Tecrübetecrube.com
Erste Schritte

How it works

The journey of a chat message through Tecrübe to the ad platform and safely back: MCP, OAuth, preview, approval, audit log and undo.

The journey of a request

  1. You type. You tell your assistant (Claude, ChatGPT, Cursor…) an ordinary sentence: "Add the search terms with no conversions as negatives."
  2. The assistant picks a tool. Over MCP it sees Tecrübe's tool list and calls the right one (e.g. search_terms_report, then add_negative_keywords) with parameters.
  3. Tecrübe authenticates. Every call carries the access token you granted through OAuth 2.1; the token says which member and which account it belongs to.
  4. Read tools answer directly. Data is pulled from the connected platform; if no account is connected, the tool says "not connected" instead of inventing numbers.
  5. Write tools produce a preview. The change goes to the action engine: what changes, in which account, old and new values. The budget guardrail applies here.
  6. You approve. In chat or in the panel's approval queue you say "apply"; only then does the real request go to the platform.
  7. It is logged and reversible. Every applied change is written to the audit log, and reversible operations can be undone with undo_action.

What is MCP, and why hosted?

The Model Context Protocol (MCP) is an open protocol that lets AI applications discover and call tools in external systems in a standard way. Tecrübe serves this protocol over the Streamable HTTP transport at a single address hosted on our infrastructure:

MCP URL
https://tecrube.com/mcp

You do not install anything on your computer or run Node or Python. Desktop, web and mobile clients connect to the same address; the tool list is updated on the server and nothing changes on your side.

Authentication: OAuth 2.1 + PKCE

There are no API keys. On first connection the client reads the .well-known/oauth-protected-resource document, finds Tecrübe's authorization server, registers itself dynamically (DCR) and sends you to the Tecrübe sign-in page in your browser. After signing in you see which assistant is connecting on the consent screen and approve it; the client exchanges a PKCE-protected authorization code for an access token.

  • Tokens are specific to a member and an assistant; each can be revoked from the panel.
  • When the access token expires the refresh token is used; you are not asked to sign in again.
  • The discovery document is public and contains no data:
Discovery document
https://tecrube.com/.well-known/oauth-protected-resource

Safety layers

Preview and approval

Write tools show the plan first. With the approval policy set to "ask", nothing is applied on its own.

Budget guardrail

A budget rises by at most 50% per change; the total increase within 24 hours cannot exceed twice the starting budget. Requests beyond that are not applied even if approved.

Audit log

Every tool call is recorded: who, when, with which parameters and what the result was. Visible in the panel.

Real undo

Budget, pause, negative keywords, publishing, WordPress edits and similar operations are reversed with a real request to the platform.

See Security & Approval for details.

Nächste Schritte