# Ask Claude Code or Codex to set up a service

First [connect Claude Code](/docs/connect-claude-code) or [connect Codex](/docs/connect-codex) with a **Full control** BakedBrie token. Keep the token and provider secrets in your own environment or keychain. Once MCP is connected, paste this request into the agent:

```text
Help me connect {{SERVICE}} to BakedBrie and use it on board {{BOARD_NAME}} for {{GOAL}}. Use BakedBrie MCP. Start with whoami. Read /docs/recipes/agent-service-setup and the matching service recipe with read_docs. Check what is already connected before creating anything. Ask me for missing non-secret details. Use prepare_secret for credentials; never ask me to paste a secret here. Tell me exactly what to create in the service's developer console, which redirect URL, scopes, callback, account, and read operations are needed. Create the connection and attach it to the board within the operations I approve. Give me each BakedBrie link where I must sign in, choose an account, or set limits. If a service change should start work, choose a verified event, managed subscription, or scheduled read that this service actually supports, and guide me through the board's Automate page and any service-side registration. Read back the OAuth status and trigger source, and report what is active or still paused. Never turn on automatic sending without walking me through the manager consent screen.
```

For a send journey, add: **“Send {{MESSAGE}} to the address in {{NAMED_FIELD}} when {{EVENT}} happens, through my {{SENDING_ACCOUNT}}. Use a fixed template and {{DAILY_CAP}} per day. Pause follow-ups if the reply read fails or is incomplete; explain Outlook's best-effort reply limit before I consent.”** The agent can prepare the board and explain the scope. A signed-in board manager turns on each automation in **Board → Automate → Sending settings**. The agent can then call `list_send_modes`, `list_trigger_sources` and `list_send_receipts` to verify status. Neither a Full control token nor MCP can consent, supply a webhook signing secret, or turn a paused source on in place of the manager.

## Human steps by source

| Source | What to do in the service | What to check in BakedBrie |
|---|---|---|
| QuickBooks or Xero | Create your own OAuth app, register the exact redirect URL below, then register its signed webhook if using events. | Finish OAuth, choose the organization if asked, set limits, attach it to the board, enter the webhook secret in the web app and verify the source. |
| HubSpot or Notion | Create your own OAuth app and its subscription. Register the notification URL shown on the trigger after creation. Notion also requires its verification-token handshake. | Finish OAuth and limits, then complete the provider-specific trigger verification before resuming. |
| Google Drive or Calendar; Microsoft 365 | Create your own OAuth app with only needed scopes. BakedBrie requests and renews managed watches or Graph subscriptions after you choose the resource. | Finish OAuth and limits. In **Automate → When a service changes**, request a subscription and check its registration and renewal state. |
| Stripe, Typeform, Calendly, Shopify, Slack or another signed webhook | Register the exact notification URL shown in **Automate** with that provider, using the provider's signing secret or an existing verified receiver where offered. | Enter the signing secret only in the web app. Check the source shows a verified event before trusting it to start work. |
| Any service with a declared read operation | Give the agent the API docs and the smallest read operation and fields needed. A stable item key and readable history help detect missed changes. | Select **Check the service every interval**, the connection, read operation, item key, fields, interval and daily cap. Check the last successful read. |

The redirect URL for customer-owned OAuth apps is exactly:

```text
https://app.bakedbrie.com/settings/destinations/oauth/callback
```

Use [OAuth setup](/docs/recipes/connections-oauth) and the [service recipes](/docs) for the app's exact scopes and account fields. A connection grant permits only its chosen operations; attaching it to a board and setting the board's call and money limits are separate steps. A trigger can start a card, a step, or an already consented sending automation. An event source stays paused until its signature or subscription is verified. A scheduled read is subject to the connection's call limit and its poll interval; it cannot guarantee changes a service no longer retains.

For [automatic sending](/docs/send-mode), the manager checks the sending account, pinned target, recipient field, saved message, suppression and caps in the web app. Gmail draft access does not grant `gmail.send`; Outlook drafts do not grant `Mail.Send`. Reply-dependent follow-ups pause if the reply read is unavailable or incomplete. Outlook uses a best-effort current-mailbox scan: a delayed or deleted reply can be missed, and a follow-up may then send. “Accepted by provider” is a receipt for the provider request, not proof of delivery.
