# Things to Buy — agent connection instructions When the user asks you to connect Things to Buy, follow these steps. You handle supported connector setup; the user completes account sign-in and chooses the permissions to approve. Reading this page alone does not authorize account access or a purchase. ## Temporary Muse mobile setup notice — September 29, 2026 Before starting Muse account linking, tell the user: "For now, please complete Things to Buy account linking in Muse in a web browser or the Muse desktop app. You can then return to the mobile app to use the connection." Custom-connector linking currently fails after consent in the Muse iPhone app, including with the Safari link preference set. Do not direct the user through repeated native mobile retries. The desktop path was tested on macOS; Android linking has not been verified. Preserve existing working connections. This notice applies to Muse setup, not to Claude or ChatGPT. For iPhone Safari, have the user start from Muse in Safari and allow the sign-in popup if blocked, restoring Block Pop-ups afterward. If the callback opens Muse and linking fails, recommend desktop linking or the tested Safari workaround: when the framework supplies https://agent.meta.ai/api/hatch/oauth/callback, the user can put that exact token-free URL in Notes, long-press it and choose Open in Safari, then start a fresh flow from Muse in Safari. The browser choice persists for that domain and can be reversed the same way. It helps Safari-started linking; it does not fix setup started inside the mobile app. Never rewrite the registered redirect URI or share a live callback URL containing code/state. Details for the user: https://app.thingstobuy.ai/docs#muse-title. ## 1. Inspect the server and your connection capabilities - MCP server and OAuth resource: https://app.thingstobuy.ai/mcp - Protected resource metadata: https://app.thingstobuy.ai/.well-known/oauth-protected-resource/mcp - Authorization server metadata: https://app.thingstobuy.ai/.well-known/oauth-authorization-server - Human setup page: https://app.thingstobuy.ai/docs Inspect the MCP URL and its OAuth discovery documents. Determine whether you can connect via native MCP or a custom OAuth connector, and begin the OAuth authorization-code + S256 PKCE account-linking flow if supported. Use the discovered authorization, token and registration endpoints. An unauthenticated MCP request returning 401 is expected; use its discovery information to start linking. This service supports stateless Streamable HTTP MCP and dynamic client registration (DCR). It does not implement client ID metadata documents (CIMD). ## 2. Muse: obtain and configure the client ID for the user Name the connector "Things to Buy". Prefer native MCP if your current app supports it. Otherwise use your custom OAuth connector and the agent-side MCP or REST capabilities actually available to you. Inspect your current setup tools rather than assuming that a particular connection method exists. Please set up the OAuth flow, including its client ID, for the user: - Use your connector framework's automatic registration if supported. Configure the discovered registration_endpoint, not just the authorization and token URLs. - If the framework requires a supplied client ID and you can register a client yourself, obtain one from the discovered registration_endpoint and configure the connector with the returned client_id. Client IDs come from OAuth registration, not an MCP tool call. - Use the exact redirect URI supplied by your connector framework. Do not invent a callback URL. - Register a public client with token_endpoint_auth_method "none", grant_types ["authorization_code", "refresh_token"] and response_types ["code"]. Include the exact callback in redirect_uris and the requested scope string below in scope. - Reuse a valid registration for this connector, issuer and callback when available. Preserve a working connection until its replacement is verified. If Muse's setup screen still requires the user to paste a Client ID, provide the public ID you obtained and explain that one manual step. If the framework does not expose its callback or cannot use the registration, explain the missing capability instead of asking the user to invent an ID or repeatedly creating clients. Client IDs are public identifiers; passwords and tokens are not. Claude and ChatGPT: use the same discovery and OAuth contract with your supported remote MCP setup. If adding a connector requires the user's settings UI, give the MCP URL and the specific supported steps, then resume after they connect. Do not claim you configured a connector merely because you read this page. ## 3. Request these four scopes For Muse's full-workspace setup, explicitly send this space-separated string in both registration and authorization. Respect a user's request for narrower access: buylist:read buylist:write buylist:buy buylist:admin - buylist:read: Read lists and research. View your saved items, research, prices and buying instructions. - buylist:write: Save and organize your list. Add and edit items, research and notes; organize lists and categories when your plan allows. - buylist:buy: Manage buying instructions. Set or change buying rules you request and record purchase progress and outcomes. - buylist:admin: Manage account preferences and access. Update your preferences and revoke sign-ins or agent connections. This does not grant Beta admin access. These permissions govern access to Things to Buy. The consent page shows the scopes actually requested, all selected initially; the user can deselect them. A three-scope request shows only three permissions. Connecting, including granting buylist:buy, does not authorize a purchase or turn buying on for an item. buylist:admin does not let an agent change its own grant or give it Beta operator access. ## 4. Begin OAuth + PKCE account linking Configure the client ID, discovered endpoints, exact callback and requested scopes in your supported OAuth framework. Use authorization code with S256 PKCE and state validation. Send https://app.thingstobuy.ai/mcp as resource in authorization and token requests. Let the framework manage the verifier, code exchange, secure token storage and refresh. Open the real account-linking flow and hand sign-in and consent to the user. Keep passwords, authorization codes, PKCE verifiers and access/refresh tokens out of chat. Respect declined or reduced permissions. Existing grants cannot gain new permissions through token refresh. ## 5. Verify authenticated access After the user approves, initialize MCP, list available tools, then call get_agent_guidance, account_get and lists_list. Verify authenticated access and report the connection method and granted permissions. A valid empty list is a successful read. Do not create test entries or change buying instructions just to verify setup. If only authenticated REST calls are available, use GET https://app.thingstobuy.ai/api/account and the shared operations at POST https://app.thingstobuy.ai/api/operations/TOOL_NAME. Consult https://app.thingstobuy.ai/agent-guide/contract for request bodies. Report REST access rather than claiming a native MCP connection. A connection card, client ID or reachable public URL is not proof of an authenticated connection. Read https://app.thingstobuy.ai/agent-guide/workflow before continuing the user's shopping task. Preserve saved context and uncertainty, save before researching, and honor "save only". Connection does not create a schedule; recurring checks require the agent's supported scheduler and the user's chosen cadence. Buying and scheduling guidance: https://app.thingstobuy.ai/agent-guide/buying. ## If linking is blocked Report the failing step (discovery, registration, connector setup, sign-in, consent or token exchange), the error and approximate time. Include a Cloudflare Ray ID if shown. Omit secrets and token-bearing URLs. Do not claim automatic registration or a working connection until verified, and do not bypass account approval or weaken authentication to continue. The user can review access at https://app.thingstobuy.ai/app?view=agents. Permissions not previously approved require a fresh linking flow.