How it works
The journey of a chat message through Tecrübe to the ad platform and safely back: MCP, OAuth, preview, approval, audit log and undo.
The journey of a request
- You type. You tell your assistant (Claude, ChatGPT, Cursor…) an ordinary sentence: "Add the search terms with no conversions as negatives."
- The assistant picks a tool. Over MCP it sees Tecrübe's tool list and calls the right one (e.g.
search_terms_report, thenadd_negative_keywords) with parameters. - Tecrübe authenticates. Every call carries the access token you granted through OAuth 2.1; the token says which member and which account it belongs to.
- Read tools answer directly. Data is pulled from the connected platform; if no account is connected, the tool says "not connected" instead of inventing numbers.
- Write tools produce a preview. The change goes to the action engine: what changes, in which account, old and new values. The budget guardrail applies here.
- You approve. In chat or in the panel's approval queue you say "apply"; only then does the real request go to the platform.
- It is logged and reversible. Every applied change is written to the audit log, and reversible operations can be undone with
undo_action.
What is MCP, and why hosted?
The Model Context Protocol (MCP) is an open protocol that lets AI applications discover and call tools in external systems in a standard way. Tecrübe serves this protocol over the Streamable HTTP transport at a single address hosted on our infrastructure:
https://tecrube.com/mcpYou do not install anything on your computer or run Node or Python. Desktop, web and mobile clients connect to the same address; the tool list is updated on the server and nothing changes on your side.
Authentication: OAuth 2.1 + PKCE
There are no API keys. On first connection the client reads the .well-known/oauth-protected-resource document, finds Tecrübe's authorization server, registers itself dynamically (DCR) and sends you to the Tecrübe sign-in page in your browser. After signing in you see which assistant is connecting on the consent screen and approve it; the client exchanges a PKCE-protected authorization code for an access token.
- Tokens are specific to a member and an assistant; each can be revoked from the panel.
- When the access token expires the refresh token is used; you are not asked to sign in again.
- The discovery document is public and contains no data:
https://tecrube.com/.well-known/oauth-protected-resourceSafety layers
Preview and approval
Write tools show the plan first. With the approval policy set to "ask", nothing is applied on its own.
Budget guardrail
A budget rises by at most 50% per change; the total increase within 24 hours cannot exceed twice the starting budget. Requests beyond that are not applied even if approved.
Audit log
Every tool call is recorded: who, when, with which parameters and what the result was. Visible in the panel.
Real undo
Budget, pause, negative keywords, publishing, WordPress edits and similar operations are reversed with a real request to the platform.
See Security & Approval for details.
Nächste Schritte
- SchnellstartVerbinden Sie Tecrübe in fünf Minuten mit Ihrem Assistenten: Konto anlegen, Client wählen, per OAuth anmelden, erstes Konto verbinden und erstes Tool ausführen.
- Sicherheit & FreigabeDas Sicherheitsmodell von Tecrübe: OAuth 2.1, Vorschau → Freigabe, Budget-Leitplanke, Prüfprotokoll, echtes Rückgängig und Ergebnisse, die der Assistent nicht erfinden kann.