Signing in

The server needs to know whose account a search is charged to. There are two ways to tell it, and both end in the same kind of token.

Sign in with OAuth

For Claude, ChatGPT and other assistants that offer it. Nothing to copy:

The connection then appears on your profile page, tab API / MCP, under Connected apps.

Or use a token

For code editors, command-line agents and your own scripts. Issue a token on your profile page and give the client this header:

Authorization: Bearer <token>

It is the same token the API uses, and up to ten can exist at once, so give each client its own: if one leaks, delete it alone. Keep tokens out of files you commit - most clients can read the token from an environment variable or ask for it once; the client pages show how.

A client that offers OAuth may still fail to sign in here: some register themselves with every server first, or expect to return to an address of their own scheme such as myapp://. Neither is supported. Use a token with those.

How long access lasts

Until you take it away. Tokens and connected apps do not expire, so an assistant that works today works tomorrow without signing in again. To cut access, on your profile page:

Removing PublicWWW in the assistant itself does not always tell us; if you want to be sure the access is gone, disconnect it here as well.

What the assistant gets

Search and the account summary - the two tools. Both only read: nothing in your account can be changed through them. Its searches count against your plan's daily searches, exactly as if you ran them yourself.

Building an application that signs people in? The OAuth flow, the client metadata document and the endpoints are in OAuth 2.1 for applications.

Next Claude