Skip to content

Integrations

Let an assistant read your rooms,without handing it the keys.

Connect Claude, Claude Code, ChatGPT or an MCP client on your own computer to the data rooms you choose, on Business and Enterprise. It reads what you allow, writes or reorganises only if you say so, and cannot delete anything at all.

Plans
Business, Enterprise
Permissions
Four, each untickable
Rooms
Off until you say
Revoke
Any time

AI assistant access is rolling out to Business and Enterprise accounts. If the connection step does not find the server yet, it has not reached your account.

What it can do

A small, deliberate set of tools.

An assistant does not get a general connection to your account. It gets a fixed list of named tools, and that list is the whole surface. Everything absent from it is absent because it was left out on purpose.

Read

whoami
Which account this connection acts as, which permissions it holds, and which rooms it can reach.
list_datarooms
The data rooms you can reach whose owner is on Business or Enterprise.
list_documents
The documents inside a room you have shared with it.
read_document
The contents of a single document.
search_documents
Find documents by their text, with a matching passage from each. Covers markdown, HTML, PDF, Word, Excel and PowerPoint. A document becomes searchable when it is next saved or uploaded, and a scanned PDF with no text layer holds nothing to find.
list_document_versions
The saved version history of a document: version numbers, dates and sizes. No content.
read_document_version
The contents of one earlier version of a document. Earlier versions may contain material since removed or redacted.
get_storage_usage
How much of your storage allowance is used.
list_qa_threads
Questions counterparties have asked through a room's share links, with status, priority and a preview. Covers links you created or administer; the asker's email address is never returned, so threads are identified by the same Q-number you see in the app.
read_qa_thread
One question and every answer on it. Answers you kept private are included and labelled as internal, so an assistant reads the whole thread without mistaking a note you held back for a reply the asker saw. The asker's email address is never returned.
list_share_recipients
Which share links a room has and, for links you created, who they went to and when they last opened them. Recipient email addresses are never returned - a recipient appears under the label you typed for them. Link URLs and per-recipient access tokens are never returned either. For a colleague's link you are told only its creator can see its recipients.
get_room_engagement
How much each document has actually been read: views, distinct viewers, seconds actively engaged, and how far through people got. Aggregates only - no viewer identities, email addresses, IP addresses or locations - and your own previews are excluded.
search_unfiled_documents
Find your own documents that are not in any data room, by their text. These sit outside the rooms you chose when connecting, so reaching them is a separate permission you grant on the same screen. Only your own documents ever appear.
read_unfiled_document
The contents of one of your own documents that is not in any data room. A document that is in a room is refused here, whichever rooms you shared.
list_agent_selections
The documents you picked out for it in 99 Data Rooms, with the note you wrote. It sees them the next time it runs, because the protocol only lets the assistant ask; nothing here can start it off. Documents in rooms you did not share with that connection are left out.
read_documents
The contents of up to ten documents in one call. Each one is subject to exactly the same permissions as reading it singly, and one it cannot reach is reported on its own without stopping the rest.
compare_document_versions
What changed between two versions of a document, paragraph by paragraph. For a document written in the room the comparison is of the text itself; for a PDF or an Office file it is of the text read out of each version, and the assistant is told which case it is in so it can say so.

Write, only if you grant it

create_dataroom
Create a new data room. It cannot reach the new room until you reconnect and choose it.
create_text_document
Create a new markdown or HTML document in a room.
update_text_document
Update one it has already read, checking it has not changed underneath.
upload_document
Upload a file into a room.
draft_qa_answer
Write a draft reply to a counterparty's question, for you to review. Nothing is sent: the draft is visible only to you, the person who asked sees nothing, and publishing it stays a step you take yourself in 99 Data Rooms.

By design, it cannot

  • Delete a document, a room, or anything else
  • Archive anything, or empty a room
  • Rename or move anything, unless you grant Organise
  • Change who a room is shared with, or issue a link
  • Reply to a viewer comment in your name
  • Reach a room you did not choose at the moment you connected

These are not permissions held back at runtime. There is no tool for any of them, so there is nothing for a confused or manipulated assistant to call.

Pointing it at something

An assistant asks. It cannot be summoned.

The protocol behind this connection lets your assistant call us; it gives us no way to call your assistant. Nothing in 99 Data Rooms can start its turn, and we have not built a back channel that pretends otherwise. That is worth knowing before you wonder why nothing happened.

So there are two honest ways to point it at particular documents. Tick them in your documents list and choose Send to your assistant: we keep the choice, with an optional note, and the assistant picks it up the next time it runs, which you can hurry along simply by talking to it. Or choose Copy prompt, which puts a ready-made instruction on your clipboard naming those documents and the tool that reads them, for you to paste in right now. The first suits work you are queueing up; the second suits a question you are asking this minute.

A selection you leave is yours: it is visible only to you and to an assistant acting under your own grant, documents in rooms that connection cannot reach are left out of it, and it is deleted after seven days whether or not anything ever collected it.

Before it works

Four gates, and three of them fail quietly.

Wrong plan, an organisation veto, and a room left switched off all look identical from the assistant's side: it connects, reports success, and sees nothing. Work through these in order and that whole class of confusion disappears.

  1. Be on Business or Enterprise

    Room access for assistants is a Business and Enterprise capability. The plan that counts is the plan of the room's OWNER, not of whoever connects the assistant.

  2. If you are in an organisation, check it is not switched off company-wide

    An organisation owner can forbid AI assistant access for everybody. That veto overrides every individual room switch, and it applies to rooms that were already switched on.

  3. Switch AI access on for each room

    Every room is off by default, including rooms you create after connecting. This is the step people miss: a connection can be perfectly healthy and still see nothing, because no room has been switched on.

  4. Connect, and choose the rooms at that moment

    The rooms you tick during the connect flow are fixed for the life of that connection. Widening it later means connecting again; that is deliberate, so a connection cannot quietly grow.

How to connect

Three ways in, same consent screen.

Whichever client you use, the approval happens on our side: you confirm it is you, then tick the rooms it may reach. Nothing is shared before that screen.

Add it as a custom connector, then approve it once.

  1. Open Settings, then Connectors, then Add custom connector.
  2. Paste the server URL: https://mcp.99datarooms.com/authed-mcp
  3. Sign in with the email on your 99 Data Rooms account and enter the code we send you.
  4. Tick the rooms this assistant may reach, and confirm.

One command, then approve it in the browser tab it opens.

  1. Run: claude mcp add --transport http 99dr https://mcp.99datarooms.com/authed-mcp
  2. Run /mcpand choose to authenticate.
  3. Finish the same email step and room choice in the browser.
  4. Check it worked with /mcp: the server should list as connected.

Standard OAuth 2.1. Nothing about this server is bespoke.

  1. Point the client at https://mcp.99datarooms.com/authed-mcp. It advertises its own authorization server and protected-resource metadata, so a compliant client needs no further configuration. OpenAI Codex connects this way.
  2. Client registration is dynamic and open, so there is no key to request from us first.
  3. PKCE with S256 is required. A request without it is refused.
  4. Ask for datarooms.read, datarooms.write, or both. An unrecognised scope is refused outright rather than quietly dropped, so a client can never believe it holds a permission it was not granted.
datarooms.read Read
See what this connection can reach, list rooms, list the documents in them, read and search documents, read several at once, read an earlier version of a document, compare two versions, pick up a set of documents you chose for it, see storage usage, read the Q&A on a room's share links, see which links exist and who they went to, and see how much each document has been read.
datarooms.write Write
Create a data room, create and update native text documents, and upload a file. Granted separately from read.
documents.unfiled.read Beyond your rooms
Search and read documents you own that you have not filed in any data room. The room list you choose when connecting does not limit this one, which is why it is a separate tick rather than part of Read.
datarooms.organise Organise
Create folders, move documents into them, and rename documents. Filing only: it never deletes anything and never changes what a document says. Granted separately from Write, so an assistant that can draft cannot reorganise your room and one that can file cannot rewrite your documents.

Per-assistant guides

Setting up your own assistant.

The steps above cover every MCP client. These go further for the three assistants people ask about most, including the parts each one gets wrong.

Worth knowing first

Where your documents actually go.

An assistant sends the contents of the rooms you give it to your own AI provider, under your agreement with them, not ours. A zero data retention agreement you hold may not cover this route: Anthropic, for one, states that data processed by third-party tools or MCP servers is not covered by ZDR. If retention matters to you, check with your provider before you connect one.

We also make no claim to prevent prompt injection. An assistant reading a document that contains instructions may follow them, which is why the tool surface above is as small as it is and why nothing in it can destroy anything. See our security page for how we think about that.

Questions

The ones people actually ask.

It cannot delete or archive anything: no such tool exists for it to call. It can only write if you grant write access separately, and then it creates and updates documents rather than removing them. It can rename or move documents only if you grant the separate organise permission, and even then nothing is deleted.

Only the rooms you tick at the moment you connect it, and only if those rooms have AI access switched on. Every room is off by default. The set is fixed for the life of that connection, so it cannot quietly widen later.

The room contents an assistant reads are sent to your own AI provider, under your agreement with them, not ours. That is the point worth checking before you connect one: a zero data retention agreement you hold may not cover this route. Anthropic, for one, states that data processed by third-party tools or MCP servers is not covered by ZDR.

Yes. Every action is recorded and the room owner can read that record, with the room attribution derived from the caller's own session rather than from anything the assistant claims about itself.

Revoke it in Settings, under Connected apps. It stops working on its next request. Where the underlying session cannot be closed immediately, the panel says so rather than claiming a clean kill.

Yes. An organisation owner can switch AI assistant access off company-wide, which overrides every individual room switch and applies to rooms that were already switched on.