Verigrant › Guide to Connect
Connect your assistant to Verigrant
Connect is one click from your AI assistant. You sign in to Verigrant, read what the assistant is asking for in plain words, and approve. No keys to copy and no codes to paste. The assistant then acts for you at websites inside the limits you set, and it never holds your password, your keys or anything sealed in your record. This page says how, what it gets, what it never gets, and how to disconnect it. Pairing by hand, with two keys and a code, is still there and is the guide for people.
1. Before you start
- A Verigrant account for a person It is free, and so is everything on this page.
-
An assistant that connects to remote MCP servers
Claude, ChatGPT, OpenClaw or any assistant that adds a remote MCP server and signs in
to it with OAuth. Verigrant's address for it is
https://verigrant.com/api/agent/mcp. - Your authenticator app, for some approvals Turn it on in Settings, under Account and security. A step your assistant proposes may ask for its code before it runs.
2. Connect it
- Add Verigrant in your assistant. Add it as a connector or a remote MCP server at the address above. The assistant opens Verigrant in your browser.
- Sign in, and unlock your record. The page shows nothing about the request until you do, and nothing is shared until you approve.
- Read who is asking. The page shows the assistant's name, and with it the address the browser will go to afterwards, which is the one fact Verigrant can vouch for. A line says the name is the assistant's own and Verigrant does not check it. If the address is on this device, the page warns you: any program on this device could be listening there, so approve only if you just started it yourself.
- Read what it may do. Each permission it asks for, in words. "See what institutions have sent you: who sent what and when, never the contents." And "Act for you at websites inside the permission below: get passes, plan tasks for you to approve, and place orders you approve."
- Set its limits. Where it may go, why it may act for you, what it may do, and for how many days. The page reads the whole permission back to you in plain words, with the approvals each kind of step will need, before the button.
- Approve. Your browser signs the permission with your own key and sends you to the assistant with a code good for one minute. The assistant trades the code for an access token. From then on it calls Verigrant with that token, and nothing else.
3. What it gets
- An access token, for ten minutes at a time Renewed while you stay connected, and never past the day your permission ends. Each renewal spends the old token; one presented twice ends the whole connection and tells you.
- A pass for one site at a time Ten minutes at most, carrying an address that means you at that one site and never your name, within the limits you set. A site checks it itself against keys Verigrant publishes.
- Tasks you approve When it wants to do several things, it proposes a task, and nothing runs until you approve it in Agents and approvals. Some steps then need one tap or your authenticator code.
- Orders you approve It can drop a complete order for a business and read the business's signed answer. You set the most it may charge, and nothing is paid without your approval.
- Your inbox, outside only If you allowed it, who sent you what and when. Never the contents.
A connected assistant is held to every rule a paired agent is: the same limits, the same approvals, the same receipts, and the same place to stop it.
4. What it never gets
The page says it before the button, and it is worth saying here in the same words: "It never gets your password, your keys or anything sealed in your record. It holds an access token that lasts ten minutes and is renewed while you stay connected, and every payment and every step you chose to approve still waits for you here."
- No key to any part of your record An agent you pair by hand holds the key to one section of your record, the one you chose. A connected assistant holds none. It cannot open anything sealed, so a mistake on its side cannot reach your record.
- No way to approve anything A payment, a step you chose to approve, and a form filled from your record all come back to you, on Verigrant's own page. Nothing the assistant sends can approve a step.
- No wider permission than you gave A permission it did not ask for is refused. A purpose you did not allow is refused exactly as for a paired agent. It cannot widen its permission by renewing.
- Nobody else's account Its token acts only for you, and is not a sign in anywhere.
5. What Verigrant keeps, and what it sees
- The connection The assistant's name as it gave it, the address it sends you to, the permission you signed, when you connected it, when it was last used and when its permission ends. They are in Settings, Agents and approvals, under Connected assistants, and they leave with your account.
- Each pass it asks for Verigrant sees the site at that moment. It does not see the pages your assistant reads there, or what comes back. If you limited it to a list of sites, Verigrant can read that list.
- Your receipts Every pass, payment approval and order is written to a record sealed to your key. Verigrant can write it and cannot read it.
The full list of what Verigrant can and cannot read is on the security page and in the privacy policy.
6. Disconnecting it
- From Verigrant Settings, Agents and approvals, Connected assistants, then "Disconnect this assistant". It stops at once: its token is refused on the next request, and a code it has not yet used is dead. There is no key to retire, so there is nothing to finish at your next sign in.
- From the assistant An assistant that revokes its token when you remove Verigrant from it, as the standard lets it, shows as disconnected on your side. One that does not still stops when you disconnect it here.
- A pass it already holds Works at that one site until it ends, ten minutes at most. Revoking stops the next pass; it does not reach a request already made.
- Stop one task instead Press Stop on the task in Agents and approvals. Every later step stops at once.
7. What is not live yet
- Sealed traveller details through a connected assistant A connected assistant holds no key, so a copy of your traveller details sealed for it would be sealed to nobody. A purchase that needs them goes through an agent you paired by hand for now.
- Pass length and daily count on the consent page The page uses the same defaults as pairing for how long each pass lasts and how many it may get in a day. You cannot change those two numbers there yet.
- Payments that move money Payments through Verigrant run in test mode. An approval you give today does not move money.
- Passkeys A step that needs one cannot be approved.
- Agent fronts on everyday websites Your assistant can use a pass at a site that reads Verigrant passes. Fronts hosted by Verigrant go live on their own day.