be-mcp
משרד עורכי הדין לדוגמה · היוםExample law office · todayנתוני המחשה, לא נתוני be-mcpIllustrative data, not be-mcp's לקוחותClients38 תיקים פתוחיםOpen cases14 ספקיםSuppliers6 חובות פתוחיםOpen debts₪ 42,300
סטודיו כושרFitness studio מוסךGarage

הסוכן מסכם מסמך מהתיק, עורכת הדין חותמת, הלקוח מאשר.The agent summarizes a document from the case, the lawyer signs, the client approves.

המשרד שלכם, עם סוכן שעובד בשמכם.Your office, with an agent that works on your behalf.

הסוכן קורא מסמך מהתיק ומסכם, קובע פגישות ומכין מסמך לחתימה, בהרשאות של מי שאישר אותו. כל פעולה נרשמת בציר הזמן של התיק.The agent reads a document from the case and summarizes it, sets meetings and prepares a document for signature, with the rights of the person who approved it. Every action is recorded on the case timeline.

נכנסים עם Google · 24 שעות · עד 30 בו-זמניתGoogle sign-in · 24 hours · up to 30 at a time

בודקים כמה מקומות פנויים...Checking available seats...

מתנסים בעסק בדיוני לפי הרשאות ההדגמה: יוצרים ועורכים אנשי קשר, פריטים ועבודות. בלי הגדרות, חיוב וחתימות.You try a fictional business within the demo permissions: create and edit contacts, items and jobs. No settings, billing or signatures.

כבר יש לכם חשבון? כניסהAlready have an account? Sign in

מה הסוכן עושה בעסקWhat the agent does in the business

קריאת מסמך מהתיקReading a case document

קורא קובץ מהתיק ומסכם, בהרשאות שלכם. קבצים קטנים, עד 48KBReads a file from the case and summarizes it, with your rights. Small files, up to 48KB

קביעת פגישותSetting meetings

עבודה מסוג פגישה, נרשמת בשם האדםA meeting-type job, recorded in the person's name

מסמך לחתימהA document for signature

הלקוח מאשר בעמוד החתימהThe client approves on the signing page

נט המשפטNet HaMishpat

דרך הסוכן שלכם, עם הגישה שלכםThrough your agent, with your access

תזכורת חובDebt reminder

לפי יתרה פתוחה בתיקBased on the case's open balance

כל מקרי השימוש במערכת ←All use cases in the system →

מקרי שימושUse cases

איך עובדים במערכת, מסך אחר מסך: מה עושים, מי מאשר ומה נרשם.How the system works, screen by screen: what you do, who approves, and what gets recorded.

אנשי קשרContactsלהוסיף אדם או ארגון, לקבוע מה הם אצל המשרד ולחבר את הכרטיס לעבודות ולקבצים.Add a person or an organization, decide what they are to the office, and link the card to jobs and files. קטלוגCatalogלבנות סוגי פריטים, למלא את המאפיינים ולראות אילו פריטים מגיעים לאנשים דרך הפרסונה שלהם.Build item types, fill in their properties, and see which items reach people through their persona. עבודותJobsלקבוע משתתפים ומועד, לעבור בין שלבים ולחזור לעבודות של אדם או של פריט.Set participants and a date, move between steps, and return to a person's or an item's jobs. תורQueueלמצוא עבודות שמחכות לטיפול, בקשות הצטרפות ומסמכים שמחכים לאישור.Find jobs waiting for handling, join requests, and documents waiting for approval. ציר זמןTimelineלברר מה קרה, לסנן את הרישומים, להוציא דוח ולתקן רישום בלי למחוק את המקור.Find out what happened, filter records, export a report, and correct a record without deleting the original. החיבורים שליMy connectionsלאשר לסוכן שלכם לעבוד בשמכם, לראות מה מחובר ולנתק כשלא רוצים להמשיך.Approve your agent to work on your behalf, see what is connected, and disconnect when you want to stop. הגדרותSettingsלהגדיר את השדות וסוגי העבודה של המשרד, ולבחור מי רשאי להשתמש בכל חלק.Define the office's fields and job types, and choose who may use each part. כל מקרי השימושAll use casesלקוח מבקש עבודה, מסמך לחתימה, חיוב, אוטומציות וחיבור סוכן, מקרה אחר מקרה.A customer asks for a job, a document to sign, billing, automations and connecting an agent, case by case.

חברו את הסוכן שכבר עובד אצלכםConnect the agent you already use

Claude ChatGPT · Codex Cursor VS Code

כתובת החיבור:Connection address:https://crm.wplinfo.co.il/mcp

הוראות לכל כליInstructions for each tool

כל כפתור פותח את הכלי שלך עם השרת ממולא, והכלי שואל אם להתקין. הגישה עצמה ניתנת רק אחרי שאתה נכנס ומאשר בדפדפן — והסוכן מקבל את הזכויות שלך, לא יותר.Each button opens your tool with the server filled in, and the tool asks before installing. Access itself is granted only after you sign in and approve in the browser — the agent gets your rights, no more.

העתק — לסוכן שלךCopy — for your agent

כתובת ה-MCP של המוצר: https://crm.wplinfo.co.il/mcp. כל בלוק מועתק בלחיצה.The product's MCP URL: https://crm.wplinfo.co.il/mcp. Each block copies in one click.

1. הנחיה לכל סוכן (קריאה בלבד)1. Prompt for any agent (read only)

הנחיהPrompt
תקרא את https://crm.wplinfo.co.il/llms.txt — אני רוצה להבין מה התוכנה הזאת עושה, איך סוכן מתחבר אליה, אילו פעולות היא מציעה ומה החוקים שלה. אל תתחבר ואל תזדהה — רק תסביר לי בעברית.

  Read https://crm.wplinfo.co.il/llms.txt, tell me what this system does and how an agent connects, and do not connect until I approve.

2. הנחיית חיבור (אחרי שאישרתם)2. Connect prompt (once you decide to connect)

הנחיית חיבורConnect prompt
חבר אותי ל-CRM דרך MCP: https://crm.wplinfo.co.il/mcp
  התחל מ-https://crm.wplinfo.co.il/llms.txt, השתמש בגילוי ה-OAuth וברישום הדינמי, ותן לי את קישור האישור — אני אכנס ואאשר בדפדפן. אל תבצע שום פעולה לפני שאישרתי.

  Connect me to the CRM over MCP: https://crm.wplinfo.co.il/mcp
  Start from https://crm.wplinfo.co.il/llms.txt, use the OAuth discovery and dynamic registration, and give me the approval link — I will sign in and approve in the browser. Do nothing before I approve.

Claude Code

shell
claude mcp add --transport http crm https://crm.wplinfo.co.il/mcp

Codex CLI — ~/.codex/config.toml

toml
[mcp_servers.crm]
  url = "https://crm.wplinfo.co.il/mcp"

קליינט אחר — mcp.jsonAny other client — mcp.json

json
{"mcpServers":{"crm":{"type":"http","url":"https://crm.wplinfo.co.il/mcp"}}}

בקליינטים עם OAuth מובנה אין מפתח להדביק: בחיבור הראשון נפתח דפדפן, נכנסים ומאשרים. האסימון חי 24 שעות ואין רענון — אחרי כן הקליינט מתחבר מחדש מול אותו אישור-דפדפן.Clients with built-in OAuth have no key to paste: on first connect a browser opens, you sign in and approve. The token lives 24 hours and there is no refresh — afterwards the client reconnects through the same browser approval.

איך זה עובד — שלב אחר שלבHow it works — step by step

  1. גילוי.Discovery. מסמכים ציבוריים, בלי הזדהות: /llms.txt (טקסט לסוכן), /agent.json, ו-/.well-known/oauth-protected-resource ו-/.well-known/oauth-authorization-server (RFC 9728 / RFC 8414). robots.txt מתיר את אלה בלבד.Public documents, no sign-in: /llms.txt (agent-readable text), /agent.json, /.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server (RFC 9728 / RFC 8414). robots.txt allows only these.
  2. רישום דינמי.Dynamic registration. POST /oauth/register (RFC 7591): קליינט ציבורי עם PKCE, בלי סוד. שם אופציונלי, 1–5 כתובות חזרה מדויקות (https, או http בכתובת מקומית localhost / 127.0.0.1 / [::1]). נרשם רק authorization_code. הרישום לא מאשר גישה לאף אחד.POST /oauth/register (RFC 7591): a public PKCE client, no secret. Name optional, 1–5 exact redirect URIs (https, or http on a loopback host localhost / 127.0.0.1 / [::1]). Only authorization_code is registered. Registering grants access to nobody.
  3. בקשת הרשאה.Authorization request. GET /oauth/authorize עם code_challenge בשיטת S256 ופרמטר resource = כתובת ה-MCP. כתובת חזרה שלא נרשמה לא מקבלת הפניה לעולם.GET /oauth/authorize with a code_challenge using S256 and a resource parameter equal to the MCP URL. An unregistered redirect address is never redirected to.
  4. עמוד האישור — כאדם.Consent page — as the person. האדם נכנס בעצמו ורואה: איזו אפליקציה (השם והכתובת הם מה שהיא אמרה על עצמה, לא נבדקו), מה היא תוכל לעשות בשמו, ומה היא לא תוכל — לראות או לעשות משהו שאין לו הרשאה אליו, או לפעול בשם מישהו אחר. אפשר לסמן «הצעה בלבד עבורי». רק כך ניתן אישור — מכונה לא מאשרת בשם אדם.The person signs in themselves and sees: which app (name and address are what it said about itself, unverified), what it may do on their behalf, and what it may not — see or do anything they have no permission for, or act as anyone else. They may tick «proposals only for me». That is the only way a grant happens — a machine never consents as a person.
  5. אסימון = הזכויות של האדם.Token = the person's rights. POST /oauth/token (קוד + code_verifier + resource) מחזיר אסימון Bearer ל-24 שעות, בלי רענון. בכל קריאה המערכת בודקת מחדש את האדם, הזכויות שלו והאישור שנתן — אדם שהזכויות שלו הצטמצמו, הסוכן שלו מצטמצם איתו. קוד שנוצל פעמיים מבטל את האסימון שהוציא.POST /oauth/token (code + code_verifier + resource) returns a Bearer token for 24 hours, no refresh. On every call the system re-checks the person, their live rights and the consent they gave — if the person's rights shrink, so does their agent's. A code used twice revokes the token it produced.
  6. עבודה.Work. POST /mcp (JSON-RPC, Streamable HTTP). אחרי האישור tools/list מחזיר כל פעולה שהאדם רשאי לעשות במסך וכל קריאה — לפי הזכויות שלו ומצב הסוכן של המשרד. כל פעולה נרשמת בציר הזמן: «בוצע על ידי הסוכן בשם <אדם>».POST /mcp (JSON-RPC, Streamable HTTP). After approval tools/list carries every action the person may take in the screens and every read — derived from their rights and the office's agent mode. Each action lands on the timeline: «performed by the agent on behalf of <person>».
  7. ביטול.Revoke. האדם נכנס ל«החיבורים שלי» ולוחץ «נתק»: הבקשה הבאה של הסוכן נדחית, והצעות שעוד ממתינות לאישורו לא יבוצעו. הסוכן עצמו יכול לבטל אסימון ב-POST /oauth/revoke (RFC 7009).The person opens «My connections» and presses «Disconnect»: the agent's next request is refused and any proposals still waiting for their confirmation will not run. The agent itself can revoke a token at POST /oauth/revoke (RFC 7009).

הכלליםThe rules

  • סוכן פועל בזכויות של האדם שאישר אותו, לא יותר. אותן פעולות כמו על המסך.An agent acts with the rights of the person who approved it, never more — the same actions as on screen.
  • מצב הסוכן של המשרד: «פעולה מלאה» (ברירת מחדל) או «הצעה בלבד» — הסוכן מציע, והאדם מאשר כל שינוי.The office's agent mode: «full action» (default) or «proposals only» — the agent proposes and the person confirms each change.
  • המשרד קובע מי רשאי להתחיל חיבור של סוכן: כולם (ברירת מחדל, רישום דינמי) או רק אפליקציה רשומה.The office decides who may start an agent connection: everyone (default, dynamic registration) or only a registered application.
  • המסמכים הציבוריים לא חושפים אנשים, אנשי קשר, עבודות, קבצים, לקוחות רשומים או כל נתון של עסק — רק מה המערכת יודעת לעשות ואיך מקבלים רשות לבקש.The public documents expose no people, contacts, works, files, registered clients or any business data — only what the system can do and how one earns the right to ask.

כתובותEndpoints

מהWhatכתובתURL
MCPhttps://crm.wplinfo.co.il/mcp
llms.txthttps://crm.wplinfo.co.il/llms.txt
agent.jsonhttps://crm.wplinfo.co.il/agent.json
OAuth resourcehttps://crm.wplinfo.co.il/.well-known/oauth-protected-resource
OAuth serverhttps://crm.wplinfo.co.il/.well-known/oauth-authorization-server
רישוםRegisterhttps://crm.wplinfo.co.il/oauth/register
authorize / token / revoke/oauth/authorize · /oauth/token · /oauth/revoke