Connect an app
Muse connector submission
What Meta's connector review asks for, answered for Covo: authentication, tool classifications, data handling and testing.
Meta reviews connectors in three stages: risk assessment, tool-by-tool review, and end-to-end testing. This page answers what its documentation asks for.
Connection
| Asked for | Covo |
|---|---|
| Integration type | Hosted MCP server at https://covo.lanaai.io/mcp (Streamable HTTP). REST API at https://covo.lanaai.io/api/v1 with OpenAPI 3.1. |
| Authentication | OAuth 2.1 with PKCE (S256), discovery (RFC 9728, RFC 8414), dynamic client registration (RFC 7591) and client metadata documents. Access tokens last 1 hour; refresh tokens rotate. |
| Read-only option | Yes: the person can choose read-only on the consent screen, which keeps only read scopes. |
| Requested scopes | agents:read agents:write by default; agents:test, agents:publish, agents:delete and conversations:read on request. See Scopes. |
| Credentials | Never in prompts, tool descriptions, responses, URLs or logs. Tokens are stored only as hashes. |
| Rate limits | 300 requests a minute per token; 429 with Retry-After. |
Tool classifications
Every tool is classified Read, Write or Sensitive write, and carries matching MCP annotations. The full table, with inputs, outputs, side effects and errors for each: API reference.
Data handling
- Covo stores what the person teaches their Concierge and the conversations visitors have with it, for that person.
- Conversation tools need the separate
conversations:readscope because conversations contain personal data visitors shared. - Every call is recorded in the account's audit log with the app's name.
- People disconnect the app at any time in Settings, Developer Access; every token stops working at once.
- Privacy policy: https://covo.lanaai.io/privacy. Terms: https://covo.lanaai.io/terms.
Test account
- Create a free account at https://covo.lanaai.io/admin/signup (it starts with 7 days of Pro) and confirm the email.
- Connect Muse to the MCP address and approve on the consent screen.
- Try
get_account,list_agents,get_agent_configuration, then apreview_agent_changesandupdate_agent_configuration.