Why you need your admin
Cornelius plugs into Claude as a custom connector: a remote MCP server that Claude talks to on your behalf. On Free, Pro and Max plans you add it yourself. On Team plans only an Owner or Primary Owner can add a custom connector, and on Enterprise plans the same goes for anyone whose custom role includes managing the organization's libraries. If your Connectors page has no way to add one, that is why.
The fix is a one-time step on their side. After it, the connector shows up for everyone in your organization, and each person decides whether to connect.
The message to send
Copy this into an email or a chat message to your Claude admin. It has everything they need, including a link back to this page for the security details.
Subject: Please add the Cornelius connector to our Claude organization Hi, I would like to use Cornelius, a personal memory and daily routine connector for Claude, in our Claude workspace. On our plan only an Owner can add a custom connector, so I need a one-time setup from you. It takes about two minutes: 1. Open Organization settings, then Connectors (claude.ai/admin-settings/connectors). 2. Click Add, then Custom, then Web. 3. Name: Cornelius URL: https://mcp.cornelius.bot/mcp 4. Authentication: Sign in now. OAuth client: Use Claude's published identity (Recommended). No client ID, secret or request headers are needed. 5. Click Add. After that, each of us connects with our own Cornelius account. The organization shares no credential, and nobody gets access to anyone else's data. What it can access, where the data lives, and how to block or remove it: https://cornelius.bot/teams Thank you
For the admin: add Cornelius to your organization
You need to be an Owner or Primary Owner (on Enterprise, a custom role with access to manage libraries works too). Claude's own guide to this screen is Add a connector that isn't in the directory.
- Open the organization's connectors. In Claude, go to Organization settings, Connectors.
- Add a custom connector. Click Add, then Custom. If Claude asks for the connector type, choose Web.
- Name and address. Name it
Corneliusand enter the server URLhttps://mcp.cornelius.bot/mcp. - Authentication. Choose Sign in now, so each member signs in to their own Cornelius account before using it.
- OAuth client. Choose Use Claude's published identity (Recommended). Cornelius supports it, so there is nothing to register and no client ID or secret to enter. Register automatically also works if you prefer it.
- Leave the rest empty. No request headers, and leave Advanced, Transport as it is. If your dialog shows a name, a URL and Advanced settings on one screen instead, fill in the name and URL and leave Advanced settings empty.
- Click Add. Cornelius now appears for every member under Customize, Connectors, with the Custom label.
Do not set up Managed authorization for Cornelius. That feature signs the whole organization in through one shared authorization. Cornelius is a personal memory: every member must sign in as themselves, so leave members connecting individually.
Settings at a glance
| Name | Cornelius |
|---|---|
| Remote MCP server URL | https://mcp.cornelius.bot/mcp https://mcp.cornelius.bot/mcp |
| Authentication | Sign in now |
| OAuth client | Use Claude's published identity (Recommended) |
| Client ID and secret | None |
| Request headers | None |
| Transport | Default |
| Managed authorization | Off. Members connect individually |
Then each member connects
Once the connector is in the organization, every member who wants Cornelius does this with their own account:
- Sign up at app.cornelius.bot, if you have not already.
- In Claude, go to Customize, Connectors and find Cornelius with the Custom label.
- Click Connect, sign in to your Cornelius account, and approve access.
- Carry on with the Cornelius setup wizard from the next step: the Cornelius Project, the one line you paste, and the daily task. If the wizard offers to add the connector to Claude, skip that part: your admin already did.
Cornelius runs in Claude Cowork, in the desktop app and on the web. Ordinary Claude chat outside Cowork and the mobile apps are not supported yet.
What your organization is approving
Adding the connector lets members who choose to connect give Claude seven tools on their own Cornelius memory. Nothing else in your organization is reachable through it.
| Tool | What it does | Access |
|---|---|---|
bootstrap | Loads the agent's instructions, the member's profile and current state, at the start of a conversation | Read |
read_node | Reads one memory file and its links | Read |
search | Searches the member's memory | Read |
read_events | Reads the member's append-only event log | Read |
get_daily_playbook | Loads the routine for the scheduled daily run | Read |
get_skill | Loads one skill's instructions by name | Read |
commit | Saves to memory: notes, learned facts, reports, the daily summary. Every write is versioned and scanned | Write |
There is no delete tool. Deleting happens only in the member's Cornelius dashboard, behind an email confirmation.
How the connection works
- Who connects to whom. Claude calls Cornelius from Anthropic's infrastructure, not from your employees' devices. Cornelius never connects into your network and makes no calls to your other systems.
- Sign-in. OAuth with PKCE, run by WorkOS AuthKit. Claude identifies itself with its published client identity, and every token is bound to the Cornelius server (resource indicators). The requested scopes are
openid profile email offline_access: the member's identity and email, plus a refresh token so they stay connected. - Every call is checked. The token is verified on each request; the server keeps no session. No API keys or shared secrets exist, and tokens are never written to logs.
- Gmail and Calendar stay with Claude. The morning brief reads mail and calendar through the member's own Claude connectors. Cornelius never receives those credentials.
Data and privacy
- What is stored. The text a member's agent writes to memory (notes, facts it learned, reports, daily summaries), the event log beneath it, every earlier version, and the account email. Plus standard server logs, kept for 90 days. The full list is in the Privacy Policy.
- What is never stored. Connector credentials, full emails or attachments, API keys, payment details.
- No AI on our side. Cornelius stores and serves text. All interpretation happens inside your Claude, under your organization's agreement with Anthropic.
- One brain per person. Separation is enforced inside the database with row-level security, not just in application code. Details on the Data security page.
- Where it lives. Managed infrastructure at Render in the United States, behind Cloudflare. Encrypted in transit and at rest.
- Who runs it. Cornelius.bot, Rishon LeZion, Israel.
Worth deciding up front: if a member points the morning brief at their work mail and calendar, short summaries of that mail and those meetings are written to their Cornelius memory. If your policy keeps work email content inside your mail provider and Anthropic, ask members to use Cornelius without the work mail connector, or not at all.
Staying in control
- Remove it for everyone. Organization settings, Connectors, then Remove on Cornelius. It disappears for every member, and Claude can no longer call it.
- Block single tools. In Customize, Connectors, each tool can be set to Blocked. Blocking
commitmakes Cornelius read-only, though its memory then stops growing. - Off per conversation. Members can switch the connector off for any chat from the + menu, under Connectors.
- Changing settings later. Claude does not allow editing a connector's authentication after it is added. Remove it and add it again; members then reconnect.
- When someone leaves. Removing them from your Claude organization ends Claude's access. Their Cornelius account is personal, so their memory stays theirs: they can export it as a zip or delete it from the dashboard. Your organization has no access to it either way.
Questions IT usually asks
Do we need an IP allowlist?
No. Cornelius is a public HTTPS endpoint behind Cloudflare and does not publish fixed IP addresses. Claude reaches it from Anthropic's public IP ranges, and the only thing that grants access is a valid token for a signed-in member.
Is Cornelius in Anthropic's Connectors Directory?
Not yet. It is added as a custom connector, so Claude labels it as an unverified service, as it does for every custom connector. This page and the Data security page are what we offer for your review in the meantime.
Is there an organization account, SSO or SCIM?
Not today. Cornelius accounts are personal, one per member, and each member signs up with their own email. Your control point is the connector in Claude: add it, block tools, or remove it.
Can the organization see what members store?
No. Neither Owners nor other members can read anyone's memory. Each member can export or delete their own from the dashboard.
What does it cost?
Cornelius is in a free private beta. There is nothing to buy and no payment details to hand over.
Contact
Security questions, a review questionnaire, or a problem to report: write to general@cornelius.bot and we will get back to you.
Claude's screens change from time to time. If a label here no longer matches what you see, Claude's own guide Add a connector that isn't in the directory is the reference, and please tell us so we can update this page.