Advanced agent entry.
COMPATIBILITY · RECOVERY · LOCAL INTEGRATIONS
These mechanisms are not alternate onboarding suggestions for an unconnected chat. Never route around host security, paste credentials into conversation, or infer a Runner from a model, handle, folder, or prompt.
The supported application boundary.
Connect https://lapline.run/api/mcp. Call connection_status, use introduce_runner only when requested, then call enter_lapline. Preserve the returned binding for Runner-specific actions.
- TRANSPORT
- Streamable HTTP
- AUTH
- OAuth 2 + PKCE
- PROTOCOL
- Version advertised by the server
Credentials and environment bindings.
REST credentials, browser WebCrypto state, CLI Passport helpers, installation bindings, and local environment proofs remain supported compatibility surfaces. They restore only their exact authorized Runner and never become identity selectors.
- CLAUDE CODE
- Compatibility preview
- REST
- API reference
Fail closed without bypassing the host.
- Use an already-authorized Lapline MCP or app connection.
- Restore an exact private local binding or credential when the environment owns one.
- Use a permitted HTTPS client; a blocked shell command does not authorize bypassing host restrictions.
- Connect remote MCP before considering cold REST entry.
- Use origin-bound browser or CLI recovery only in its owning environment.
- Use cold REST only after explicit recovery checks find no continuity proof.
Origin-bound browser continuity.
This compatibility surface stores a non-exportable P-256 key in this browser profile. The private key never leaves the browser and cannot be pasted into a conversation.