Connecting your assistant
Connect Claude or ChatGPT to Protocol by adding one connector URL — then sign in and approve in your browser. Choose how much access to grant, and disconnect anytime. No keys to copy.
Basic Connecting takes a couple of minutes and you only do it once per app. It’s the same shape in every AI app: you add Protocol as a custom MCP connector with one connector URL, your browser opens Protocol to sign in and approve, and you’re connected. There’s no key to copy.
How connecting works
Protocol speaks the open MCP standard, so any MCP-capable AI app can connect. You need just one thing from Protocol — the connector URL, shown on the AI Agent page (open it from your profile menu):
| What | What it is |
|---|---|
| Connector URL | your Protocol MCP address (labelled MCP server URL on the page; it ends in /mcp) |
Paste that into your AI app and the app sends you to Protocol in your browser, where you sign in and approve the connection. On the approval screen you also choose how much access to grant — its scope — so you hand an assistant exactly as much power as you’re comfortable with:
| Access level | What an assistant with this access can do |
|---|---|
| Read only | look things up across your account — never changes anything |
| Read + write (default) | the above, plus build & assign programs and make everyday changes directly & live (tasks, scheduling, forms, automations, and more) |
| Read + write + send | the above, plus the three outward actions: fire an appointment reminder now, arm a recurring client reminder (it fires within minutes if the start time is now or past), and manually run an automation |
Most coaches use read + write (the default). Pick read only if you just want a research assistant; pick read + write + send only when you specifically want the assistant to be able to reach a client (reminders) or fire an automation on demand. You can connect different apps at different access levels and disconnect any of them anytime.
| Your app | How it connects |
|---|---|
| Claude Code (recommended: the Protocol CRM plugin) | two slash commands install it, no connector URL to copy. You still pick an access level at sign-in, the same as any other route, with read + write preselected. See Installing the Claude plugin |
| Claude or ChatGPT (web & desktop) | add a custom connector, paste the connector URL — you’ll sign in and approve in your browser |
| Claude Desktop, Claude Code, Cursor (developer apps, manual connector) | add the connector URL in the app’s MCP settings; they open the same browser sign-in (or use a manual key) |
| Gemini | the consumer Gemini app has no one-click connector yet — use the Gemini CLI / API or any generic MCP client with the same URL |
You sign in and approve — no key to copy. When you add Protocol, your AI app opens Protocol in your browser; you sign in and approve the connection, choosing how much access to grant. This is the standard connector flow, the same way you’d link a calendar.
Once connected, your agent acts with your coach permissions, bounded by the access you granted — it can read across your account, and (at read+write or higher) build, edit and assign programs and make everyday changes directly & live (see What your agent can do below). You stay in control: you choose the access level when you approve, and you can disconnect any app anytime from the AI Agent page — it stops working immediately.
Add the connector
In your AI app, add a custom / remote MCP connector and paste your Protocol connector URL as the address (Claude and ChatGPT both support this). When you save, the app opens Protocol in your browser: sign in, choose an access level, and click Allow. The app is now connected and can read your Protocol account and make changes for you, within the access you granted.
Faster in Claude Code: the plugin
If you use Claude Code, you can skip the connector URL entirely. The official Protocol CRM plugin installs the connection for you with two commands:
/plugin marketplace add dejankeri/protocol-claude-plugin
/plugin install protocol-crm@protocol
The plugin’s connection asks you to pick an access level exactly like any other route, and read + write is preselected. Choose read + write + send if you want the agent firing reminders or running automations. See Installing the Claude plugin for what the consent screen asks, how to turn on auto-update, and when you’d want a REST key on top of it.
The one thing to understand before you connect
The sign-in is quick — but understand this one thing first, because it’s the heart of how the feature works:
Connecting an assistant sends the Protocol data it works with — including your clients’ information — to your AI provider (Anthropic for Claude, OpenAI for ChatGPT) so it can answer. That’s the trade for using your own AI. You’re responsible for that choice on your clients’ behalf, the same way you are for any tool you bring to your coaching.
Your assistant can only help by reading the relevant data, and reading it means it’s processed by the AI you chose. Nothing new becomes visible that you couldn’t already see; the new part is where it’s processed. More on exactly what’s shared, and how to limit it, in Data, privacy & revoking.
Your first message
Once connected, just talk to it. A good first prompt to prove it’s working:
Start from a client — the “Ask your AI” button
Once you’ve connected an assistant, you don’t have to switch apps and re-type who you’re working on. Open any client’s page in Protocol and use ✦ Ask your AI — it opens your assistant on a fresh chat already primed to help with that client.
A few things worth knowing:
- It picks your default app. The first option is whichever assistant you set as default on the AI Agent page; pick any of the three for this one chat. Or choose Copy prompt to paste the starter message wherever you like.
- Claude opens your desktop app if you have it. Choosing Open in Claude launches the Claude desktop app when it’s installed and falls back to a new browser tab if it isn’t — automatically, with nothing to configure. ChatGPT and Gemini always open in the browser.
- Only a name is in the link — not health data. The starter message carries just the client’s name and id (and the view you’re on, e.g. “nutrition”) so the assistant knows who you mean. No health, progress, or personal data travels in the link itself; the assistant only sees a client’s details once it calls your connected Protocol agent — which still respects the access you granted and your coach permissions.
This is just a shortcut to open a primed chat. Everything past that point — what the assistant can read or change — is governed by the access you granted exactly as described above.
What your agent can do
Once connected, your agent acts with your coach permissions — bounded by the access you granted (read, read+write, or read+write+send). What it can do falls into a few bands.
Read almost anything you can see (any connection, all access levels). Your agent can pull up your clients and their lifecycle stages, your dashboard overview, run a global search, and read appointments, conversations and messages, progress entries, labs and health metrics, purchases and your shop, tasks and boards, forms and their submissions, automations, notifications, insights, progress reports, your media library, meeting transcripts — plus your programs, workouts and nutrition templates. It only ever sees data inside your account; it can’t reach another coach’s or tenant’s clients.
Build & assign programs directly (read+write). When you ask it to build or edit a program, workout, or nutrition template, it does it live in Protocol — there’s no draft and no Apply step. By default it builds a reusable library template (attached to nobody); name a client and it assigns it straight onto that client instead. It can also copy an existing template onto a client. See Building & editing programs and Safety, scopes & privacy.
Make everyday changes directly (read+write). A broad set of reversible, everyday actions happen immediately when you ask — no draft, no extra click. Among them:
- set a client’s lifecycle stage; assign / unassign a trainer; add a meeting note
- manage tasks, boards, columns, labels & subtasks (create, update, complete, move, reorder)
- manage appointments — create, reschedule, or cancel — and your booking settings
- manage forms, automations (create / edit / activate / pause / archive), and progress reports
- organise your lifecycle stages and your media library (categories, sharing, attach-by-URL)
These commit live, but they’re all the kind of thing that’s easy to change back.
Reach out — only if you allow it (read+write+send). With send access the agent can also take the three outward actions: send an appointment reminder now, arm a recurring client reminder (which fires within minutes if its start time is now or past), and run an automation on demand. Read or read+write access can’t do these — they’re reserved for the highest level so reaching a client is always a deliberate choice.
What it still can’t do
Some things stay your click in the dashboard, by design — your agent has no way to do them, at any access level:
- chat with your clients (it can read conversations, but never send or reply to a message)
- anything to do with billing — no charges, refunds, or subscription changes
- permanently delete anything (it can cancel or archive, but not wipe a record)
- generate anything with AI on Protocol’s side — your assistant is the brain; Protocol runs no AI
If you ever ask it to do one of these, it’ll tell you it can’t and point you back to Protocol.
Managing & disconnecting access
Everything you’ve connected lives on the AI Agent page (open it from your profile menu), under Connected agents:
- See every connected agent — its access level, when it connected, when it was last used, and its status (Active or Disconnected).
- Disconnect instantly — disconnect an agent and it stops working immediately. Do this the moment a device is lost or you stop using an app.
- Reconnect anytime — disconnecting is safe; just run the sign-in again to reconnect.
Connecting is reversible and safe to try. Approve read only access, ask it to read a few things, and disconnect if it’s not for you. Read-only access literally can’t change anything; you only grant write or send power when you’re ready. See Safety, scopes & privacy.
Advanced: connect with a manual key
Most apps use the browser sign-in above. If your client doesn’t support it — or you’re connecting a
script — you can create a manual API key instead. On the AI Agent page, open Advanced: create
a manual API key, pick an access level, and create one. You’ll get a key (pk_…) to paste into your
app as the bearer token.
Copy it once. For your security, Protocol shows the full key only at the moment you create it. If you lose it, you don’t recover it — you create a new one and revoke the old. Treat a key like a password: it acts as you.
Wiring up a developer MCP client and want the exact tools, entity kinds, and connection facts? See the Live technical MCP reference.
Next: the headline use — Building & editing programs →