# AddMyLegacy > This site is chatbot-friendly and open for communication. A chat app can connect > on behalf of a person after that person approves it in the browser. Document, verify, share, and license intellectual assets. Public pages can be read without an account. Account actions run only after approval. ## Connect a chat app - Connector: https://addmylegacy.com/mcp - Protocol: Model Context Protocol (MCP), Streamable HTTP, JSON responses. - The first call without a bearer token (GET or POST) returns HTTP 401 and starts browser sign-in. - With a token, GET returns 405 JSON because there is no event stream. Send requests with POST. - The person approves with a passkey (Face ID or Touch ID on Apple devices) or a 6-digit email code. - Discovery: https://addmylegacy.com/.well-known/oauth-protected-resource/mcp - Authorization server: https://addmylegacy.com/.well-known/oauth-authorization-server - Client registration: https://addmylegacy.com/mcp/oauth/register/ (dynamic, no secret, PKCE S256) - Server card with every tool and its input schema: https://addmylegacy.com/.well-known/mcp/server-card.json - Human guide: https://addmylegacy.com/chat/ After approval, the chat app acts as that account. Public reads (certificates, license templates, and World Gallery) are included. Deleting an asset still needs the email confirmation code. Password changes and payouts stay on the website. ## Upload a file 1. create_asset with a title (the type is set from the file). 2. create_upload with asset_id, filename, and size. It returns a signed upload_url that expires in 15 minutes and accepts only that one file. 3. PUT the raw bytes to upload_url with the returned headers. Never put bytes in a tool call. 4. attach_upload with asset_id and upload_id. The asset moves to uploaded. 5. declare_rights with asset_id and use_account_defaults true. This copies the account rights profile onto the asset. No email code. 6. finalize_my_asset with asset_id. This issues the certificate. Any type is accepted: images, video, audio, 3D, documents, CAD, code, datasets, and archives (type other). Empty files, files over the size limit, and executables are refused. ## Tools - `asset_processing_status` (account read): Asset processing status - `attach_upload` (account write): Attach an uploaded file - `check_permission_grant_use` (public read): Check permission grant use - `confirm_sensitive_action_code` (account write): Confirm an email code - `create_asset` (account write): Create an asset draft - `create_license_offer` (account write): Create a license offer - `create_preservation_order` (account write): Create a preservation order - `create_upload` (account write): Start a file upload - `declare_rights` (account write): Declare rights - `delete_my_asset` (account write, deletes data): Delete my asset - `finalize_my_asset` (account write): Finalize my asset - `get_certificate_audit_reference` (public read): Get certificate audit reference - `get_certificate_document` (public read): Get certificate document - `get_certificate_signing_key` (public read): Get certificate signing public key - `get_certificate_transparency` (public read): Get certificate transparency record - `get_evidence_package_manifest` (public read): Get evidence package manifest - `get_license_credential` (public read): Get license credential - `get_my_asset` (account read): Get my asset - `get_ownership_credential` (public read): Get ownership credential - `get_public_license_offer` (public read): Get a public license offer - `get_rights_policy` (public read): Get rights policy - `list_asset_permission_grants` (public read): List public permission grants - `list_license_templates` (public read): List license templates - `list_my_assets` (account read): List my assets - `list_my_license_offers` (account read): List my license offers - `list_my_preservation_orders` (account read): List my preservation orders - `request_sensitive_action_code` (account write): Email a confirmation code - `update_my_asset` (account write): Update my asset - `verify_certificate` (public read): Verify a certificate - `verify_evidence_event` (public read): Verify an evidence event - `whoami` (account read): Who am I - `world_associate_observer` (public read): Associate an observer with placements - `world_comment` (account write): Comment on a placement - `world_my_placements` (account read): My world placements - `world_nearby_placements` (public read): Nearby world placements - `world_place_asset` (account write): Place a work in the world - `world_placement_detail` (public read): World placement detail - `world_remove_placement` (account write, deletes data): Remove a world placement - `world_search_placeable_assets` (public read): Search placeable works ## Public pages - [Home](https://addmylegacy.com/): what the platform does - [About](https://addmylegacy.com/about/): proof, sharing, licensing, and preservation - [Chat apps](https://addmylegacy.com/chat/): how a person connects a chatbot - [World Gallery](https://addmylegacy.com/world/): nearby placed works - [Marketplace](https://addmylegacy.com/marketplace/): works offered for license - [Protection](https://addmylegacy.com/protection/): content policy - [Terms](https://addmylegacy.com/terms/): terms of service - [Privacy](https://addmylegacy.com/privacy/): privacy policy ## Closed to crawlers Do not collect account pages, private assets, admin, or the JSON API. Use the connector instead of scraping signed-in pages.