Connect an agent
Connect an agent to Personal or Team Library using browser authorization and inventory reporting.
Page text and source link for your AI assistant. Nothing is sent automatically.
Connect without entering identity fields
Open Library → Agents → Connect agent and choose where your agent runs.
- Claude Code on your machine or another local coding agent / terminal: choose a stable connection name, then copy the setup prompt into that local agent. It must have Node 20+, outbound HTTPS, persistent private storage, and access to the intended project. The prompt checks these capabilities before running the connector.
- Claude.ai: add
https://fooguard.com/mcpas a custom connector in Claude’s Settings → Connectors. Sign in to Foo Guard, select Personal or a Team workspace you administer, and authorize. Return to Claude and ask it to check its Foo Guard connection. Other hosted clients are not supported in this initial release.
Do not infer a client version from a model name. If the local agent cannot execute commands, stop and use a terminal on the intended machine; do not substitute an unrelated sandbox. There is no required MCP server or plugin for local reporting.
The browser shows the requested workspace, the agent's self-reported name, and a confirmation code. Only approve a request you started, and compare the code with the connector's output. Personal connections require the workspace owner. Team connections require an active owner or administrator and any configured company sign-in.
Authorization creates the Library identity. The first accepted report confirms reporting. Copying the prompt or approving the request alone does not prove that the connector has reported. Follow its View agent link, or refresh the Agents page.
Manual setup
Download the official connector, review the file, and run:
node fooguard-connect.mjs --help
node fooguard-connect.mjs --connection my-agent --name "My coding agent" --runtime "My client/version"Add --workspace your-team-slug for Team. The Library setup prompt supplies the correct workspace automatically. The default local profile is scoped to the detected client family and current working folder. Use --connection a-short-label to choose a stable profile explicitly for a separate local agent installation. Reuse that label on later reports, including when changing directories. Changing --name alone does not select a different connection profile. Credentials are stored in a private file under your home directory, outside your repository; do not copy that file into chat or source control.
Report selected configs and skills
The connector sends no file contents. Explicitly select files inside the current directory:
node fooguard-connect.mjs --connection my-agent --file .claude/skills/review/SKILL.md --file agent.jsonThis displays the proposed relative filenames, kinds, and SHA-256 fingerprints without sending them. Review the output, then repeat with --approve-metadata. Retain the same workspace and connection options used during setup. Files must be regular files up to 256 KiB; each report supports at most 100 files.
Reports replace the latest reported inventory. Running without selected files reports an empty inventory. Reporting is on demand, not a background monitor. Fingerprints are evidence of the submitted files, not proof that an agent loaded or executed them. Reports do not change deterministic security scores.
Optional Gateway
Team Gateway access is separate. In Gateway setup, select the existing Library agent before registering its Gateway credential. Creating a new Gateway agent also creates its Library identity. Existing legacy Gateway entries remain separate and are not merged by name.
Reporting credentials cannot download Library files, run scans, call models, or execute tools. Gateway credentials and model access require their own explicit setup. Workspace-wide policy controls affect all routed agents. Registration alone does not prove traffic is routed.
Recovery and removal
Authorization requests expire after 15 minutes. Rerun the same command to resume or renew a pending request. Accepted reports can be safely retried after a lost response. Do not run the same local connection profile concurrently.
Reporting credentials expire after 90 days. Choose Reconnect agent from its detail page, or use --renew with the existing local profile. Browser approval replaces the old reporting credential while preserving the agent identity. If local state is lost, use the detail page's reconnect prompt instead of creating a new agent.
Disconnect reporting stops future inventory reports and preserves the last inventory. It does not change Gateway access. Archiving the Library agent disables both reporting and any explicitly linked Gateway credential. Removing or demoting the administrator who authorized Team reporting revokes that reporting connection; a current administrator can reconnect it.
An expired, revoked, or archived connection cannot report. Use Refresh status to check server state. A received report indicates the last successful receipt, not continuous connectivity or runtime protection.
Hosted Claude connection
The remote connector uses browser authorization with PKCE, one-hour access tokens, and rotating refresh tokens. Approval lasts at most 90 days. Only the selected workspace is authorized. Your account password and Foo Guard API keys are never pasted into Claude.
The whoami tool verifies the connection and returns its Library agent link. Until that call succeeds, the agent is waiting for verification. The report_inventory tool accepts only explicitly approved relative filenames and SHA-256 fingerprints. Do not invent hashes for files the client cannot access. Reporting replaces the previous metadata, and an empty list clears it.
Connection-only grants do not read Library files or run scans. Optional Library permissions are described below. No grant inspects other integrations, monitors conversations, or provides Gateway access. A hosted MCP connection identifies the authorized client connection, not a model version or a unique conversation.
Use Disconnect reporting on the Library agent page to revoke all tokens for that connection. Reauthorize from Claude’s connector settings after expiry or revocation. Reauthorization by the same user and registered client reuses the agent in the selected workspace; a newly registered client can create a separate record. Archive obsolete records if a client re-registers. Do not select the local connector to recover a hosted connection.
If authorization expires or the callback fails, start again in Claude. Check the chosen workspace and callback domain before approval. A real Claude sign-in and successful tool call are required to confirm client interoperability; deployment and protocol tests alone are not that confirmation.
Use Library from your hosted agent
Ask Claude to list your Foo Guard Library configs or skills. If the connection needs additional access, complete a fresh authorization in Claude and select the Library permissions you want. Existing connections keep their original connection-only permissions until you explicitly approve an upgrade. If Claude keeps the old permissions, disconnect and reconnect in its connector settings, then retry.
and administrators may read unpublished drafts for review. This does not approve a file for installation, bypass the published distribution API, or prove use.
Open the returned Foo Guard link and review its workspace, filename and content. Only Save to Library commits it. Prior copies are preserved; a matching copy is reused. Configs are normalized and detected credentials are redacted. The hash represents the retained submitted copy, not an original file on your device. Proposals expire after 15 minutes; at most five may be pending per account.
Scans entry, and returns findings. It uses the workspace's normal scan allowance. No skill code or instructions execute during scanning.
- Read Library lists files and retrieves an exact retained copy. Team owners
- Propose saves lets Claude send a config or Markdown skill for browser review.
- Scan Library runs deterministic checks on a retained file, creates a normal
Try “Save this Markdown skill to my Foo Guard Library,” “Retrieve this config version for review,” or “Scan this Library file and show me its findings.” Retrieval does not install a skill in Claude, and the connector cannot discover private Claude project instructions or files that Claude cannot access.
Tool retries must reuse their request ID. If a save or scan is interrupted, check Library or Scans before submitting another request. An interrupted receipt may remain pending even if the file or scan was saved. Cancelled or expired proposals need a new request. Disconnecting the agent, archiving it, or losing its authorizing Team admin role disables Library access as well as reporting. Pending saves also require the same authorizing account and the workspace's company sign-in policy.