sends the Protocol data it works with - including your clients’ information - to your AI provider (Anthropic for Claude, OpenAI for ChatGPT) so it can answer. That’s the trade for using your own AI. You’re responsible for that choice on your clients’ behalf, the same way you are for any tool you bring to your coaching.

Your assistant can only help by reading the relevant data, and reading it means it’s processed by the AI you chose. Nothing new becomes visible that you couldn’t already see; the new part is where it’s processed. More on exactly what’s shared, and how to limit it, in Data, privacy & revoking.

Your first message

Once connected, just talk to it. A good first prompt to prove it’s working:

What can you do with my Protocol account?
I can read across your account - clients and their lifecycle, your dashboard, appointments, conversations, progress, labs, purchases, tasks & boards, forms & submissions, automations, notifications, insights, progress reports, your media library, and your exercise & food library. With read+write access I make changes directly and live - I build, edit and assign programs, workouts and nutrition (as a library template, or straight onto a client), and handle everyday changes: tasks, boards & subtasks, a client's stage, trainer assignments, meeting notes, appointments (create / update / cancel), forms, automations, progress reports, lifecycle stages, and media. If you granted send access (read+write+send) I can also do the things that reach a client: send an appointment reminder now, arm a recurring one, run an automation on demand, and email guests an invite or let a client know their report is ready. I can't chat with your clients, touch billing, delete your records for good (only an article or saved audience, after you confirm), or generate with AI - no access level unlocks those. Want a rundown of your roster to start?

Start from a client: the AI Agent button

Once you’ve connected an assistant, you don’t have to switch apps and re-type who you’re working on. Open any client’s record in Protocol and use the AI Agent button in the header. One click opens your assistant on a fresh chat already primed to help with that client.

In a client record's header
✦ AI Agent  ↗
The AI Agent button on a client record. There's no menu to pick from: it opens your default assistant in a new tab with a starter message naming the client, so the assistant immediately fetches that client's context through your connected app.

A few things worth knowing:

  • It uses your default assistant. That’s the Default agent you pick on the AI agent page, either Claude or ChatGPT. It’s saved on that device, so you can have one default on your laptop and another on a second machine.
  • Claude opens your desktop app if you have it. The button launches the Claude desktop app when it’s installed and falls back to a new browser tab if it isn’t, automatically, with nothing to configure. ChatGPT always opens in the browser.
  • Only a name is in the link, not health data. The starter message carries just the client’s name and id (and the view you’re on, e.g. “nutrition”) so the assistant knows who you mean. No health, progress, or personal data travels in the link itself; the assistant only sees a client’s details once it calls your connected Protocol agent, which still respects the access you granted and your coach permissions.
  • Nothing connected yet? The button explains the setup instead of opening anything, and Set up connection takes you straight to the AI agent page.

This is just a shortcut to open a primed chat. Everything past that point - what the assistant can read or change - is governed by the access you granted exactly as described above.

What your agent can do

Once connected, your agent acts with your coach permissions - bounded by the access you granted (read, read+write, or read+write+send). What it can do falls into a few bands.

Read almost anything you can see (any connection, all access levels). Your agent can pull up your clients and their lifecycle stages, your dashboard overview, run a global search, and read appointments, conversations and messages, progress entries, labs and health metrics, purchases and your shop, tasks and boards, forms and their submissions, automations, notifications, insights, progress reports, your media library, meeting transcripts - plus your programs, workouts and nutrition templates. It only ever sees data inside your account; it can’t reach another coach’s or tenant’s clients.

Build & assign programs directly (read+write). When you ask it to build or edit a program, workout, or nutrition template, it does it live in Protocol - there’s no draft and no Apply step. By default it builds a reusable library template (attached to nobody); name a client and it assigns it straight onto that client instead. It can also copy an existing template onto a client. See Building & editing programs and Safety, scopes & privacy.

Make everyday changes directly (read+write). A broad set of reversible, everyday actions happen immediately when you ask - no draft, no extra click. Among them:

  • set a client’s lifecycle stage; assign / unassign a trainer; add a meeting note
  • manage tasks, boards, columns, labels & subtasks (create, update, complete, move, reorder)
  • manage appointments - create, reschedule, or cancel - and your booking settings
  • manage forms (including habit forms with your own custom habits), automations (create / edit / activate / pause / archive, and put one on a schedule), and progress reports (approve one or a batch, or unsend one that went out wrong)
  • set a task to repeat (every 8 weeks, say) or make it private; move a client between the lead, low-ticket and full client tiers
  • manage articles: write, publish, duplicate, tag and file them, give a published one a public link to share or embed, and edit your saved audiences
  • organise your lifecycle stages and your media library (categories, sharing, attach-by-URL)
  • star or unstar exercises in your Favorites
  • leave a draft reply in a client’s conversation for you to review and send (it never sends it)
  • record a payment a client already made against their purchase (cash, bank transfer, a link paid outside Protocol)

These commit live, but they’re all the kind of thing that’s easy to change back.

Reach out - only if you allow it (read+write+send). With send access the agent can also take the outward actions: send an appointment reminder now, arm a recurring client reminder (which fires within minutes if its start time is now or past), run an automation on demand, record a sale to a client (no card is charged, but the purchase shows in their app and can trigger payment or expiry reminders if you have those switched on), and - only when you ask - email the guests on an appointment it books, moves or cancels, push a client when it approves their report, or email a new client their login code. Read or read+write access can’t do these - they’re reserved for the highest level so reaching a client is always a deliberate choice. At read+write the agent still books the appointment or approves the report; it just tells nobody.

What it still can’t do

Some things stay your click in the dashboard, by design - your agent has no way to do them, at any access level:

  • send your clients a message (it can read conversations and leave a draft for you, but never send or reply)
  • charge, refund or invoice - no card payments, refunds, invoice emails or subscription changes (it can only record a sale or a payment you already received)
  • permanently delete your records (it can cancel, archive or unpublish; the only exception is an article or a saved audience, which it deletes only after showing you what would go and you confirm)
  • generate anything with AI on Protocol’s side - your assistant is the brain; Protocol runs no AI

If you ever ask it to do one of these, it’ll tell you it can’t and point you back to Protocol.

Managing & disconnecting access

Everything you’ve connected lives on the AI agent page (your avatar, top-right, then AI agent), under Connected agents:

  • See every connected agent - its access level, when it connected, when it was last used, and its status (Active or Disconnected).
  • Disconnect instantly - disconnect an agent and it stops working immediately. Do this the moment a device is lost or you stop using an app.
  • Reconnect anytime - disconnecting is safe; just run the sign-in again to reconnect.

Connecting is reversible and safe to try. Approve read only access, ask it to read a few things, and disconnect if it’s not for you. Read-only access literally can’t change anything; you only grant write or send power when you’re ready. See Safety, scopes & privacy.

Advanced: connect with a manual key

Most apps use the browser sign-in above. If your client doesn’t support it, or you’re connecting a script, you can create a manual API key instead. On the AI agent page, scroll to the Create an API key card: give it a Label so you’ll recognise it later, pick a Scope (the same three access levels), and click Create key. You’ll get a key (pk_…) to paste into your app as the bearer token.

Copy it once. For your security, Protocol shows the full key only at the moment you create it. If you lose it, you don’t recover it - you create a new one and revoke the old. Treat a key like a password: it acts as you.

Wiring up a developer MCP client and want the exact tools, entity kinds, and connection facts? See the Live technical MCP reference.


Next: the headline use - Building & editing programs →

Protocol is a wellness and optimization platform. It is not a medical device and does not diagnose, treat, cure or prevent any disease. Ranges and trends shown in the product are wellness reference points, not clinical thresholds. Always discuss your health, and any result that concerns you, with a qualified healthcare provider.