Skip to content
Open the app

Connect an AI assistant to the console (MCP)

The console runs its own MCPAn open standard that lets AI assistants call tools on a server in a consistent way. server, separate from the public Knowledge Base one. A staff member connects an assistant they already use, signs in with their university account, and the assistant can then work in the console as them: reading the cohort's weekly content and writing drafts, and, where the institution allows it, reading the same aggregate figures the Insights page shows.

Not yet available to institutions

The privacy terms now cover it: the data processing agreement (clause 3.7), the pilot charter and the privacy policy were updated on 6 October 2026 to describe it. First Six has not yet made it available to institutions, so the console refuses every connection and the setting below reads "Not available yet".

What it can and cannot do

It acts as the person who connected it, with their permissions and nothing more.

It canIt cannot
List cohorts and audience groupsPublish anything
Read a week's existing content and your university's connected source pagesChange settings, roles or people
Draft events, weekly blocks, links, help routes and Ask Anything answersRead or change an individual student's information
With the insights switch: read check-in trends, leaving reasons and the evidence pack, with groups under five suppressedTouch help requests or the crisis pathway

Everything it writes is a draft. A person reviews and publishes it in the console, exactly as with the console's built-in assistant, and every call it makes is written to your institution's audit log with the assistant's name and the tool it used.

Three switches, all off by default

  1. First Six makes it available. A platform setting, off today.
  2. Your institution switches it on, in Settings, Integrations, under AI assistants, by someone with the manage integrations permission. Content access and insights access are separate switches. Turning either off disconnects every assistant straight away.
  3. Each person consents on a consent screen when they connect, and needs the author content permission for content access or the view insights permission for insights access.

All three are re-checked on every request, so a permission removed this morning stops working this morning.

Connecting

The server address is your console's address followed by /api/mcp, for example:

https://console.firstsix.com.au/api/mcp

In Claude, add it under Settings, Connectors, Add custom connector. Claude then opens the console's sign-in, you sign in with your university account as usual, and a consent screen shows the assistant's name, what it is asking for, and where it will send you back to. The name is whatever the assistant calls itself, so the return address is the part to check: the screen names the ones it recognises (claude.ai, chatgpt.com, or an app on your own computer) and warns you about any other. Choose Connect.

To disconnect, open Your account in the console and choose Disconnect next to the assistant. Someone who manages integrations can also see and disconnect every assistant connected at your institution.

How it is secured

  • OAuth 2.1 with PKCE, the standard MCP clients expect, with the console as its own authorisation server. Login is your institution's existing single sign-on; First Six never sees a password.
  • Public clients only. Assistants register themselves (dynamic client registration) and receive no secret, because PKCE is the protection.
  • Tokens are stored only as hashes. An access token lasts an hour. A refresh token lasts 30 days, is replaced every time it is used, and a connection cannot be extended past 90 days without connecting again. Presenting an old refresh token ends the whole connection, because it means two parties hold it. The one allowance is a retry within 30 seconds by the same assistant, which is what a dropped network response looks like; if that retry was really a copied token, the connection ends the next time the genuine assistant renews.
  • Tokens are bound to this server (the resource parameter), so one issued for the console cannot be replayed somewhere else.
  • Log out everywhere ends connections too.
  • Rate limits: 120 requests a minute per connection, plus limits on registration and the token endpoint (see Authentication, rate limits, and errors).

Who processes what

Each staff member chooses which assistant to connect. Your institution decides whether its staff may connect one at all, and today that is the only choice it makes: nothing yet limits connections to particular assistants, so an institution that has approved one provider should say so in its own staff guidance (a per-institution list of approved assistants is planned before this is switched on for any university).

The assistant's provider (for example Anthropic for Claude, or OpenAI for ChatGPT) processes what the assistant reads, under whatever terms apply between your institution and that provider. It is not a First Six subprocessor, because First Six neither chooses nor contracts with it; clause 3.7 of the data processing agreement sets this out. With content access, what it reads is your institution's authored content. With insights access it also reads aggregate figures that never name or identify a student.

Common questions

Can the assistant publish to students by mistake?

No. There is no publishing tool on this server at all. Drafts reach students only when a person publishes them in the console.

Can it see a particular student's check-ins?

No. Even with insights access it reads only group figures, and any group smaller than five is suppressed in the database before anything leaves it.

What does a demo account do?

A demonstration session cannot connect an assistant. Sign in with your own account.

How do we see what an assistant did?

In the console's audit log. Each connection, each call and each disconnect is a row, naming the person and the assistant, including disconnects the console makes by itself (for example when someone leaves, loses the permission, or a renewal token is used twice).

Was this helpful?
Need more help?

The fastest answer is usually one question away.

Contact us
Edit this page on GitHub