# Changelog

> What changed in the developer docs and public contracts.

Changes that are not backward compatible are marked **Breaking**.

## 2026-10

### Connect MCP by signing in (2026-10-04)

- The customer MCP (`https://api.gujo.ai/api/mcp`) now connects without a key. Give your client just the URL: the first time it connects, you sign in to your Gujo account in the browser and approve its permissions, and the client receives a token (OAuth, MCP 2025-11-25 authorization).
- The install buttons and configs in [Connect MCP](mcp/index.md) now carry only the URL. Connect Cursor and VS Code with the button, Claude Code with `claude mcp add --transport http gujo <url>` then `/mcp`, Codex with `codex mcp add gujo --url <url>` then `codex mcp login gujo`, and Claude.ai by entering the URL as a custom connector.
- The default permissions are `mcp.read` and `products.read`. Anything else an app asks for is granted only if you check it on the consent screen. Access tokens last one hour and the client refreshes them on its own. See and disconnect connected apps under **Connected apps** in your account security settings.
- Connecting with an account API key still works. It stays under **Connect with a key** for each client, for CI and scripts. What changed and how to choose are in [Authentication and API keys](auth.md).
- Human staff connect to the staff MCP by signing in too. The guide is in the staff docs.

### Customer MCP tools are built from the account API (Breaking)

- The customer MCP (`https://api.gujo.ai/api/mcp`) now builds its tools from the account API. One endpoint called with an account API key is one tool, and tool names match the `tool` column of the [API reference](api-reference.md).
- **Breaking**: the old tools built from MCP server and tool rows users registered (named like `mcp_tool_{id}`) are gone. Calling those names returns `-32602 Unknown tool`. Use the new tool names for the same work.
- The first tool list holds the meta tools `search_tools`, `enable_toolset` and `disable_toolset` plus the `library` toolset. Turn on a toolset to use the rest. Details are in [Connect MCP](mcp/index.md).
- Sessions continue through the `Mcp-Session-Id` header returned by `initialize`.

### Staff MCP and human approval

- A staff MCP for Gujo staff and operations agents is open. Agents do reads and reversible work right away and only file approval requests for work that is hard to undo. When a human staff member approves, the server runs that work once.
- It has its own credentials and tools, separate from the customer MCP, and customer keys cannot call it. The guide lives in the staff docs only.

### The Design Gallery's real screens need a sign-in

- The real screen gallery at design.gujo.ai, the screen JSON (`/api/v1/*`), design images, code assets and search suggestions are open only to signed-in Gujo members and design agent tokens with the `read` role. Page requests without a sign-in get a sign-in wall, and JSON and image requests get 401.
- The landing, style, token, component and pattern docs and the MCP guide stay public. Credentials for the design MCP and the docs API did not change. Details are in [Design Gallery](design.md).

### Developer docs site

- The developer docs site is open. Every page is also available as raw `.md` and through `/llms.txt` and `/llms-full.txt`.
- The [API reference](api-reference.md) and [`/openapi.json`](https://developers.gujo.ai/openapi.json) are built from the server's router.
- [Connect MCP](mcp/index.md) gained install buttons and copyable configs for each client.
