Assist With PlantsFor an assistant · and for you

Two audiences, one page

Written for your AI. Plain enough for you.

If you are an assistant: the next section is your brief — what this site is, the address to connect to, what your tools can do today, and what only the person may do. Everything after it is true and is written for them; you can read it, and you can teach it to them. The same facts as plain text are at /ai.txt.

If you are a person: nothing here is written in code. Your route starts at Two ways to connect, and the connect page is the shorter version of it. Whichever path you take, the boundary does not move: your AI sees only what you chose.

The endpoint is live and guarded. One assistant has connected — and a connected assistant is not a supported one.

The endpoint is deployed and it is guarding your records properly: an assistant that arrives without an approved credential is turned away, every time. Claude Cowork reconnected, listed every tool in the published catalogue, and completed the named-client knowledge migration. A marked synthetic production canary separately proved media, writing, cross-surface readback, replay, stale refusal, and exact cleanup. That is the proved 2.9.0 boundary, not a promise about every client.

Claude Cowork has signed in, reconnected after the 2.9.0 deploy, listed every tool in the published catalogue, and completed the named-client portion of the reusable-knowledge migration. A separate marked synthetic production canary proved private licensed media, save and cross-surface readback, replay and stale refusal, inheritance, and exact cleanup under the same authority model. This proves the 2.9.0 knowledge workflow; it does not certify every client or client-native byte-transfer path as broadly supported.

So the manual handoff below still works exactly as it always has, and in v2.17.0 it is the path that needs nothing of your app at all.

If you are an assistant reading this

This site is a private field journal for one person's plants. It stores what they and you write about a plant — dated observations, photographs, measurements, research with its sources, and the conclusions either of you have drawn — and hands a bounded slice of it back when it is asked. It does no thinking. It has no model of its own, it never diagnoses, decides, waters, buys, schedules or messages anything, and it will never claim to have advised the person. That part is your job and stays your job.

Two things are worth saying plainly because they are what a first connection gets wrong. One: the pause is not a failure. Setting this up reaches a sign-in only the person can complete — say what you are waiting for rather than retrying around it. Two: do not tell them a product is supported here. One client has connected, signed in and completed a bounded run — and a connected client is not a supported one. No assistant, product or platform has been through the whole lifecycle here, so naming one as working would be a support claim nobody can back. The first that earns it will be named at Updates.

Two ways to connect, and what each one costs you

From here down the page is addressed to the person. An assistant reading it is reading what it will need to explain, so nothing below is written in shorthand either.

Both routes end in the same place. They differ in how long they take and in how much of it you do yourself, and knowing that in advance is most of the difference between a minute and ten. The address either one needs is https://www.assistwithplants.com/mcp — that exact hostname, including the www.

Signing in proves who you are and which assistant is connecting. Under the default Plants policy, verified MCP sign-in activates the product-owned normal-care access: read and maintain ordinary records and journal entries, including records marked private, use permitted photos and location context, keep reported decisions and care with clear attribution, and save attributed results. Archive/Restore and every permission or authority change require your separate action. Your AI client may still ask before individual tools run. If you turn on approval-first in Your AI settings, new assistants instead wait there with no Plants access until you approve. That page is your connections page.

The handoff that works today

  1. 1
    Leave a queue request

    Attach the open plant record, say what you want help with, and wait for the site to confirm the request is saved. It then keeps its own address, so you can come back to it, reword it, or add a dated note while it waits.

  2. 2
    Choose what leaves, then copy the brief

    The brief always carries that one plant, its request, the safety boundaries, and the ready-to-complete result shape. You tick which dated observations, stored research, equipment context, and connections to add, and which location precision to disclose. Anything you leave unticked—and every other plant—stays in your workspace. A ticked photo or document contributes its name and caption only; the file itself and its private link never leave a hand-copied brief, so you decide whether to show your AI the image. A connected AI is different by your choice: it can ask for the photos and voice notes on a request and be handed the picture or the recording itself, never a link, and nothing here transcribes a recording. If something you ticked can no longer be carried, the brief says so by name rather than quietly leaving it out, so your AI is never told an incomplete brief is a complete one.

  3. 3
    Review and import one result

    Paste the completed JSON, review it, and save. The example template cannot be saved unchanged; the site validates its workspace, queue item, plant, size, and shape before confirming the result.

Where this happens

If a save fails, nothing was changed and retrying is safe: every change carries an operation id — spelled opId, and on the batch tools it belongs to each item in the list rather than to the call — so a repeated attempt is recognised as the same one rather than applied twice. If the request changed while you had it open, the older write is refused rather than allowed to overwrite what is there.

The connection that is live

Live, protected, and knowledge-proved — by one connected client and one marked synthetic run, not yet by any named client end to end.

A remote MCP connection takes the copy-and-paste step out. You give your assistant one address, sign in once, and from then on it can see the requests you marked ready, read the brief you prepared, and hand one reviewed result back into the same record. The normal Plants grant also lets it write in the journal as you dictate it: dated observations and measurements, a plant added or its name or placement corrected, what you believed a plant to be, a decision or care you tell it you performed, plus permitted media and location context. Archiving or restoring a plant stays behind its own approval. Every other boundary on this page stays exactly where it is — nothing there decides anything, deletes anything, or acts outside your record. The endpoint that does this is deployed and guarding your records today; what has not happened is one complete real-client workflow through media, saved work, revoke, reconnect, and cleanup.

What you give your assistant

What connecting it looks like

  1. 1
    You paste the address into your assistant

    It reads that address, finds where to sign you in, and sends you to the sign-in you already use here. This is the part that takes about a minute, and it is the only part that needs you.

  2. 2
    You sign in and allow it — and that is the approval

    Signing in proves the account is yours, and pressing Allow says which assistant may act for you. There is no further button to find and no waiting screen. Being asked to prove the same thing twice before anything worked would be ceremony, not safety.

  3. 3
    It starts working, inside the everyday permissions

    Straight away it can read and maintain ordinary plant records—including records marked private—and journal entries, use permitted photos and location context, keep the decisions and care you report clearly attributed, and save its answers. Archive/Restore remains a separate choice you make.

  4. 4
    You change it, or take it back

    Every live permission or authority change happens on your connections page: widening, narrowing, expiry, Archive access, or revocation. Your assistant can prepare a request and hand you the link; it cannot apply the change itself. Results it already saved stay in your record, marked with which assistant saved them.

If you would rather have the stricter version, you can have it. There is a switch on your connections page that makes every new assistant wait for your approval before it can do anything. It is off to begin with, because most people connecting an assistant have just said yes to that assistant by name.

Your AI client may keep its own tool controls and ask before a read or write, or block one. The Plants grant does not override that separate client-side choice.

If a photo upload is blocked by your AI

The connector and its tools can work while the separate code-execution sandbox still blocks a photo PUT. That is your AI client's network policy, not a Plants permission, and Plants cannot change it. The narrow setting is to allow only www.assistwithplants.com. Backblaze is never a domain to allowlist: the private provider hop now happens behind Plants. An “All domains” setting also permits the upload, but it is broader than Plants requires.

Claude Cowork, checked 2026-09-02: where the account offers domain controls, use Settings → Capabilities; on Team or Enterprise, an owner may need to use Organization settings → Capabilities. Choose package managers plus specific domains and add www.assistwithplants.com. After changing it, start a new conversation—the existing sandbox keeps the network rules it started with. See Claude's network-access controls and its Cowork session note.

Other AI apps may separate connector access, tool approval, local-file access, and sandbox network egress differently. Do not invent a menu path. Name the blocked layer, ask the person to use that provider's own current settings or documentation, and use the exact first-party hostname from the upload URL. Plants will add dated client-specific directions only after that path is observed.

What it is allowed to do

Holding one of these never makes it imply another. Each connection also carries which plants it reaches, which kinds of record it may see, how precisely location may be disclosed, and a date it stops working. New ordinary-care grants start at every plant, ordinary record categories including reported human state, records marked private, permitted location context, and 30 days. Any later change happens at your connections page.

The standing rules

These are the exact sentences a connected assistant is served live when it asks plants_manage_connection to describe its own authority — printed here from the same source, so this page and the server cannot tell the two of you different things.

40 tools, and nothing else

  1. 1
    reads · plants:readplants_list_directives

    See which of your requests you marked ready for your AI.

  2. 2
    reads · plants:readplants_get_workspace_overview

    See a compact active-workspace summary: your Queue, upcoming care, and suggestions.

  3. 3
    reads · plants:readplants_search_workspace

    Search your active records and return the exact words, dates, authors, and stable references.

  4. 4
    reads · plants:readplants_get_record_context

    Open one active record with its summary, history, relationships, care context, and sources.

  5. 5
    reads · plants:readplants_get_entry

    Read back one of your journal entries in full, with its corrections.

  6. 6
    reads · plants:readplants_find_plants

    Look up which of your plants a request is about.

  7. 7
    reads · plants:readplants_area_walk

    Read a whole area of your garden back in one go, the way you walk it.

  8. 8
    reads · plants:readplants_recall_season

    Look back at what you wrote about a plant around this same week in earlier years.

  9. 9
    reads · plants:readplants_list_species

    List your real Species records and how many visible plants link to each one.

  10. 10
    reads · plants:readplants_list_documents

    Browse the reusable research Documents available to this connection.

  11. 11
    reads · plants:readplants_search_documents

    Find prior research before asking your AI to repeat it.

  12. 12
    reads · plants:readplants_read_document

    Read the exact full text of one permitted research Document.

  13. 13
    reads · plants:readplants_list_library

    Browse saved Library shelf pointers without opening their content.

  14. 14
    reads · plants:readplants_list_care_due

    See which of your plants are due for water, in the order you would walk round them.

  15. 15
    reads · plants:readplants_get_context

    Read the brief you prepared for one request.

  16. 16
    reads · plants:readplants_start_directive

    Open one request with its brief, the plant's record, and the answer format.

  17. 17
    reads · plants:readplants_get_evidence

    Read the dated observations and research behind that brief.

  18. 18
    reads · plants:media:readplants_get_media_batch

    Be shown the photos, and played the voice notes, you attached to a request.

  19. 19
    writes · plants:result:writeplants_save_complete_result

    Save one complete answer against a request, and move it to Done. When it suggests several things, they arrive in the order it would do them — an opinion for you to weigh, not work assigned to you.

  20. 20
    writes · plants:result:writeplants_update_result

    Correct or add to an answer it already saved, including changing its mind about what matters most. Your own call on each suggestion stays yours.

  21. 21
    writes · plants:result:writeplants_suggest_directives

    File suggestions you might want to pursue, on your AI Suggestions page rather than in your Queue. Each one waits for you to make it your own request or put it down, and the order it recommends is shown as its opinion.

  22. 22
    writes · plants:result:writeplants_suggest_duplicate

    Ask whether two visible Plant records describe one individual. Nothing changes unless you accept the exact reversible action on AI Suggestions; nothing ever merges or deletes.

  23. 23
    writes · plants:result:writeplants_suggest_tendency

    Ask whether it has read how you like to work — one line at a time, on your AI Suggestions page, in the exact words it would keep. Nothing is stored unless you accept, it can only ever shape how answers are written, and you can retire any of them.

  24. 24
    writes · plants:result:writeplants_queue_for_later

    Write down work you asked it to do later, as ordinary requests waiting in your Queue. Each one says your AI wrote it down at your request, and nothing starts until you ask.

  25. 25
    writes · plants:records:writeplants_save_observations

    Write dated observations and measurements into your journal as you dictate them.

  26. 26
    writes · plants:records:writeplants_save_species

    Create and correct real Species records, and resolve plant identity claims honestly.

  27. 27
    writes · plants:records:writeplants_save_documents

    Save substantial attributed research as reusable, linked Documents.

  28. 28
    writes · plants:records:writeplants_save_plant_records

    Add a plant, correct its name or placement, or record what you believe it is.

  29. 29
    writes · plants:records:writeplants_set_primary_images

    Choose the primary image your record leads with; every change is stale-protected and replay-safe.

  30. 30
    writes · plants:records:writeplants_attach_photo

    Attach a license-clean photograph to an approved Plant, Species, Product, or Tool, marked as attached by it rather than by you. Only you can remove it.

  31. 31
    writes · plants:records:writeplants_save_site_record

    Write down the things that are true of your whole garden — zone, frost dates, the lot, which way it faces — so every later answer starts from the same facts.

  32. 32
    writes · plants:records:writeplants_save_places

    Save a public or third-party spot for something you encountered, separate from where you live; or correct an older Place.

  33. 33
    writes · plants:records:writeplants_save_growing_contexts

    Record your real Property, its named Areas, and the Ground Plot/Bed, Planter, or Pot/Container each plant grows in without turning any of them into the wrong kind.

  34. 34
    writes · plants:records:writeplants_save_collections

    Group plants you think about together — one row, one bed, one purchase — so advice about them arrives once instead of once each.

  35. 35
    writes · plants:records:writeplants_save_equipment

    Keep a record of the products and tools you use — what you bought, what its label says — so later answers can name them exactly.

  36. 36
    writes · plants:records:writeplants_record_human_states

    Write down a decision you made or care you performed, as you report it.

  37. 37
    writes · plants:records:writeplants_save_care_plans

    Write down how often and how much to water a plant, so the answer stops living in a chat.

  38. 38
    writes · plants:records:writeplants_log_care

    Write down a watering or feeding you tell your assistant about, with the date and the amount.

  39. 39
    writes · plants:archiveplants_archive_plants

    Move a plant out of your active list, or bring it back. Nothing is deleted.

  40. 40
    writes · plants:readplants_manage_connection

    Look up what it is allowed to do or ask you for a change. It cannot change its own authority.

An assistant starts at plants_list_directives, which is what tells it what you marked ready. There is no 41th tool, and no way to read a request you have not marked ready. There is a search — and what is bounded about it is worth saying exactly: it reaches your active records only, it decides what you may see before it matches a single word, so a hidden field cannot be found by guessing at it, and anything out of its reach — archived, outside the grant, or private where you have not given this assistant your private records — changes neither its hits nor its counts. It finds where something was recorded; it never hands over the workspace.

What it could never do

What your AI should preserve

What only the person can do

These are not permissions anybody has forgotten to add. There is no tool behind any of them, in any account, at any level of access — and an assistant that offers to do one of them is offering something this site cannot carry out.

If something here is wrong

This site has no inbox and no email address of its own. Everything—a broken step in the handoff, a brief that carried the wrong thing, an improvement worth making—goes to the one shared desk at Support.

Still later, even then

Connecting an assistant would not add sharing, notifications, scheduled care, equipment control, purchasing, or diagnosis. None of those exists here, and none is part of this work. The connection makes the handoff you already do less tedious. It does not widen what this site is allowed to do, and the manual path stays available whether you connect anything or not.