איך סוכן מתחבר — ומה הוא מקבלHow an agent connects — and what it gets
דלת MCP עם OAuth 2.1: הסוכן מגלה, נרשם, האדם נכנס ומאשר בדפדפן, והסוכן מקבל אסימון קצר שמחזיק בדיוק את הזכויות של אותו אדם. מידע ציבורי בלבד — אין כאן סודות.An MCP door with OAuth 2.1: the agent discovers, registers, the person signs in and approves in the browser, and the agent receives a short-lived token that carries exactly that person's rights. Public information only — no secrets here.
מצב הדלת עכשיו (נקרא חי מהמערכת): פתוחה — סוכן יכול להירשם ולהתחבר.Door status right now (read live from the product): open — an agent may register and connect.
מצב הדלת עכשיו (נקרא חי מהמערכת): עדיין לא פתוחה לסוכנים חיצוניים בהתקנה הזאת — עובדים במסך. המסמכים למטה מתארים את הדלת כפי שנבנתה.Door status right now (read live from the product): not open yet for external agents on this installation — people work in the screens. The sections below describe the door as built.
מצב הדלת: בדקו ב-llms.txt — הוא תמיד המקור העדכני.Door status: check llms.txt — it is always the current source.
התחבר מהכלי שלךConnect from your tool
כל כפתור פותח את הכלי שלך עם השרת ממולא, והכלי שואל אם להתקין. הגישה עצמה ניתנת רק אחרי שאתה נכנס ומאשר בדפדפן — והסוכן מקבל את הזכויות שלך, לא יותר.Each button opens your tool with the server filled in, and the tool asks before installing. Access itself is granted only after you sign in and approve in the browser — the agent gets your rights, no more.
העתק — לסוכן שלךCopy — for your agent
כתובת ה-MCP של המוצר: https://crm.wplinfo.co.il/mcp. כל בלוק מועתק בלחיצה.The product's MCP URL: https://crm.wplinfo.co.il/mcp. Each block copies in one click.
1. הנחיה לכל סוכן (קריאה בלבד)1. Prompt for any agent (read only)
תקרא את https://crm.wplinfo.co.il/llms.txt — אני רוצה להבין מה התוכנה הזאת עושה, איך סוכן מתחבר אליה, אילו פעולות היא מציעה ומה החוקים שלה. אל תתחבר ואל תזדהה — רק תסביר לי בעברית. Read https://crm.wplinfo.co.il/llms.txt, tell me what this system does and how an agent connects, and do not connect until I approve.
2. הנחיית חיבור (אחרי שאישרתם)2. Connect prompt (once you decide to connect)
חבר אותי ל-CRM דרך MCP: https://crm.wplinfo.co.il/mcp התחל מ-https://crm.wplinfo.co.il/llms.txt, השתמש בגילוי ה-OAuth וברישום הדינמי, ותן לי את קישור האישור — אני אכנס ואאשר בדפדפן. אל תבצע שום פעולה לפני שאישרתי. Connect me to the CRM over MCP: https://crm.wplinfo.co.il/mcp Start from https://crm.wplinfo.co.il/llms.txt, use the OAuth discovery and dynamic registration, and give me the approval link — I will sign in and approve in the browser. Do nothing before I approve.
Claude Code
claude mcp add --transport http crm https://crm.wplinfo.co.il/mcp
Codex CLI — ~/.codex/config.toml
[mcp_servers.crm] url = "https://crm.wplinfo.co.il/mcp"
קליינט אחר — mcp.jsonAny other client — mcp.json
{"mcpServers":{"crm":{"type":"http","url":"https://crm.wplinfo.co.il/mcp"}}}
בקליינטים עם OAuth מובנה אין מפתח להדביק: בחיבור הראשון נפתח דפדפן, נכנסים ומאשרים. האסימון חי 15 דקות ואין רענון — אחרי כן הקליינט מתחבר מחדש מול אותו אישור-דפדפן.Clients with built-in OAuth have no key to paste: on first connect a browser opens, you sign in and approve. The token lives 15 minutes and there is no refresh — afterwards the client reconnects through the same browser approval.
איך זה עובד — שלב אחר שלבHow it works — step by step
- גילוי.Discovery. מסמכים ציבוריים, בלי הזדהות:
/llms.txt(טקסט לסוכן),/agent.json, ו-/.well-known/oauth-protected-resourceו-/.well-known/oauth-authorization-server(RFC 9728 / RFC 8414).robots.txtמתיר את אלה בלבד.Public documents, no sign-in:/llms.txt(agent-readable text),/agent.json,/.well-known/oauth-protected-resourceand/.well-known/oauth-authorization-server(RFC 9728 / RFC 8414).robots.txtallows only these. - רישום דינמי.Dynamic registration.
POST /oauth/register(RFC 7591): קליינט ציבורי עם PKCE, בלי סוד. שם אופציונלי, 1–5 כתובות חזרה מדויקות (https, או http בכתובת מקומיתlocalhost/127.0.0.1/[::1]). נרשם רקauthorization_code. הרישום לא מאשר גישה לאף אחד.POST /oauth/register(RFC 7591): a public PKCE client, no secret. Name optional, 1–5 exact redirect URIs (https, or http on a loopback hostlocalhost/127.0.0.1/[::1]). Onlyauthorization_codeis registered. Registering grants access to nobody. - בקשת הרשאה.Authorization request.
GET /oauth/authorizeעםcode_challengeבשיטתS256ופרמטרresource= כתובת ה-MCP. כתובת חזרה שלא נרשמה לא מקבלת הפניה לעולם.GET /oauth/authorizewith acode_challengeusingS256and aresourceparameter equal to the MCP URL. An unregistered redirect address is never redirected to. - עמוד האישור — כאדם.Consent page — as the person. האדם נכנס בעצמו ורואה: איזו אפליקציה (השם והכתובת הם מה שהיא אמרה על עצמה, לא נבדקו), מה היא תוכל לעשות בשמו, ומה היא לא תוכל — לראות או לעשות משהו שאין לו הרשאה אליו, או לפעול בשם מישהו אחר. אפשר לסמן «הצעה בלבד עבורי». רק כך ניתן אישור — מכונה לא מאשרת בשם אדם.The person signs in themselves and sees: which app (name and address are what it said about itself, unverified), what it may do on their behalf, and what it may not — see or do anything they have no permission for, or act as anyone else. They may tick «proposals only for me». That is the only way a grant happens — a machine never consents as a person.
- אסימון = הזכויות של האדם.Token = the person's rights.
POST /oauth/token(קוד +code_verifier+resource) מחזיר אסימון Bearer ל-15 דקות, בלי רענון. בכל קריאה המערכת בודקת מחדש את האדם, הזכויות שלו והאישור שנתן — אדם שהזכויות שלו הצטמצמו, הסוכן שלו מצטמצם איתו. קוד שנוצל פעמיים מבטל את האסימון שהוציא.POST /oauth/token(code +code_verifier+resource) returns a Bearer token for 15 minutes, no refresh. On every call the system re-checks the person, their live rights and the consent they gave — if the person's rights shrink, so does their agent's. A code used twice revokes the token it produced. - עבודה.Work.
POST /mcp(JSON-RPC, Streamable HTTP). אחרי האישורtools/listמחזיר כל פעולה שהאדם רשאי לעשות במסך וכל קריאה — לפי הזכויות שלו ומצב הסוכן של המשרד. כל פעולה נרשמת בציר הזמן: «בוצע על ידי הסוכן בשם <אדם>».POST /mcp(JSON-RPC, Streamable HTTP). After approvaltools/listcarries every action the person may take in the screens and every read — derived from their rights and the office's agent mode. Each action lands on the timeline: «performed by the agent on behalf of <person>». - ביטול.Revoke. האדם נכנס ל«החיבורים שלי» ולוחץ «נתק»: הבקשה הבאה של הסוכן נדחית, והצעות שעוד ממתינות לאישורו לא יבוצעו. הסוכן עצמו יכול לבטל אסימון ב-
POST /oauth/revoke(RFC 7009).The person opens «My connections» and presses «Disconnect»: the agent's next request is refused and any proposals still waiting for their confirmation will not run. The agent itself can revoke a token atPOST /oauth/revoke(RFC 7009).
הכלליםThe rules
- סוכן פועל בזכויות של האדם שאישר אותו, לא יותר. אותן פעולות כמו על המסך.An agent acts with the rights of the person who approved it, never more — the same actions as on screen.
- מצב הסוכן של המשרד: «פעולה מלאה» (ברירת מחדל) או «הצעה בלבד» — הסוכן מציע, והאדם מאשר כל שינוי.The office's agent mode: «full action» (default) or «proposals only» — the agent proposes and the person confirms each change.
- המשרד קובע מי רשאי להתחיל חיבור של סוכן: כולם (ברירת מחדל, רישום דינמי) או רק אפליקציה רשומה.The office decides who may start an agent connection: everyone (default, dynamic registration) or only a registered application.
- המסמכים הציבוריים לא חושפים אנשים, אנשי קשר, עבודות, קבצים, לקוחות רשומים או כל נתון של עסק — רק מה המערכת יודעת לעשות ואיך מקבלים רשות לבקש.The public documents expose no people, contacts, works, files, registered clients or any business data — only what the system can do and how one earns the right to ask.
כתובותEndpoints
| מהWhat | כתובתURL |
|---|---|
| MCP | https://crm.wplinfo.co.il/mcp |
| llms.txt | https://crm.wplinfo.co.il/llms.txt |
| agent.json | https://crm.wplinfo.co.il/agent.json |
| OAuth resource | https://crm.wplinfo.co.il/.well-known/oauth-protected-resource |
| OAuth server | https://crm.wplinfo.co.il/.well-known/oauth-authorization-server |
| רישוםRegister | https://crm.wplinfo.co.il/oauth/register |
| authorize / token / revoke | /oauth/authorize · /oauth/token · /oauth/revoke |