Agent connection

Your assistant connects to your account; you approve the order

You can connect the AI assistant you already use (Claude, for example) to your SendTheCanary account. It reads your test requests and reports and prepares drafts; the decision to submit stays with you.

Server address
https://mcp.sendthecanary.com/mcp
Protocol
MCP + OAuth

Before you connect

Nothing to install

An account with us is all you need. There is nothing to download and nothing to install on a server.

No secret is copied

You do not paste a password or an API key into the assistant. The connection is made over OAuth: the assistant is authorised in its own name and does not carry your credentials.

The assistant starts it, you approve it

When the assistant starts the connection you are sent to the panel. No access begins until you have seen the consent screen.

What the consent screen says

There are two permissions and they are asked for separately. A permission you did not grant does not exist on the server either.

stc.read — reading

Your account and organisation details, your balance, the package catalogue, your projects, your test requests and the reports belonging to them.

stc.draft — preparing drafts

Creating draft test requests and projects. A draft is not a submitted request: it creates no order and incurs no charge.

What the assistant can do once connected

Ten tools; eight only read, two prepare drafts.

  • Readiness check: verifies account, balance and package eligibility in one call
  • Account summary: organisation details and balance
  • Packages: the package catalogue
  • Projects: your project list
  • Request list: your test requests
  • Request detail: one request in full
  • Report: a test report
  • Authorisation text: the declaration to read before submitting
  • Create project (writes)
  • Create draft request (writes)

What the assistant cannot do

This is not a promise but a permission list enforced on the server: any request outside it is refused.

  • It cannot submit a request
  • It cannot make a payment
  • It cannot add or remove organisation members
  • It cannot change organisation settings
  • It cannot delete the account

The agent prepares, you submit

Submitting creates an order and a debit on your account. Your declaration that you are authorised to have the test carried out is also recorded, together with your IP address.

So you read the draft in the panel, correct it if needed, and make the decision to submit yourself. The assistant cannot take that step for you.

The panel also shows which client opened a draft. When you open one yourself, that field stays empty.

Removing access

Panel → Security → Connected applications, whenever you want.

Refresh authority is revoked the moment you remove it. The access token already in the assistant's hands is signed and cannot be recalled, so it expires within five minutes at the latest.

Where the data goes

We do not send your data to Anthropic or any other AI provider. The connection is made by your own assistant, and that assistant calls our server; the flow runs from your tool towards us.

The privacy policy of the assistant you use continues to apply to everything you share with it.

Questions, answered without hedging.

Can my assistant order a test on my behalf?
No. The assistant can only prepare a draft. Submitting depends on a separate approval you give in the panel, and that limit is enforced on the server.
Do I have to give the assistant my password or an API key?
No. The connection is made over OAuth; you copy no secret into the assistant. Its authority is limited to the permissions you granted on the consent screen.
Is my data sent to the AI provider?
Not by us. The connection is made by your own assistant and it calls our server. For what you share with the assistant, that assistant's own privacy policy applies.
How do I cut off access?
Remove it in the panel under Security → Connected applications. Refresh authority is revoked immediately; a token already issued expires within five minutes at the latest.
Which assistants does it work with?
Any client that supports the Model Context Protocol. The server address is https://mcp.sendthecanary.com/mcp — give that address to your client's "add MCP server" screen.

This page describes the flow. The binding text is the "Connected AI agents" section of the Privacy Policy.

Don't test the next release alongside your users.

Sign up in the panel, pick what you want tested, pay. The first findings start landing in the same panel within hours.

SendTheCanary provides independent software testing for web, mobile and API products. Ten separate services from functional testing to payments and localization, delivered within 72 hours as a single inspection report signed by a named person.