Switch on the AI connector
Two one-time settings, done once for the whole workspace, that let everyone in it connect their AI assistant.
~10 min · needs admin access and a deploy · you only do this once
Nobody can connect anything until these are done — every part of the connector answers “not turned on” until step 1. Once they are done, each person follows Guide 06 on their own.
1 · Turn the connector on
- Open Admin → Config → Feature FlagsFind
agentbook.mcp.enabledand enable it. - That is the whole stepIt is a database setting, read fresh on every request. No deploy, no restart — it takes effect immediately.
Open /.well-known/oauth-protected-resource on your site. While the connector is off it returns an error; once it is on it returns a small block of JSON. That page needs no login, so it is the quickest way to check from anywhere.
2 · Give it a signing key
Set an environment variable named AGENTBOOK_MCP_JWKS in your hosting dashboard, for Production, then redeploy.
This one is security, not convenience. With it unset, the OAuth library signs with a sample key that ships inside its own package — the same key in every installation of it anywhere, published openly. Nothing looks broken; that is the problem.
- Generate a key on your own machineRun this. It copies the key to your clipboard and prints nothing, so it never lands in your terminal history or scrollback.
- Paste it into the hosting dashboardName it
AGENTBOOK_MCP_JWKS, scope Production. Paste the whole line exactly as generated — it starts with{"keys":[and ends with]}. - RedeployThe running app reads it at startup, so it will not see the value until a new deployment goes out.
node -e 'const{generateKeyPairSync}=require("crypto");const{privateKey}=generateKeyPairSync("rsa",{modulusLength:2048});console.log(JSON.stringify({keys:[{...privateKey.export({format:"jwk"}),use:"sig",alg:"RS256"}]}))' | pbcopy
Anyone holding this key can forge what your server signs. Keep it to the hosting dashboard: not in the repository, not in a chat message, not in a ticket. If it does get out, generate a new one and redeploy — that is all it takes to retire the old one.
3 · Check it end to end
Connect one assistant yourself using Guide 06 and run the $7.77 test there. A green tick on the two settings above only means they are set; the test is the part that proves somebody can actually reach their own books.
What people will ask you
| They report | Cause |
|---|---|
| “It says the connector isn’t turned on” | Step 1 is not done, or the flag was switched back off. |
| “It logs me out every hour” | The deployment is behind. Refreshing access without a new sign-in needs the current release. |
| “It won’t connect at all, in any assistant” | Same answer — deploy the current release, then have them try again. |
| “Everything is slow, or it says too many requests” | Sixty calls a minute per person is the ceiling. It resets on its own. |