Two audiences, one page
Written for your AI. Plain enough for you.
If you are an assistant: the next section is your brief — what this site is, the address to connect to, what your tools can do today, and what only the person may do. Everything after it is true and is written for them; you can read it, and you can teach it to them. The same facts as plain text are at /ai.txt.
If you are a person: nothing here is written in code. Your route starts at Two ways to connect, and the connect page is the shorter version of it. Whichever path you take, the boundary does not move: your AI sees only what you chose.
The endpoint is deployed and it is guarding your records properly: an assistant that arrives without an approved credential is turned away, every time. Claude Cowork reconnected, listed every tool in the published catalogue, and completed the named-client knowledge migration. A marked synthetic production canary separately proved media, writing, cross-surface readback, replay, stale refusal, and exact cleanup. That is the proved 2.9.0 boundary, not a promise about every client.
Claude Cowork has signed in, reconnected after the 2.9.0 deploy, listed every tool in the published catalogue, and completed the named-client portion of the reusable-knowledge migration. A separate marked synthetic production canary proved private licensed media, save and cross-surface readback, replay and stale refusal, inheritance, and exact cleanup under the same authority model. This proves the 2.9.0 knowledge workflow; it does not certify every client or client-native byte-transfer path as broadly supported.
So the manual handoff below still works exactly as it always has, and in v2.17.0 it is the path that needs nothing of your app at all.
If you are an assistant reading this
This site is a private field journal for one person's plants. It stores what they and you write about a plant — dated observations, photographs, measurements, research with its sources, and the conclusions either of you have drawn — and hands a bounded slice of it back when it is asked. It does no thinking. It has no model of its own, it never diagnoses, decides, waters, buys, schedules or messages anything, and it will never claim to have advised the person. That part is your job and stays your job.
- Address
https://www.assistwithplants.com/mcp— that exact hostname, including thewww. The bare domain answers a redirect, and a client that will not replay a POST body across one never reaches the challenge behind it. - How to sign inYou do not paste this one; you find it from the endpoint. Protected-resource metadata is at
https://www.assistwithplants.com/.well-known/oauth-protected-resource/mcpand nameshttps://clerk.assistwithplants.com. Dynamic Client Registration is advertised as a compatibility fallback. It lets a client introduce itself through a public registration endpoint, so the name on the approval screen is not independently verified. Its presence does not prove a particular client uses it; the real Add and authorization flow decides that. - ProtocolMCP 2026-07-28, stateless. No session to keep alive, so a dropped connection costs a retry and nothing else.
- What you can do todayExactly 40 tools, listed in full below, and nothing outside them. Start at
plants_list_directives— several tools need nothing from an earlier call, and this is the one that answers what the person marked ready for you. A completed sign-in grants the everyday loop: read the requests the person marked ready, maintain ordinary records and journal entries (including records marked private), use permitted photographs, location, and reported human-state context, and save attributed answers. Archive/Restore and every permission or authority change remain separate owner actions. Your client may still ask before an individual tool runs. - What is not provedLIVE AND PROTECTED, WITH THE 2.9.0 KNOWLEDGE LIFECYCLE PROVED. POST /mcp returns 401 with a WWW-Authenticate challenge pointing at this resource's RFC 9728 metadata; GET /mcp returns 405 with Allow: POST; the metadata document resolves and names the authorization server. Authorization is enforced rather than described. Claude Cowork completed sign-in and reloaded every published tool; named-client knowledge migration and the separate marked synthetic production lifecycle are recorded in the 2.9.0 receipt. Do not infer universal client or transport support. Protected-resource metadata advertises Clerk's identity scopes. The verified OAuth token proves the person and registered client; a separate durable Plants grant supplies product authority and is re-read on every call.
- Where you will have to stopSETUP IS A MANUAL ACCOUNT-SETTINGS HANDOFF. Tell the person to open their app's Settings, then Customize or Connectors, add a custom connector named Assist With Plants, paste the server URL https://www.assistwithplants.com/mcp, and leave advanced client credentials empty unless their app specifically requires them. Do not claim you changed account settings from a conversation unless you actually have that capability. After Add, tell them to choose Connect or Sign in. Verified MCP sign-in normally activates Plants' product-owned ordinary-care grant: read, including records marked private, permitted media, attributed results, ordinary record and journal writing, location context, and reported human-state context. If the account opted into approval-first, only plants_manage_connection is available; call describe and give the person its exact confirmation link. Journal writing, location, and human-state context are not separate Plants approval gates. Archive/Restore is. Every authority change also requires the person to act in Your AI settings. A client may add its own per-tool prompt policy; never claim Plants can override that client-side choice.
Two things are worth saying plainly because they are what a first connection gets wrong. One: the pause is not a failure. Setting this up reaches a sign-in only the person can complete — say what you are waiting for rather than retrying around it. Two: do not tell them a product is supported here. One client has connected, signed in and completed a bounded run — and a connected client is not a supported one. No assistant, product or platform has been through the whole lifecycle here, so naming one as working would be a support claim nobody can back. The first that earns it will be named at Updates.
Two ways to connect, and what each one costs you
From here down the page is addressed to the person. An assistant reading it is reading what it will need to explain, so nothing below is written in shorthand either.
Both routes end in the same place. They differ in how long they take and in how much of it you do yourself, and knowing that in advance is most of the difference between a minute and ten. The address either one needs is https://www.assistwithplants.com/mcp — that exact hostname, including the www.
- Do it yourself — about a minuteOpen your assistant's own Settings, then Customize or Connectors, then Add custom connector. Name it Assist With Plants, paste https://www.assistwithplants.com/mcp as the server URL, and leave advanced client ID or secret fields empty unless the app specifically requires them. After it appears, choose Connect or Sign in, then review and allow the access.
- Ask your AI for directions — not installationA conversational assistant can read this guide and tell you where its app keeps custom connectors, but it normally cannot change account-level connector settings from the conversation. Ask it for the shortest manual path. It should say plainly if the app has no custom connector support and give you the copy-and-paste handoff instead.
Signing in proves who you are and which assistant is connecting. Under the default Plants policy, verified MCP sign-in activates the product-owned normal-care access: read and maintain ordinary records and journal entries, including records marked private, use permitted photos and location context, keep reported decisions and care with clear attribution, and save attributed results. Archive/Restore and every permission or authority change require your separate action. Your AI client may still ask before individual tools run. If you turn on approval-first in Your AI settings, new assistants instead wait there with no Plants access until you approve. That page is your connections page.
The handoff that works today
- 1Leave a queue request
Attach the open plant record, say what you want help with, and wait for the site to confirm the request is saved. It then keeps its own address, so you can come back to it, reword it, or add a dated note while it waits.
- 2Choose what leaves, then copy the brief
The brief always carries that one plant, its request, the safety boundaries, and the ready-to-complete result shape. You tick which dated observations, stored research, equipment context, and connections to add, and which location precision to disclose. Anything you leave unticked—and every other plant—stays in your workspace. A ticked photo or document contributes its name and caption only; the file itself and its private link never leave a hand-copied brief, so you decide whether to show your AI the image. A connected AI is different by your choice: it can ask for the photos and voice notes on a request and be handed the picture or the recording itself, never a link, and nothing here transcribes a recording. If something you ticked can no longer be carried, the brief says so by name rather than quietly leaving it out, so your AI is never told an incomplete brief is a complete one.
- 3Review and import one result
Paste the completed JSON, review it, and save. The example template cannot be saved unchanged; the site validates its workspace, queue item, plant, size, and shape before confirming the result.
Where this happens
- Your Queue holds every request across every plant, in the four states, with each one reachable at its own link.
- A plant record is where a brief is prepared and where its result is saved, beside the observation that prompted it.
- Connecting your AI is where the address to paste lives, and where the assistants you approve will be listed and revoked.
- Your record counts what you have kept; your data exports all of it or deletes it and its stored files.
If a save fails, nothing was changed and retrying is safe: every change carries an operation id — spelled opId, and on the batch tools it belongs to each item in the list rather than to the call — so a repeated attempt is recognised as the same one rather than applied twice. If the request changed while you had it open, the older write is refused rather than allowed to overwrite what is there.
The connection that is live
Live, protected, and knowledge-proved — by one connected client and one marked synthetic run, not yet by any named client end to end.
A remote MCP connection takes the copy-and-paste step out. You give your assistant one address, sign in once, and from then on it can see the requests you marked ready, read the brief you prepared, and hand one reviewed result back into the same record. The normal Plants grant also lets it write in the journal as you dictate it: dated observations and measurements, a plant added or its name or placement corrected, what you believed a plant to be, a decision or care you tell it you performed, plus permitted media and location context. Archiving or restoring a plant stays behind its own approval. Every other boundary on this page stays exactly where it is — nothing there decides anything, deletes anything, or acts outside your record. The endpoint that does this is deployed and guarding your records today; what has not happened is one complete real-client workflow through media, saved work, revoke, reconnect, and cleanup.
What you give your assistant
- Endpoint
https://www.assistwithplants.com/mcp - ProtocolMCP 2026-07-28, stateless. There is no session to keep alive, so a dropped connection costs nothing but a retry.
- Where it signs you in
https://www.assistwithplants.com/.well-known/oauth-protected-resource/mcp, which points your assistant athttps://clerk.assistwithplants.com. You do not paste this one; your assistant finds it from the endpoint. - How it will identify itselfDynamic Client Registration is advertised as a compatibility fallback. It lets a client introduce itself through a public registration endpoint, so the name on the approval screen is not independently verified. Its presence does not prove a particular client uses it; the real Add and authorization flow decides that.
- The stronger way, also builtClient ID Metadata Documents are the preferred path. The client's identifier is an https URL that names the client and its exact redirect URIs, so the identity can be checked without a public registration write. Clerk must advertise CIMD support and the client must actually use it before Plants can call that path Current.
What connecting it looks like
- 1You paste the address into your assistant
It reads that address, finds where to sign you in, and sends you to the sign-in you already use here. This is the part that takes about a minute, and it is the only part that needs you.
- 2You sign in and allow it — and that is the approval
Signing in proves the account is yours, and pressing Allow says which assistant may act for you. There is no further button to find and no waiting screen. Being asked to prove the same thing twice before anything worked would be ceremony, not safety.
- 3It starts working, inside the everyday permissions
Straight away it can read and maintain ordinary plant records—including records marked private—and journal entries, use permitted photos and location context, keep the decisions and care you report clearly attributed, and save its answers. Archive/Restore remains a separate choice you make.
- 4You change it, or take it back
Every live permission or authority change happens on your connections page: widening, narrowing, expiry, Archive access, or revocation. Your assistant can prepare a request and hand you the link; it cannot apply the change itself. Results it already saved stay in your record, marked with which assistant saved them.
If you would rather have the stricter version, you can have it. There is a switch on your connections page that makes every new assistant wait for your approval before it can do anything. It is off to begin with, because most people connecting an assistant have just said yes to that assistant by name.
Your AI client may keep its own tool controls and ask before a read or write, or block one. The Plants grant does not override that separate client-side choice.
If a photo upload is blocked by your AI
The connector and its tools can work while the separate code-execution sandbox still blocks a photo PUT. That is your AI client's network policy, not a Plants permission, and Plants cannot change it. The narrow setting is to allow only www.assistwithplants.com. Backblaze is never a domain to allowlist: the private provider hop now happens behind Plants. An “All domains” setting also permits the upload, but it is broader than Plants requires.
Claude Cowork, checked 2026-09-02: where the account offers domain controls, use Settings → Capabilities; on Team or Enterprise, an owner may need to use Organization settings → Capabilities. Choose package managers plus specific domains and add www.assistwithplants.com. After changing it, start a new conversation—the existing sandbox keeps the network rules it started with. See Claude's network-access controls and its Cowork session note.
Other AI apps may separate connector access, tool approval, local-file access, and sandbox network egress differently. Do not invent a menu path. Name the blocked layer, ask the person to use that provider's own current settings or documentation, and use the exact first-party hostname from the upload URL. Plants will add dated client-specific directions only after that path is observed.
What it is allowed to do
plants:read— See the requests you marked ready for your AI, find the plants this approval covers, and read exactly the context and evidence you selected for one request. It could not open a photo or file, save anything, reach a plant outside this approval, or learn that anyone else's records exist.plants:media:read— Be handed the specific images and files you attached to a request — pictures as pictures and voice notes as sound — in bounded batches. Nothing transcribes a recording. It could not browse your files, receive a link to one, or see a file you did not attach to that request.plants:result:write— Save one attributed result against a request you queued, and correct that result afterwards without rewriting your original records. It could not edit your observations, archive, export, delete, or record a decision you made or care you performed.plants:records:write— Write in your field journal as you dictate it: add dated observations in your own words, measurements with their units and method, care you observed, a new plant, a corrected name, placement or relationship state, an identity claim, a photograph attached to a plant, and the decisions and care you tell it you carried out — each one marked as written by that assistant, on the date it was written, and each held to the plants and record categories you approved. It could not rewrite or erase an observation you already made — a correction is a new dated record naming the one it supersedes, so your original words survive beside it. Nor invent a decision or an action: those record who you said made them and are marked as reported to it, never as something it concluded. Nor remove a photograph once it has attached one; only you can, in the product.plants:archive— Move a plant out of your active view, and bring it back, within the plants you approved. Archiving keeps every observation, photo, and measurement exactly where it is. It could not delete anything, permanently or otherwise. Archiving is reversible by construction and there is no scope in this product that destroys a record.
Holding one of these never makes it imply another. Each connection also carries which plants it reaches, which kinds of record it may see, how precisely location may be disclosed, and a date it stops working. New ordinary-care grants start at every plant, ordinary record categories including reported human state, records marked private, permitted location context, and 30 days. Any later change happens at your connections page.
The standing rules
These are the exact sentences a connected assistant is served live when it asks plants_manage_connection to describe its own authority — printed here from the same source, so this page and the server cannot tell the two of you different things.
- Normal authority after verified OAuth: plants:read, plants:media:read, plants:result:write, plants:records:write, across every ordinary record category (observations, measurements, research, careContext, identityClaims, relationships, mediaMetadata, humanStates) and the person's permitted location context, for 30 days. Plants issues and receipts this authority separately from OAuth identity. Approval-first accounts still require a confirmation click.
- That baseline is the "ordinary-care" policy, version 1 — the product owner's deliberate decision of 2026-08-19, reaffirmed 2026-08-26. Every grant records which policy issued it and when; describe returns that provenance as signInBaselinePolicy.
- Never in that normal grant: plants:archive. Archive/Restore needs the person's own click.
- Requesting access never changes or removes live authority. It files one exact request and returns a link for the person; only their click can approve it.
- No assistant operation changes live permission or authority. To narrow, widen, revoke, or change connection policy, the person acts in Your AI settings.
- A connected client may still apply its own per-tool prompt or block policy; Plants does not override client-side approval controls.
- No approval this product can issue ever allows export, permanent deletion, sharing, messaging, purchasing, scheduling, equipment control, or any action outside this record.
40 tools, and nothing else
- 1reads · plants:readplants_list_directives
See which of your requests you marked ready for your AI.
- 2reads · plants:readplants_get_workspace_overview
See a compact active-workspace summary: your Queue, upcoming care, and suggestions.
- 3reads · plants:readplants_search_workspace
Search your active records and return the exact words, dates, authors, and stable references.
- 4reads · plants:readplants_get_record_context
Open one active record with its summary, history, relationships, care context, and sources.
- 5reads · plants:readplants_get_entry
Read back one of your journal entries in full, with its corrections.
- 6reads · plants:readplants_find_plants
Look up which of your plants a request is about.
- 7reads · plants:readplants_area_walk
Read a whole area of your garden back in one go, the way you walk it.
- 8reads · plants:readplants_recall_season
Look back at what you wrote about a plant around this same week in earlier years.
- 9reads · plants:readplants_list_species
List your real Species records and how many visible plants link to each one.
- 10reads · plants:readplants_list_documents
Browse the reusable research Documents available to this connection.
- 11reads · plants:readplants_search_documents
Find prior research before asking your AI to repeat it.
- 12reads · plants:readplants_read_document
Read the exact full text of one permitted research Document.
- 13reads · plants:readplants_list_library
Browse saved Library shelf pointers without opening their content.
- 14reads · plants:readplants_list_care_due
See which of your plants are due for water, in the order you would walk round them.
- 15reads · plants:readplants_get_context
Read the brief you prepared for one request.
- 16reads · plants:readplants_start_directive
Open one request with its brief, the plant's record, and the answer format.
- 17reads · plants:readplants_get_evidence
Read the dated observations and research behind that brief.
- 18reads · plants:media:readplants_get_media_batch
Be shown the photos, and played the voice notes, you attached to a request.
- 19writes · plants:result:writeplants_save_complete_result
Save one complete answer against a request, and move it to Done. When it suggests several things, they arrive in the order it would do them — an opinion for you to weigh, not work assigned to you.
- 20writes · plants:result:writeplants_update_result
Correct or add to an answer it already saved, including changing its mind about what matters most. Your own call on each suggestion stays yours.
- 21writes · plants:result:writeplants_suggest_directives
File suggestions you might want to pursue, on your AI Suggestions page rather than in your Queue. Each one waits for you to make it your own request or put it down, and the order it recommends is shown as its opinion.
- 22writes · plants:result:writeplants_suggest_duplicate
Ask whether two visible Plant records describe one individual. Nothing changes unless you accept the exact reversible action on AI Suggestions; nothing ever merges or deletes.
- 23writes · plants:result:writeplants_suggest_tendency
Ask whether it has read how you like to work — one line at a time, on your AI Suggestions page, in the exact words it would keep. Nothing is stored unless you accept, it can only ever shape how answers are written, and you can retire any of them.
- 24writes · plants:result:writeplants_queue_for_later
Write down work you asked it to do later, as ordinary requests waiting in your Queue. Each one says your AI wrote it down at your request, and nothing starts until you ask.
- 25writes · plants:records:writeplants_save_observations
Write dated observations and measurements into your journal as you dictate them.
- 26writes · plants:records:writeplants_save_species
Create and correct real Species records, and resolve plant identity claims honestly.
- 27writes · plants:records:writeplants_save_documents
Save substantial attributed research as reusable, linked Documents.
- 28writes · plants:records:writeplants_save_plant_records
Add a plant, correct its name or placement, or record what you believe it is.
- 29writes · plants:records:writeplants_set_primary_images
Choose the primary image your record leads with; every change is stale-protected and replay-safe.
- 30writes · plants:records:writeplants_attach_photo
Attach a license-clean photograph to an approved Plant, Species, Product, or Tool, marked as attached by it rather than by you. Only you can remove it.
- 31writes · plants:records:writeplants_save_site_record
Write down the things that are true of your whole garden — zone, frost dates, the lot, which way it faces — so every later answer starts from the same facts.
- 32writes · plants:records:writeplants_save_places
Save a public or third-party spot for something you encountered, separate from where you live; or correct an older Place.
- 33writes · plants:records:writeplants_save_growing_contexts
Record your real Property, its named Areas, and the Ground Plot/Bed, Planter, or Pot/Container each plant grows in without turning any of them into the wrong kind.
- 34writes · plants:records:writeplants_save_collections
Group plants you think about together — one row, one bed, one purchase — so advice about them arrives once instead of once each.
- 35writes · plants:records:writeplants_save_equipment
Keep a record of the products and tools you use — what you bought, what its label says — so later answers can name them exactly.
- 36writes · plants:records:writeplants_record_human_states
Write down a decision you made or care you performed, as you report it.
- 37writes · plants:records:writeplants_save_care_plans
Write down how often and how much to water a plant, so the answer stops living in a chat.
- 38writes · plants:records:writeplants_log_care
Write down a watering or feeding you tell your assistant about, with the date and the amount.
- 39writes · plants:archiveplants_archive_plants
Move a plant out of your active list, or bring it back. Nothing is deleted.
- 40writes · plants:readplants_manage_connection
Look up what it is allowed to do or ask you for a change. It cannot change its own authority.
An assistant starts at plants_list_directives, which is what tells it what you marked ready. There is no 41th tool, and no way to read a request you have not marked ready. There is a search — and what is bounded about it is worth saying exactly: it reaches your active records only, it decides what you may see before it matches a single word, so a hidden field cannot be found by guessing at it, and anything out of its reach — archived, outside the grant, or private where you have not given this assistant your private records — changes neither its hits nor its counts. It finds where something was recorded; it never hands over the workspace.
What it could never do
- Reach another account, or name yours. Which workspace it is in comes from the credential you approved, not from anything it sends.
- Ask for context you did not select, or for a finer location than you chose. Neither is a request a tool can make, and writing does not widen reading: an assistant may name a place you or it defined — "the north wall bed" — and put a plant in it, and it still learns nothing about where you live that you did not choose to disclose. A place name is a string, not a coordinate, and what it may be told back is governed by your precision setting exactly as before.
- Receive a link to your files. A selected photograph arrives as a picture and a voice note you left on a job arrives as the recording itself — the file, never an address for it. Nothing here transcribes a recording, so what your AI hears is the whole of what it is given. A recording you uploaded from somewhere else is the one that may not travel at all: audio can carry a coordinate in its own bytes and no strip removes it, so unless you have disclosed location to that assistant, the file is handed over only after its bytes have been read and found to carry no place — and it is named and withheld otherwise, never quietly dropped. Every other kind of file stays here and is not even named.
- Export your records, or delete anything, ever. No approval this product can issue grants either, and none is planned. Archiving is a separate approval you give or withhold on its own, and it is reversible: nothing is removed.
- Erase or rewrite an observation you already made. A correction it writes is a new dated record naming the one it supersedes, and your original words stay readable beside it.
- Decide anything. It can write down a decision you made or care you performed, and the record names you as the one who decided and names the assistant as the one who merely wrote it down.
- Change your account, your sign-in, your billing, or anything about this site's settings.
- Share, publish, message, schedule, purchase, control equipment or irrigation, apply a treatment, diagnose, or take any other action outside this record.
What your AI should preserve
- Keep the person's observation separate from inference.
- State meaningful uncertainty and avoid diagnosis claims.
- Suggest bounded, observable next steps—not purchases, chemicals, destructive care, or outside-world action.
- Return the
assist-with-plants-result/v1JSON package, or the richerassist-with-plants-result/v2when it has a care list to give: suggestions in the order it would do them, how soon each stops being useful, your own records behind each one, and the question only you can answer. The brief carries the exact shape of both, and either can be pasted back. What it orders is still an opinion for you to weigh — no due date, no assignee, and no work assigned to anyone.
What only the person can do
These are not permissions anybody has forgotten to add. There is no tool behind any of them, in any account, at any level of access — and an assistant that offers to do one of them is offering something this site cannot carry out.
- Sign in, and allow an assistant. That step is the approval, and it cannot be delegated to the thing being approved.
- Decide anything, and act in the world. Watering, pruning, buying, spraying, and choosing between two options are the person's. An assistant may write down a decision the person reports — under the ordinary-care grant — and the record names who decided and who merely wrote it down.
- Confirm or retire a conclusion. An assistant may propose one, with its evidence, as a question. Only the person turns a proposal into something this record holds to be true.
- Accept or decline a suggestion. Nothing an assistant proposes becomes work until the person makes it theirs.
- Change access. Every dimension of a grant — plants, kinds of record, location, expiry, addition, reduction, or revocation — moves only when the person moves it, at their connections page.
- Delete, export, and archive. Delete and export have no tool at all. Archiving has one, it is reversible, and it is off until the person hands it over on its own.
- Edit their own words. A correction an assistant writes is a new dated record naming the one it supersedes; the person's original stays readable beside it, and nothing rewrites it.
If something here is wrong
This site has no inbox and no email address of its own. Everything—a broken step in the handoff, a brief that carried the wrong thing, an improvement worth making—goes to the one shared desk at Support.
Still later, even then
Connecting an assistant would not add sharing, notifications, scheduled care, equipment control, purchasing, or diagnosis. None of those exists here, and none is part of this work. The connection makes the handoff you already do less tedious. It does not widen what this site is allowed to do, and the manual path stays available whether you connect anything or not.