Skip to content
Covo Developers

Connect an app

Muse connector submission

What Meta's connector review asks for, answered for Covo: authentication, tool classifications, data handling and testing.

Meta reviews connectors in three stages: risk assessment, tool-by-tool review, and end-to-end testing. This page answers what its documentation asks for.

Connection

Asked forCovo
Integration typeHosted MCP server at https://covo.lanaai.io/mcp (Streamable HTTP). REST API at https://covo.lanaai.io/api/v1 with OpenAPI 3.1.
AuthenticationOAuth 2.1 with PKCE (S256), discovery (RFC 9728, RFC 8414), dynamic client registration (RFC 7591) and client metadata documents. Access tokens last 1 hour; refresh tokens rotate.
Read-only optionYes: the person can choose read-only on the consent screen, which keeps only read scopes.
Requested scopesagents:read agents:write by default; agents:test, agents:publish, agents:delete and conversations:read on request. See Scopes.
CredentialsNever in prompts, tool descriptions, responses, URLs or logs. Tokens are stored only as hashes.
Rate limits300 requests a minute per token; 429 with Retry-After.

Tool classifications

Every tool is classified Read, Write or Sensitive write, and carries matching MCP annotations. The full table, with inputs, outputs, side effects and errors for each: API reference.

Data handling

  • Covo stores what the person teaches their Concierge and the conversations visitors have with it, for that person.
  • Conversation tools need the separate conversations:read scope because conversations contain personal data visitors shared.
  • Every call is recorded in the account's audit log with the app's name.
  • People disconnect the app at any time in Settings, Developer Access; every token stops working at once.
  • Privacy policy: https://covo.lanaai.io/privacy. Terms: https://covo.lanaai.io/terms.

Test account

  1. Create a free account at https://covo.lanaai.io/admin/signup (it starts with 7 days of Pro) and confirm the email.
  2. Connect Muse to the MCP address and approve on the consent screen.
  3. Try get_account, list_agents, get_agent_configuration, then a preview_agent_changes and update_agent_configuration.