# Muse connector submission

What Meta's connector review asks for, answered for Covo: authentication, tool classifications, data handling and testing.

Meta reviews connectors in three stages: risk assessment, tool-by-tool review, and end-to-end testing. This page answers what its documentation asks for.

## Connection

| Asked for | Covo |
| --- | --- |
| Integration type | Hosted MCP server at `https://covo.lanaai.io/mcp` (Streamable HTTP). REST API at `https://covo.lanaai.io/api/v1` with OpenAPI 3.1. |
| Authentication | OAuth 2.1 with PKCE (S256), discovery (RFC 9728, RFC 8414), dynamic client registration (RFC 7591) and client metadata documents. Access tokens last 1 hour; refresh tokens rotate. |
| Read-only option | Yes: the person can choose read-only on the consent screen, which keeps only read scopes. |
| Requested scopes | `agents:read agents:write` by default; `agents:test`, `agents:publish`, `agents:delete` and `conversations:read` on request. See [Scopes](https://covo.lanaai.io/docs/scopes). |
| Credentials | Never in prompts, tool descriptions, responses, URLs or logs. Tokens are stored only as hashes. |
| Rate limits | 300 requests a minute per token; 429 with Retry-After. |

## Tool classifications

Every tool is classified Read, Write or Sensitive write, and carries matching MCP annotations. The full table, with inputs, outputs, side effects and errors for each: [API reference](https://covo.lanaai.io/docs/reference).

## Data handling

- Covo stores what the person teaches their Concierge and the conversations visitors have with it, for that person.
- Conversation tools need the separate `conversations:read` scope because conversations contain personal data visitors shared.
- Every call is recorded in the account's audit log with the app's name.
- People disconnect the app at any time in Settings, Developer Access; every token stops working at once.
- Privacy policy: [https://covo.lanaai.io/privacy](https://covo.lanaai.io/privacy). Terms: [https://covo.lanaai.io/terms](https://covo.lanaai.io/terms).

## Test account

1. Create a free account at https://covo.lanaai.io/admin/signup (it starts with 7 days of Pro) and confirm the email.
2. Connect Muse to the MCP address and approve on the consent screen.
3. Try `get_account`, `list_agents`, `get_agent_configuration`, then a `preview_agent_changes` and `update_agent_configuration`.
