Overview
What the Connector does
The Xorventa Connector lets you connect an AI assistant you already use to your own Xorventa account. From that assistant you can ask Xora, Xorventa’s account assistant, about your business and your account, see what is waiting for your decision, and ask for supported work to be done — posting, replying, sending, changing settings and deleting — within the permissions you choose.
It uses the open Model Context Protocol (MCP). The address is https://api.xorventa.ai/mcp. It is included with every Xorventa account at no extra charge.
It works through the same list of actions Xora uses on your account pages, under the same switches, with a few things left out that are listed further down this page. A connected assistant cannot do anything Xora is not allowed to do for you.
Setup
How to connect
- Before you start: you need a Xorventa account you can sign in to, and an assistant that lets you add a custom connector. The setting is usually called connectors, integrations or tools.
- Add the address. In your assistant, add a new connector and enter https://api.xorventa.ai/mcp.
- Sign in to Xorventa. Your assistant opens a Xorventa page; sign in to your own account. The request lasts 10 minutes — if it lapses, start again from your assistant.
- Review the approval screen. It shows the assistant’s name and web address, the Xorventa account it will connect to, and each permission it is asking for, all ticked to start with. Untick any you do not want to grant; reading cannot be unticked. Then approve or decline.
- Ask something. Go back to your assistant and ask, for example, “What needs my attention in my Xorventa account today?”
- Nothing is connected until you approve. Declining tells the assistant you said no, and nothing is shared. Your assistant may also show its own permission prompts, for example before it uses a tool; those come from your assistant, not from Xorventa.
Permissions
The four permissions
Each permission is listed as it appears on the approval screen, with the short name your Profile Settings page shows for it. No permission includes another.
- Read your account (xorventa:read) — required — See your Xorventa products, settings, setup steps and activity, and ask Xora questions about your business.
- Change settings (xorventa:manage) — Change settings for you, where you have allowed Xora to change settings.
- Publish, send or delete directly (xorventa:execute) — Publish posts and replies, send email, and delete things for you, without asking each time — within the switches you set on the What Xora knows about you page.
- Draft for your approval (xorventa:prepare) — Draft posts, replies and other things to publish; they wait for you to confirm in Xorventa. Grant this without “Publish, send or delete directly” if you want to approve each one.
- Read only: the assistant can look and ask, and changes nothing.
- With Change settings: it can change the settings Xora is allowed to change.
- With Publish, send or delete directly: publishing, sending and deleting run as soon as the assistant asks, if your switch for that kind of action is on.
- With Draft for your approval but not Publish, send or delete directly: every publish, send or delete becomes a proposal that waits for you (see Proposals below).
- Some settings count as publishing when they are used a certain way. Switching social replies to automatic, for example, is treated as publishing.
- To change what a connection may do, disconnect it, connect again, and tick the permissions you want this time.
Your controls
What Xorventa still checks
A permission lets the assistant ask. It does not replace any of your account’s own rules. Every request is checked against:
- the permissions you granted to this connection;
- your switches on the What Xora knows about you page;
- the products your account includes;
- the services you have connected, such as a social network, mailbox or website;
- your account’s usage limits; and
- your account boundary: a connection belongs to one Xorventa account and cannot reach any other.
- Your switches and the connection are checked again at the moment an action runs. If you switch something off or disconnect the assistant, the next action stops.
- Everything a connected assistant asks for, including anything that was refused, is listed with what Xora did on your What Xora knows about you page, marked as coming from that assistant.
Tools
The twelve tools your assistant uses
Each tool is listed by the exact name your assistant sees, followed by its title and what it is for. You do not call these yourself; your assistant chooses them from what you ask. Actions are split by what they do — reading, changing settings, publishing or sending, and deleting — and each of those four tools refuses an action of another kind.
xorventa_status · Account status — Your products, unfinished setup steps, what is waiting for your decision, and links to the right pages in your account. Reads only. Needs Read.xora_ask · Ask Xora — Ask Xora a question about your account or about Xorventa. Her answer draws on Xorventa’s help material, your approved Business Facts and the number of open items in your work — not their text — and may name actions that would do what you asked. It changes no setting. The question and answer are kept as this connection’s conversation so the assistant can continue it. Needs Read.xora_capabilities · List actions — Every action Xora can take for your account and every action that stays with you, with what each one does, which permission it needs, whether it would run directly or as a proposal for this connection, and whether this connection can use it now — and if not, why not. Needs Read.xora_action_details · Action details — For one action: the information it needs, what it does, whether it runs directly or waits for you, and which page in your account it belongs to. Runs nothing. Needs Read.xora_read · Read account data — Runs one read: lists, look-ups and summaries of your chat windows, Business Facts, settings, drafts, posts, SEO audits and activity. Refuses anything that changes something. Needs Read.xora_change_settings · Change settings — Runs one settings change: chat window look and wording, Business Facts, knowledge sources, assistant, phone, mailbox and SEO settings, drafts that are not published, and similar changes inside your account. Needs Change settings; the few settings that always ask first also need Publish, send or delete directly, or become a proposal with Draft for your approval.xora_publish_or_send · Publish or send — Runs one publishing or sending action: social posts and replies, email replies, appointment changes that notify the person who booked, and website changes that go live. Runs directly with Publish, send or delete directly; becomes a proposal with Draft for your approval.xora_delete · Delete — Runs one delete: drafts, records, knowledge sources, reports, connections and published posts. Runs directly with Publish, send or delete directly; becomes a proposal with Draft for your approval.xora_action_status · Action status — The current state of an action this connection asked for. It never runs, retries or changes the action. Needs Read.xora_cancel_action · Cancel an action — Cancels a proposed or waiting action this connection asked for, as long as nothing has been handed to another service yet. Needs Draft for your approval or Publish, send or delete directly.xora_upload_prepare · Prepare an upload — Reserves a one-time upload for an action that uses a file (see Files and uploads). Needs Change settings.xora_upload_status · Upload status — Whether a prepared file arrived and passed its checks, so it can be used. Needs Read.
- Each request carries an identifier chosen by your assistant. If it sends the same request again with the same identifier, Xorventa returns the first result and does not do the work twice.
- A request comes back as done, proposed (waiting for you), queued or running (not finished yet), failed, refused (with the reason), cancelled, or indeterminate. Only done means it happened.
Proposals
Prepare without doing
If you granted Draft for your approval but not Publish, send or delete directly, anything that would publish, send or delete is prepared but not done:
- The assistant receives a proposal and a link to a confirmation page in your Xorventa account.
- You open the link, signed in to Xorventa, and see exactly what will run and where. Confirm it or choose Not now.
- You have one minute to confirm. After that the proposal expires and nothing happens; your assistant can prepare it again if you still want it.
- Once you confirm, the action runs, and the assistant can check its status.
- Your assistant cannot confirm a proposal for you. If you disconnected the assistant or switched that kind of action off in the meantime, confirming is refused and nothing runs.
Cancelling
Cancelling, and uncertain outcomes
- Your assistant can cancel a proposed or waiting action it asked for, before it has been handed to another service. Cancelling cannot undo work that has already happened.
- If an action that publishes, sends, deletes or changes something times out, or fails on the other service’s side after it has started, Xorventa reports it as indeterminate and does not try again: it may already have happened. Check the page in your Xorventa account, or the network or service itself, before asking for it again. This prevents duplicate posts and messages.
Files
Files and uploads
Some actions use a file: an image or video for a social post, a business logo or banner, a chat window image, or a document for your Business Facts. A remote assistant cannot read the files on your computer, so a file is staged first.
- Social post media — PNG, JPEG, GIF or WebP images, or video — up to 50 MB.
- Business logo or banner; chat window image — PNG, JPEG, GIF or WebP images — up to 10 MB.
- Business Facts document — PDF, Word (.docx or .doc), plain text, Markdown, HTML or CSV — up to 10 MB.
- Waiting to be used — At most 20 staged files, or 200 MB, per account at a time. A staged file is held for no more than an hour and then deleted. The product it is added to may apply its own further checks.
- The assistant declares the file: its name, type, size, a fingerprint of its contents (SHA-256) and the one action it is for. Xorventa checks the type and size and returns an upload link.
- The assistant sends the exact file to that link. The link works once, for 10 minutes, and only for the declared file. It carries its own one-time credential, so it also works from an assistant’s code tools.
- Xorventa checks the file’s size, fingerprint and type against the declaration, and rejects a file that does not match.
- The assistant then asks for the action and names the upload, within the same 10 minutes. An upload can be used by one action only.
- If the assistant has no way to send a file, it can give you a link to a Xorventa page where you choose the file yourself. The same checks apply.
- Xorventa never fetches a web address or reads a file path that an assistant names.
Limits
What the Connector cannot do
Configuration and money stay with you. These actions are marked as staying with you, and the assistant is told which page in your account to send you to. A connected assistant cannot:
- change your password, account email, two-factor settings or recovery codes;
- add, change or choose a payment card;
- buy anything, change a plan, or cancel a product;
- publish a chat window;
- start the free SEO review, or turn on automatic website changes;
- clone a voice;
- connect or sign in to a social network, mailbox, Google, Bing or a website platform on your behalf;
- delete your Xorventa account;
- turn on Xora’s switches, grant itself more permissions, or act outside the permissions you gave it;
- confirm its own proposals; or
- control a live phone call.
Your data
What a connected assistant is not given
- Content from your Google, Meta or Microsoft accounts: comment, message and mention text and who wrote it, email subjects and senders, Search Console and Google Analytics figures, questions and drafts taken from commenters’ words, and the names and email addresses of people who booked appointments. You see these in your Xorventa account; the assistant is told they are not shared. It can still publish a post you wrote to a network you connected.
- Prices and offers: what buying, upgrading, changing or cancelling a plan would cost, and promotion codes.
- Your private conversations with Xora on your account pages, and what Xora remembers about you — your saved preferences, reactions, writing samples, voice profile or session summaries.
- Your password, two-factor settings or recovery codes, and the sign-in credentials of the networks and services you have connected.
- What a connected assistant does receive is handled by the company that provides it, under that company’s own terms and privacy policy. See the Xorventa Privacy Policy, section 6, Connected AI Assistants.
Retention
What we keep, and for how long
- Sign-in: the assistant’s access credential lasts 15 minutes and is renewed with a refresh credential that lasts 30 days and is replaced each time it is used. We store only a one-way hash of each credential.
- Conversation with Xora: the last eight questions and answers for each connection, encrypted, so the assistant can continue the conversation. It stops being used 24 hours after the last question, and is erased at once when you disconnect the assistant.
- A daily clean-up deletes: expired connection requests, sign-in codes and access credentials an hour after they expire; refresh credentials an hour after they expire, or 30 days after they were replaced or cancelled; unused staged uploads an hour after they expire, and used ones 24 hours after use; expired Xora conversations an hour after they expire; a disconnected assistant’s remaining credentials and uploads 30 days after you disconnect it; and each finished action’s Connector record, including its encrypted result, after 90 days.
- Kept with your account: the entry for each action in what Xora did on your What Xora knows about you page, like every other Xora action, and the record of each connection — the assistant’s name and web address, the permissions you granted, and when it was connected, last used and disconnected.
Disconnecting
Disconnect an assistant
- In Xorventa: open Profile Settings and find Connected AI assistants. Each connection shows the assistant’s name, its permissions, when it was connected and when it was last used. Choose Revoke, then Yes, disconnect.
- It takes effect immediately. Every credential the assistant holds stops working, requests it made that have not yet been handed to another service are cancelled, and its Xora conversation is erased. Work already handed to another service before you disconnected cannot be recalled this way.
- In your assistant: you can also remove the connector from your assistant’s settings. That stops the assistant calling Xorventa; disconnecting in Xorventa is what ends the access on our side.
- To connect again later, add the connector again and approve its permissions again. If you delete your Xorventa account, every connected assistant is disconnected at once.
Troubleshooting
If something goes wrong
What your assistant reports, what it means, and what to do.
- “Connect this assistant to a Xorventa account first.” or a request to sign in again — The connection is not signed in: its 30-day sign-in lapsed, or you disconnected it. Reconnect from your assistant and approve again.
- “This connection was not granted xorventa:…” — The action needs a permission you did not grant. If you want to allow it, disconnect, connect again and tick that permission.
- “The owner has not allowed this yet. On the What Xora knows about you page, they can turn on: …” — Your switch for that kind of action is off. Turn it on at What Xora knows about you if you want to allow it.
- “… stays with the owner.” — The action is one of the configuration-and-money actions above. Do it yourself on the page your assistant names.
- “Data from Google, Meta or Microsoft accounts is not shared with connected assistants.” or “Billing previews and quotes are not shared with connected assistants.” — That information is not given to a connected assistant. See it in your Xorventa account.
- “This Xorventa account is asking Xora more than she can answer right now. Wait a minute, then try again.” — Your account has used its Xora answers for this minute (the limit is shared with Xora on your account pages). Wait a minute and ask again.
- “Xora is busy with other requests on this account — try again in a moment.” — Xora is already answering two questions for your account, from your assistant or your account pages. Ask again in a moment.
- “That was refused for now because of too many actions in a short time. Try again in a little while.” — Your account has asked for more than 40 actions in a minute, or more than 60 changes in 10 minutes. Wait, then ask again.
- An action refused as the wrong tool — The assistant sent the action to the tool for a different kind of action. Nothing ran; the assistant can send it to the right one.
- upload_quota_exceeded — Your account already has 20 staged files, or 200 MB, waiting to be used. Use the files already staged, or wait — unused files expire within an hour.
- upload_storage_full — Xorventa’s temporary file storage is full. Try again later; if it continues, contact support.
- too_large or type_not_allowed — The file is bigger than the limit for that action, or of a type it does not accept. See the limits under Files and uploads.
- size_mismatch, sha256_mismatch or content_not_… — The file sent does not match what was declared, or its contents are not the declared type. Prepare the upload again with the correct file details.
- “That upload was already used by another action, so nothing was done.” — Each upload can be used once. Stage the file again.
- An upload that has expired — The 10-minute upload link lapsed, or the connection was disconnected. Prepare a new upload.
- A proposal that expired — Nobody confirmed it within one minute. Ask your assistant to prepare it again if you still want it, and confirm it promptly.
- “The connection that asked for this was revoked, so nothing was done.” — You disconnected the assistant before the action started. Reconnect and ask again if you still want it.
- indeterminate — The action started but its outcome could not be confirmed; it may already have happened. Do not ask again until you have checked the page in your account or on the network.
- “Something went wrong on Xorventa’s side. Nothing was retried …” — A temporary problem on our side. Have the assistant check the action’s status first, then try again in a minute.
- The approval page says the request has expired, was already answered, or does not exist — The 10-minute connection request lapsed or was already used. Start connecting again from your assistant.
Help
Support
- Email support@xorventa.ai, or send us a message at https://xorventa.ai/contact.
- Tell us which assistant you use, roughly when the problem happened, and what the assistant reported. Never send us your password or a sign-in code.