AI Connector Documentation
How the Etch Express connector for Claude and ChatGPT works, how it is secured, and the controls administrators have over it.
Overview
Etch Express is production software for engraving, trophy, and awards shops. The Etch Express AI connector lets AI assistants such as Claude (Anthropic) and ChatGPT (OpenAI) work inside a user’s Etch Express workspace over MCP (Model Context Protocol). The connector always acts as the signed-in user - it has no identity, access, or permissions of its own.
How to Connect
Connecting takes about a minute per assistant. No API keys or configuration files are involved.
Claude
- Add Etch Express from the connector directory, or add it as a custom connector with the server URL https://api.etchexpress.ai/mcp.
- Approve the Etch Express authorization screen when prompted.
- Done - Claude can now work in your Etch workspace as you.
ChatGPT
- Add Etch Express from the connector directory, or add it as a custom connector with the server URL https://api.etchexpress.ai/mcp.
- Approve the Etch Express authorization screen when prompted.
- Done - ChatGPT can now work in your Etch workspace as you.
Connections are managed at app.etchexpress.ai under User Settings > Integrations, where any authorization can be reviewed or disconnected at any time.
Security Model
The connector is designed so administrators can reason about it the same way they reason about the Etch Express web app itself.
- Authorization uses OAuth 2.0 authorization code flow with PKCE, dynamic client registration, and standard discovery metadata. No API keys, no shared secrets, and no passwords are ever handled by the assistant.
- Every action executes the same permission-checked application endpoints as the web app, under the connected user’s identity. Permissions are re-checked live on every operation - role changes and revocations take effect immediately.
- Access requires all of the following: an active account, the organization’s "Allow AI integrations" setting enabled for that member, store membership with the relevant page permissions, and an active subscription. During early access, stores must also be enabled by Etch.
- Deliberately excluded: all billing and payment actions (Stripe checkout, billing portal, subscription changes) and Etch’s paid AI generation endpoints are not reachable through the connector.
- Access tokens are short-lived (10 minutes) with rotating refresh tokens and replay protection. Connections stay active while used and expire after 30 days of inactivity.
Administrator Controls
- Organization owners and admins toggle "Allow AI integrations" per member under Organization Settings > Members. Disabling it blocks that member’s connector use immediately.
- Users can disconnect any authorization themselves from User Settings > Integrations.
- When a member’s eligibility is revoked, their connection is automatically disconnected within minutes.
- All connector operations are audit-logged.
Data Handling
- The assistant sees only records the connected user can already access. There is no elevated or service-level view.
- Files are transferred directly between the assistant’s platform and Etch Express servers, with integrity checks.
- Data shared into an AI assistant is governed by that provider’s terms. Disconnecting stops new access but does not recall data already shared with the assistant.
Network Details
For teams that allowlist outbound traffic, the connector uses the following endpoints:
- MCP server: https://api.etchexpress.ai/mcp
- Authorization and consent pages: https://app.etchexpress.ai
- OAuth callbacks go only to the assistant platforms’ published callback URLs: https://claude.ai/api/mcp/auth_callback and https://chatgpt.com/connector_platform_oauth_redirect
Support
Questions from IT and security teams are welcome, including requests for more detail on any of the above.
support@etchexpress.aiEvaluating the connector for your organization?
Contact support@etchexpress.ai