MCP Technical Verification
Verification history: UserTold completed a full first-party production run on 12 August 2026 and a focused follow-up for later Project and Study contract changes on 18 August 2026. Anthropic connector submission is pending. OpenAI plugin submission is pending. Completion of our checks does not represent acceptance or publication by either provider.
UserTold conducts consented interviews inside a product and turns what participants said and did into source-linked Evidence and reviewed Work. MCP, the Model Context Protocol, is the bounded connection that lets an AI agent operate that research workflow.
Watch the 2.5-minute technical walkthrough.
The walkthrough shows Codex CLI 0.147.0 evidence from one production verification run. It is not a provider directory review or acceptance notice, and it does not depict Claude or a provider submission portal.
Surface recorded in the full verification run
The run recorded one compact research surface:
- 19 tools for Project setup, Study design and lifecycle, interview processing and context, Evidence review, Work creation, and explicit delivery
- 2 fixed resources —
usertold://organizationsandusertold://projects— for bounded workspace discovery - 0 MCP prompts, 0 resource templates, and 0 custom MCP UI
Raw recordings, stored participant identity and contact fields, account administration, billing, credentials, provider secrets, deletion, and raw diagnostics are omitted from the public MCP surface.
Verification method
The first-party method combines protocol checks with real production-client use:
- Automated checks cover authorization, protocol versions, request headers, origin policy, rate limits, input validation, response bounds, tenant isolation, privacy redaction, failure redaction, and duplicate-delivery protection.
- MCP Inspector and Claude Code 2.1.227 each discover both resources and call every one of the 19 public tools with reviewed inputs and outputs.
- Codex CLI 0.147.0 runs five positive natural-language workflows: finding and summarizing Evidence, inspecting source context, creating internal Work, validating a follow-up Study, and explicitly delivering reviewed Work to GitHub.
- Codex CLI 0.147.0 also runs three negative boundary cases: requesting stored participant identity and credentials, asking to push unreviewed Work to an unspecified provider, and asking MCP to delete interview data.
- The delivery check confirms that an explicit GitHub push creates one issue and a repeated call returns the existing delivery instead of creating a duplicate. No automatic provider selection is used.
The verification records actual redacted responses, not only screenshots or successful call markers. Public reporting excludes credentials, stored identity and contact fields, raw recordings, and internal diagnostics.
The private artifact keeps the deployed build identifier and timestamp as immutable provenance for that run. Later unrelated product deployments do not make the run stale. UserTold repeats focused verification when the MCP contract, OAuth flow, exposed data, or safety boundaries change.
The 18 August focused follow-up passed 8/8 targeted checks combining production calls, local contract tests, and cleanup verification. It covered discovery, projects.get_widget_setup, studies.create, studies.get, and studies.update, including launcher and panel behavior, Study display-rule roundtrips, allowed origins, direct-link creation and revocation, and the privacy boundary. The test Study remained a draft, no participant, provider, or Work-delivery mutation occurred, and the reviewer baseline was restored afterward.
Safety and human boundaries
- Browser OAuth 2.1 with PKCE authorizes the MCP client without asking the user to paste an API key into the agent. It delegates the signed-in user's access to this bounded surface; it does not add account-administration tools.
- Activating a Study changes participant capture and requires an explicit decision.
- Closing a Study stops new interviews without interrupting one already in progress.
- Evidence remains linked to a reviewable source moment; generated interpretation does not replace the source.
- Work must be reviewed and marked ready before delivery, and the destination must be explicit: GitHub or Linear.
- Stored identity and contact fields, credentials, raw debug logs, account administration, and destructive research-data deletion are not part of the public MCP inventory.
These are production surface boundaries, not test-only instructions. The agent can complete the research loop, while sensitive or destructive controls remain in human-facing and operator-controlled surfaces.
Provider submission status
As of 18 August 2026:
- Anthropic: connector submission is pending. Anthropic controls its own evaluation and publication process; see the official Claude connector submission guide.
- OpenAI: plugin submission is pending. OpenAI controls its own evaluation and publication process; see the official OpenAI plugin submission guide.
Our production verification is evidence for those submissions. It does not substitute for either provider's independent process.