Server HostPlaceholder name
All docs pages

Connecting your AI

Connect Claude, ChatGPT or any MCP client to your servers, choose what it may do, see what it did, and undo it.

DraftThis page is a first draft and may change.

You can run your server by talking to your own AI app. Ask it to install a plugin, change a setting, set up ranks, apply a premade setup, or explain why the server crashed. It works through a connector we host. You decide what it may do, you see everything it did, and you can undo it.

Your AI app pays for the AI. We do not charge for it and there is no extra fee to connect. The connector works on every plan, free included.

What works

Claude, ChatGPT and any other app that supports the MCP standard (for example Cursor and Claude Code). ChatGPT can add it on the plans that allow custom connectors (see Connect ChatGPT). Free Claude accounts can add one custom connector, which is why you only ever add one connector for your whole account, not one per server. Your AI asks which server you mean, then names it every time it acts.

Connect it

You add one connector for your whole account, not one per server. The connector address is https://mcp.test.quarrymc.net/mcp. You also find it in the panel under AI, and on the Connect your AI page.

Step-by-step guides for each app:

In every app the shape is the same: add a custom connector with the address, then the app sends you to Server Host to sign in, and you see the consent screen.

Inside your AI app, the connector is called Server Host (dev). While our own name is still a placeholder, that is a generic name, and it changes later; nothing for you to do.

Before an AI app can do anything, you see a screen that shows:

  • which AI app is asking. Apps we recognise are shown by name; any other app is marked unverified, because anyone can give an app any name. An app that pretends to be Claude or ChatGPT from somewhere else is refused before it gets this far.
  • the address your answer is sent back to, in full, so you can check it belongs to your app.
  • which of your servers it would be able to reach, and
  • for each server, what it may do: Allow, Ask or Block, for every action.

The app is marked Unverified app. Under Sends you back to the screen shows, in full, the address your sign-in goes back to, so you can spot a fake: for Claude it is https://claude.ai. If it is an address you do not know, choose Don't connect. The screen may also say which website the app says is its own; that is only the app's claim, and it is not where you are sent. Open a server to change what the AI may do there before you approve, and give the connection a name if you like (for example Claude on my laptop). Choose Connect to connect, or Don't connect to stop. Most apps then take you straight back to them; if one cannot, the screen tells you that you can close the tab. We email you about every new connection. You can disconnect it at any time in Account, Connected AIs, and it stops working at once.

Team members

Co-owners and admins of a server can connect their own AI to it. Their AI can only do what their role allows, and the server's Allow, Ask and Block settings still apply. Every action shows who did it. Moderators and viewers cannot use an AI on the server. If you remove someone from the team, their AI loses access to that server at once.

Allow, Ask, Block

Each server has its own list of actions, and each action has one of three settings:

  • Allow runs it straight away.
  • Ask sends it to your approvals. Nothing happens until you press Approve.
  • Block refuses it. The AI is told no.

Where to change it: the server's AI page, under What your AI may do, where three presets (Careful, Balanced, Full trust) set the whole table at once. See The AI page. You can fine-tune any single action after a preset. The full list, what each preset sets, approvals, Stop and undo are on Your AI's permissions and history.

Actions that can do damage start on Ask: giving or removing operator, ranks and permissions, deleting things and resetting a world, installing or removing plugins, restoring a backup, and building in the world. Everything else starts on Allow.

There are three one-click presets to start from: Careful, Balanced and Full trust. Pick one, then fine-tune any action. See AI permissions.

You can set any action to Allow. When you do, the panel shows a warning that says what the AI will now do without asking, and how it could be tricked. For actions that are not about one server, such as making a new server, the panel also asks for your password (or a code from your authenticator app) before it turns Allow on. Turning on Allow for one server, and approving the riskiest requests (operator and rank changes, a world reset, a roll back, a plugin from GitHub or a link), asks you to confirm it is you first if you signed in a while ago. For example, text hidden in a sign, a book or chat could trick an AI into doing something you did not want. Allow is your choice, and it is fine to use it for things you are comfortable with.

Your AI can never approve its own requests, change its own permissions or turn on chat reading. Only you can, in the panel. An approval is not run if you disconnected that AI, or set the action to Block, after it asked.

Your AI can also never spend your credits. It cannot buy, upgrade or boost anything. It can suggest one and send you a link to the panel, where only you can do it. Creating a server in a free slot is fine.

What your AI can do

Every call names a server, and that server's own settings apply.

  • Plugins and settings: find, install and set up plugins, and change server settings, config files and gamerules. It can install any plugin, not only ones from our catalog. Each file is checked for malware first, and you are warned when the source is not one we trust. Plugins from Modrinth and Hangar pass without a warning. A file the check blocks can never be installed. Gamerules change while the server is running, in its main world; if it is asleep, your AI asks you to start it first.
  • Ranks and permissions: make ranks and groups and give permissions in LuckPerms. The all-powerful * permission and LuckPerms' own permissions are for you to give in the panel.
  • Explaining and fixing: read logs and crash reports, run a diagnosis, explain what happened, and suggest or make a fix. See Troubleshooting.
  • Schedules: set up restarts, backups and commands on a timer.
  • Premade setups: look at the premade setups and apply or change one, for example "make it a lifesteal server with 5 hearts".
  • Servers: create a new server for you, inside your plan's limits. It never spends credits.
  • Commands: run commands from a limited list (messages, time, weather, gamemode, teleport, give and the like). It does not have your console, and it cannot op players, ban, run /execute or change permissions by command. It cannot hand out command blocks, books or signs, or post text that runs a command when someone clicks it, and commands with a backslash in them, which can hide one, are refused. You can do anything in your own Console.
  • Snapshots and undo: take a snapshot, roll back, and undo its own earlier changes.
  • Help pages: search these docs to answer your questions.

There is no special building tool. If you ask your AI to build, it can only use commands from its list, under your settings, with a snapshot first.

We do not put a limit on how much your AI may do on your behalf. Only a very high safety limit, far above normal use, stops a runaway loop or a stolen token.

What your AI can never do

Some things stay in the panel, whatever your settings: your AI's permissions and the chat reading switch, approving anything, your team, credits, plans and billing, account settings, SFTP logins, free file paths, deleting a server, moving regions, the internet filter, alerts, custom domains and downloading backups.

Before every change your AI makes, we save a snapshot. Next to each change is Undo, which puts the server back as it was before that change. Steps where your AI only looked (for example reading a file or listing plugins) changed nothing, so they have no Undo. Before you confirm, the panel tells you what will come back.

In config files, your AI cannot change a few settings that reach permissions or the server's own startup: where Bukkit reads permissions from, command aliases, Spigot's restart script, the proxy settings and commands that run at startup. It cannot add new sections to the server's own files either. If it tries, it is told why in plain words.

Your AI never sees passwords, keys or tokens. When it reads a config file, secrets in it are shown as [redacted: secret], and it cannot write a secret into a setting, a message or a Pane.

Safety, in short

  • Every tool is narrow. There is no free shell and no free file access.
  • Anything players wrote (chat, signs, books, names, logs) is marked as untrusted for your AI, so it knows not to follow it.
  • A snapshot is taken before every change, and every call is written to your history.
  • You can press Stop at any time, and revoke the connection at any time.

If something goes wrong

See Troubleshooting. If your AI says it cannot do something, check the Allow, Ask and Block settings for that server first, then your approvals. If it says it was stopped, someone pressed Stop on the server's AI page.