AgentBook
Guide 07

Switch on the AI connector

Your goal

Two one-time settings, done once for the whole workspace, that let everyone in it connect their AI assistant.

~10 min · needs admin access and a deploy · you only do this once

Nobody can connect anything until these are done — every part of the connector answers “not turned on” until step 1. Once they are done, each person follows Guide 06 on their own.

1 · Turn the connector on

  1. Open Admin → Config → Feature FlagsFind agentbook.mcp.enabled and enable it.
  2. That is the whole stepIt is a database setting, read fresh on every request. No deploy, no restart — it takes effect immediately.
Prove it, from any machine

Open /.well-known/oauth-protected-resource on your site. While the connector is off it returns an error; once it is on it returns a small block of JSON. That page needs no login, so it is the quickest way to check from anywhere.

2 · Give it a signing key

Set an environment variable named AGENTBOOK_MCP_JWKS in your hosting dashboard, for Production, then redeploy.

This one is security, not convenience. With it unset, the OAuth library signs with a sample key that ships inside its own package — the same key in every installation of it anywhere, published openly. Nothing looks broken; that is the problem.

  1. Generate a key on your own machineRun this. It copies the key to your clipboard and prints nothing, so it never lands in your terminal history or scrollback.
  2. Paste it into the hosting dashboardName it AGENTBOOK_MCP_JWKS, scope Production. Paste the whole line exactly as generated — it starts with {"keys":[ and ends with ]}.
  3. RedeployThe running app reads it at startup, so it will not see the value until a new deployment goes out.
Generate the key

node -e 'const{generateKeyPairSync}=require("crypto");const{privateKey}=generateKeyPairSync("rsa",{modulusLength:2048});console.log(JSON.stringify({keys:[{...privateKey.export({format:"jwk"}),use:"sig",alg:"RS256"}]}))' | pbcopy

Treat it like a password

Anyone holding this key can forge what your server signs. Keep it to the hosting dashboard: not in the repository, not in a chat message, not in a ticket. If it does get out, generate a new one and redeploy — that is all it takes to retire the old one.

3 · Check it end to end

Connect one assistant yourself using Guide 06 and run the $7.77 test there. A green tick on the two settings above only means they are set; the test is the part that proves somebody can actually reach their own books.

What people will ask you

They reportCause
“It says the connector isn’t turned on”Step 1 is not done, or the flag was switched back off.
“It logs me out every hour”The deployment is behind. Refreshing access without a new sign-in needs the current release.
“It won’t connect at all, in any assistant”Same answer — deploy the current release, then have them try again.
“Everything is slow, or it says too many requests”Sixty calls a minute per person is the ceiling. It resets on its own.
✓
Done once, for everyone. From here it is self-service: each person connects their own assistant and approves it with their own login, and can revoke it themselves.
← All guides