# Anthropic Connector Directory — submission package (prepared 2026-07-14)

Everything needed to submit Gluecron to the Claude connectors directory.
Submission happens in **claude.ai → admin settings → connector directory**
and requires a **Team or Enterprise** org, submitted by the org owner.
(Guide: https://support.claude.com/en/articles/12922490-remote-mcp-server-submission-guide)

## Connector details (paste into the form)

| Field | Value |
|---|---|
| Name | Gluecron |
| Description | AI-native git hosting — repos, PRs, issues, CI gates, and AI code review over MCP (60 tools). |
| Remote MCP URL | `https://gluecron.com/mcp` (streamable HTTP) |
| Authentication | OAuth 2.0 with **dynamic client registration** (RFC 7591) — no static client ID needed. Authorization-code + PKCE; 1-hour access tokens with 30-day rotating refresh; RFC 6750 `invalid_token` signaling. Also accepts personal access tokens as Bearer. |
| OAuth discovery | `https://gluecron.com/.well-known/oauth-authorization-server` and `/.well-known/oauth-protected-resource` (both live) |
| Privacy policy | `https://gluecron.com/privacy` |
| Terms | `https://gluecron.com/terms` |
| Docs / agent map | `https://gluecron.com/llms.txt`, `https://gluecron.com/connect/claude-guide` |
| Geographic availability | Global — no restrictions |

## Ownership verification

We own the domain, API, and all resources the connector touches. Domain
control is independently provable: `com.gluecron/gluecron` is published on
the official MCP Registry (registry.modelcontextprotocol.io), which required
cryptographic domain verification via
`https://gluecron.com/.well-known/mcp-registry-auth`.

## Tool annotations (directory requirement)

All **60 tools** carry MCP `ToolAnnotations` served on `tools/list`
(deployed 2026-07-14, commit `523ddad`):
- 26 read-only (`readOnlyHint: true`) — search, read, health, explain, status
- 27 non-destructive writes — create PR/issue/branch/file, comments, labels
- 7 destructive (`destructiveHint: true`) — delete_repo, delete_file,
  merge_pr, close_pr, close_issue, cancel_workflow_run, update_repo

## Reviewer test account + runbook

Account: **`anthropic-reviewer`** (created 2026-07-14; credentials supplied
in the submission form by the owner — never committed here). Pre-populated
with the public repo **`anthropic-reviewer/sample-api`** containing source
files, an open issue, and an open pull request.

Suggested reviewer runbook:
1. Add `https://gluecron.com/mcp` as a custom connector → Claude is
   challenged with the OAuth flow → sign in as `anthropic-reviewer`.
2. `gluecron_repo_search {query:"sample"}` → returns `sample-api` (read-only).
3. `gluecron_repo_read_file {owner:"anthropic-reviewer", repo:"sample-api", path:"README.md"}`.
4. `gluecron_create_issue` on `sample-api` → issue appears at
   `https://gluecron.com/anthropic-reviewer/sample-api/issues`.
5. `gluecron_create_pr` from the seeded feature branch → then
   `gluecron_merge_pr` (annotated destructive) to see gate enforcement.
6. Revoke access at `https://gluecron.com/settings/applications`.

## Usage-policy notes

- No financial transactions, no media generation, no conversation-data
  extraction. The connector operates only on git repositories the
  authenticated user owns or has been granted access to.
- Destructive tools are annotated and additionally gated server-side by
  per-repo write/admin ACLs and branch-protection/merge gates.

## Submission-day checklist

- [ ] Finish seeding `sample-api` (feature branch + open PR) — needs any PAT
- [ ] Org owner submits via claude.ai admin settings with the reviewer creds
- [ ] Record the submission ticket/reference here
