Integrations
Let an assistant read your rooms,without handing it the keys.
Connect Claude, Claude Code, ChatGPT or an MCP client on your own computer to the data rooms you choose, on Business and Enterprise. It reads what you allow, writes or reorganises only if you say so, and cannot delete anything at all.
- Plans
- Business, Enterprise
- Permissions
- Four, each untickable
- Rooms
- Off until you say
- Revoke
- Any time
AI assistant access is rolling out to Business and Enterprise accounts. If the connection step does not find the server yet, it has not reached your account.
What it can do
A small, deliberate set of tools.
An assistant does not get a general connection to your account. It gets a fixed list of named tools, and that list is the whole surface. Everything absent from it is absent because it was left out on purpose.
Read
whoami- Which account this connection acts as, which permissions it holds, and which rooms it can reach.
list_datarooms- The data rooms you can reach whose owner is on Business or Enterprise.
list_documents- The documents inside a room you have shared with it.
read_document- The contents of a single document.
search_documents- Find documents by their text, with a matching passage from each. Covers markdown, HTML, PDF, Word, Excel and PowerPoint. A document becomes searchable when it is next saved or uploaded, and a scanned PDF with no text layer holds nothing to find.
list_document_versions- The saved version history of a document: version numbers, dates and sizes. No content.
read_document_version- The contents of one earlier version of a document. Earlier versions may contain material since removed or redacted.
get_storage_usage- How much of your storage allowance is used.
list_qa_threads- Questions counterparties have asked through a room's share links, with status, priority and a preview. Covers links you created or administer; the asker's email address is never returned, so threads are identified by the same Q-number you see in the app.
read_qa_thread- One question and every answer on it. Answers you kept private are included and labelled as internal, so an assistant reads the whole thread without mistaking a note you held back for a reply the asker saw. The asker's email address is never returned.
list_share_recipients- Which share links a room has and, for links you created, who they went to and when they last opened them. Recipient email addresses are never returned - a recipient appears under the label you typed for them. Link URLs and per-recipient access tokens are never returned either. For a colleague's link you are told only its creator can see its recipients.
get_room_engagement- How much each document has actually been read: views, distinct viewers, seconds actively engaged, and how far through people got. Aggregates only - no viewer identities, email addresses, IP addresses or locations - and your own previews are excluded.
search_unfiled_documents- Find your own documents that are not in any data room, by their text. These sit outside the rooms you chose when connecting, so reaching them is a separate permission you grant on the same screen. Only your own documents ever appear.
read_unfiled_document- The contents of one of your own documents that is not in any data room. A document that is in a room is refused here, whichever rooms you shared.
list_agent_selections- The documents you picked out for it in 99 Data Rooms, with the note you wrote. It sees them the next time it runs, because the protocol only lets the assistant ask; nothing here can start it off. Documents in rooms you did not share with that connection are left out.
read_documents- The contents of up to ten documents in one call. Each one is subject to exactly the same permissions as reading it singly, and one it cannot reach is reported on its own without stopping the rest.
compare_document_versions- What changed between two versions of a document, paragraph by paragraph. For a document written in the room the comparison is of the text itself; for a PDF or an Office file it is of the text read out of each version, and the assistant is told which case it is in so it can say so.
Write, only if you grant it
create_dataroom- Create a new data room. It cannot reach the new room until you reconnect and choose it.
create_text_document- Create a new markdown or HTML document in a room.
update_text_document- Update one it has already read, checking it has not changed underneath.
upload_document- Upload a file into a room.
draft_qa_answer- Write a draft reply to a counterparty's question, for you to review. Nothing is sent: the draft is visible only to you, the person who asked sees nothing, and publishing it stays a step you take yourself in 99 Data Rooms.
By design, it cannot
- Delete a document, a room, or anything else
- Archive anything, or empty a room
- Rename or move anything, unless you grant Organise
- Change who a room is shared with, or issue a link
- Reply to a viewer comment in your name
- Reach a room you did not choose at the moment you connected
These are not permissions held back at runtime. There is no tool for any of them, so there is nothing for a confused or manipulated assistant to call.
Pointing it at something
An assistant asks. It cannot be summoned.
The protocol behind this connection lets your assistant call us; it gives us no way to call your assistant. Nothing in 99 Data Rooms can start its turn, and we have not built a back channel that pretends otherwise. That is worth knowing before you wonder why nothing happened.
So there are two honest ways to point it at particular documents. Tick them in your documents list and choose Send to your assistant: we keep the choice, with an optional note, and the assistant picks it up the next time it runs, which you can hurry along simply by talking to it. Or choose Copy prompt, which puts a ready-made instruction on your clipboard naming those documents and the tool that reads them, for you to paste in right now. The first suits work you are queueing up; the second suits a question you are asking this minute.
A selection you leave is yours: it is visible only to you and to an assistant acting under your own grant, documents in rooms that connection cannot reach are left out of it, and it is deleted after seven days whether or not anything ever collected it.
Before it works
Four gates, and three of them fail quietly.
Wrong plan, an organisation veto, and a room left switched off all look identical from the assistant's side: it connects, reports success, and sees nothing. Work through these in order and that whole class of confusion disappears.
- Be on Business or Enterprise
Room access for assistants is a Business and Enterprise capability. The plan that counts is the plan of the room's OWNER, not of whoever connects the assistant.
- If you are in an organisation, check it is not switched off company-wide
An organisation owner can forbid AI assistant access for everybody. That veto overrides every individual room switch, and it applies to rooms that were already switched on.
- Switch AI access on for each room
Every room is off by default, including rooms you create after connecting. This is the step people miss: a connection can be perfectly healthy and still see nothing, because no room has been switched on.
- Connect, and choose the rooms at that moment
The rooms you tick during the connect flow are fixed for the life of that connection. Widening it later means connecting again; that is deliberate, so a connection cannot quietly grow.
How to connect
Three ways in, same consent screen.
Whichever client you use, the approval happens on our side: you confirm it is you, then tick the rooms it may reach. Nothing is shared before that screen.
Add it as a custom connector, then approve it once.
- Open Settings, then Connectors, then Add custom connector.
- Paste the server URL:
https://mcp.99datarooms.com/authed-mcp - Sign in with the email on your 99 Data Rooms account and enter the code we send you.
- Tick the rooms this assistant may reach, and confirm.
One command, then approve it in the browser tab it opens.
- Run:
claude mcp add --transport http 99dr https://mcp.99datarooms.com/authed-mcp - Run
/mcpand choose to authenticate. - Finish the same email step and room choice in the browser.
- Check it worked with
/mcp: the server should list as connected.
Standard OAuth 2.1. Nothing about this server is bespoke.
- Point the client at
https://mcp.99datarooms.com/authed-mcp. It advertises its own authorization server and protected-resource metadata, so a compliant client needs no further configuration. OpenAI Codex connects this way. - Client registration is dynamic and open, so there is no key to request from us first.
- PKCE with S256 is required. A request without it is refused.
- Ask for
datarooms.read, datarooms.write, or both. An unrecognised scope is refused outright rather than quietly dropped, so a client can never believe it holds a permission it was not granted.
datarooms.readRead- See what this connection can reach, list rooms, list the documents in them, read and search documents, read several at once, read an earlier version of a document, compare two versions, pick up a set of documents you chose for it, see storage usage, read the Q&A on a room's share links, see which links exist and who they went to, and see how much each document has been read.
datarooms.writeWrite- Create a data room, create and update native text documents, and upload a file. Granted separately from read.
documents.unfiled.readBeyond your rooms- Search and read documents you own that you have not filed in any data room. The room list you choose when connecting does not limit this one, which is why it is a separate tick rather than part of Read.
datarooms.organiseOrganise- Create folders, move documents into them, and rename documents. Filing only: it never deletes anything and never changes what a document says. Granted separately from Write, so an assistant that can draft cannot reorganise your room and one that can file cannot rewrite your documents.
Per-assistant guides
Setting up your own assistant.
The steps above cover every MCP client. These go further for the three assistants people ask about most, including the parts each one gets wrong.
Worth knowing first
Where your documents actually go.
An assistant sends the contents of the rooms you give it to your own AI provider, under your agreement with them, not ours. A zero data retention agreement you hold may not cover this route: Anthropic, for one, states that data processed by third-party tools or MCP servers is not covered by ZDR. If retention matters to you, check with your provider before you connect one.
We also make no claim to prevent prompt injection. An assistant reading a document that contains instructions may follow them, which is why the tool surface above is as small as it is and why nothing in it can destroy anything. See our security page for how we think about that.
Questions
The ones people actually ask.
It cannot delete or archive anything: no such tool exists for it to call. It can only write if you grant write access separately, and then it creates and updates documents rather than removing them. It can rename or move documents only if you grant the separate organise permission, and even then nothing is deleted.
Only the rooms you tick at the moment you connect it, and only if those rooms have AI access switched on. Every room is off by default. The set is fixed for the life of that connection, so it cannot quietly widen later.
The room contents an assistant reads are sent to your own AI provider, under your agreement with them, not ours. That is the point worth checking before you connect one: a zero data retention agreement you hold may not cover this route. Anthropic, for one, states that data processed by third-party tools or MCP servers is not covered by ZDR.
Yes. Every action is recorded and the room owner can read that record, with the room attribution derived from the caller's own session rather than from anything the assistant claims about itself.
Revoke it in Settings, under Connected apps. It stops working on its next request. Where the underlying session cannot be closed immediately, the panel says so rather than claiming a clean kill.
Yes. An organisation owner can switch AI assistant access off company-wide, which overrides every individual room switch and applies to rooms that were already switched on.