01Grant narrow access
02Check the proposed action
03Record the decision
Explanatory diagram. A conceptual reading aid, not benchmark or ROI data.

Start with two kinds of information

A business website is meant to be discovered. Service descriptions, public FAQs, and ordinary contact routes can also be useful to software agents. Customer records, private documents, and job details belong behind a different boundary.

Decide what you intend to publish before designing an API. Do not generate a public catalog by giving a model unrestricted private access and asking it to hide anything sensitive.

What a public catalog can contain

A simple catalog might list service names, descriptions, delivery options, prerequisites, constraints, and a link to begin an inquiry. Its job is to explain the business. Keep it read-only: reading a service description should not book a visit, accept terms, charge a card, or retrieve a customer order.

OpenAPI provides a standard way to describe an HTTP interface. Documentation helps clients understand an interface; it does not enforce permissions.

A visible key cannot protect private data

If everyone can copy a key from a webpage, everyone can use it. Treat such a value as a public identifier, not proof that a visitor may access an account. For intentionally public data, a keyless read-only endpoint is often simpler, with caching and abuse controls appropriate to the site.

Privileged provider keys must stay out of browser-delivered code. See OpenAI’s API key safety guidance.

Private actions need separate checks

A private interface should establish who is calling and what that caller may do. Being signed in is only the beginning: the system must also check the business, the record, the requested operation, and current permission. A permission to read a lead should not silently become permission to send that lead a message.

For MCP connections, the official security guidance discusses token validation, scope minimization, confused-deputy risks, and why token passthrough is unsafe.

Trace where the information goes

Ask for a plain-language data flow: source tool, application, model provider, storage, logs, and any destination. “Private” should describe access and handling under disclosed terms. It should not imply that no provider processes the data.

Retention differs by provider feature and configuration. Review the actual endpoints and account settings used in the project. For example, OpenAI publishes product-specific behavior in its data-controls documentation.

Use a short launch checklist

  • Anonymous visitors see only owner-approved public information.
  • Wrong-tenant and wrong-role requests fail.
  • Revoked connections stop privileged work.
  • Each action checks the current permission and required approval.
  • Logs capture what happened without storing secrets.
  • Public discovery cannot call a private or mutating function.

InstallAI’s private workspace and authenticated agent interface are planned product directions. This public catalog does not imply those capabilities are live.