# MCP setup

Connect an approved host and verify profile and project reads.

## Connection prerequisites

- Maintainer-approved test access and a dedicated registered client for this host,
  S256 PKCE, and its exact callback. Dynamic client registration is disabled.
- Local resource: `https://localhost:3005/mcp`; app: `https://localhost:3000`.
- Hosted dev resource: `https://mcp-dev.postede.com/mcp`; app: `https://dev.postede.com`.
- ChatGPT cannot reach localhost directly. A local test requires an explicitly
  approved HTTPS tunnel and a client registered with the exact callback shown
  by the host. Live ChatGPT acceptance and production readiness are unverified.

Stop if registration or the matching resource is unavailable. Keep host and
environment registrations/grants separate.

## Connect and verify

1. Add the exact registered MCP resource in the host.
2. The user completes the host's browser OAuth flow and chooses permissions.
   The host manages credentials and token exchange.
3. Discover available tools. Call `get_profile` and `list_projects`, each with `{}`.

Verification prompt:

```text
Show my Postede profile and list my projects. Do not change content, settings or delivery state.
```

Confirm the intended account/environment and successful reads. An empty project
list is valid. Use the discovered catalog: 12 baseline tools or all 29 with
project parity enabled. A catalog's existence is not proof of host availability.

## Connection recovery

| Failure | Action |
| --- | --- |
| Expired access | Let the host refresh. Reconnect through OAuth if refresh fails or consent is revoked. |
| Missing tool | Check discovered catalog and operator-enabled capabilities; do not assume all 29 are exposed. |
| Permission denied | Check scope, project role and consent. Reconnect after the user changes permissions. |
| Rate limit | Follow the returned interval; do not loop or repeatedly reconnect. |

## Disconnect

Revoke the grant at `/agent/connections` in the matching app environment, then
remove the host connection. Never request passwords, cookies or tokens in
conversation.

[Tool reference](https://postede.com/docs/mcp/reference.md).
