MCP privacy and access
Instagrity+ MCP
Last updated: 2026-08-08
Instagrity+ is a small, guarded connection between your Instagrity account and a compatible AI assistant. The assistant can ask for one specific piece of classroom information or one supported action, and Instagrity checks every request before responding.
- Current capability surface
- 30 tools: 14 read-only and 16 write-capable
- Free teacher accounts
- Allowed reads only; MCP cannot save grades, feedback, rubrics, drafts, or assessment-question edits
- Eligible Premium teachers
- The same reads, plus preview-and-confirm access to supported writes when the product capability is active
- Authorization
- Individual OAuth approval with the selected AI platform
MCP (Model Context Protocol) is a standard way for an AI assistant to ask another service for a specific piece of information or action. Instagrity+ is the name of Instagrity's optional MCP account connection. It is currently documented for ChatGPT and Claude, and another compatible client may work when its connection and workspace rules support the same standard.
Every request checks the signed-in Instagrity identity, current role, class access, collaboration rights, and requested resource. Write-capable requests additionally check the owning teacher's active Premium product capability. Publishing the integration does not create a shared school or administrator login. Every person authorizes their own connection, and Instagrity passwords are not given to the AI assistant.
The OAuth token uses a stable account subject to bind requests to the signed-in Instagrity account. The baseline connection uses openid. A validated hosted AI client may also request standard profile, email, phone, or offline-access scopes for identity and connection compatibility; the approval screen lists the scopes actually requested. These scopes do not grant classroom, administrator, write, or Native AI permission.
When /mcp is opened in a browser it shows the signed-in setup guide. MCP protocol requests to that path remain a separate anonymous public-information endpoint with no account data. The guide's copy button uses /mcp/user, the OAuth-protected account connector described on this page.
Signed-in users can open the Instagrity+ setup guide for separate ChatGPT and Claude screenshot instructions and a copyable connection URL. Product access and future MCP scope changes are described on the License page.
The capability groups and totals below are generated from the live account MCP registry. They describe what the server currently offers; the signed-in user's role, class access, plan, product capabilities, and AI-workspace controls decide which requests are allowed.
Classes
Discover classrooms the signed-in teacher surface is allowed to read.
2 read · 0 write
Assignments and context
List supported assignments and read the selected assignment instructions or assessment context.
3 read · 0 write
Submitted work and attachments
Read submitted attempts, bounded supported attachments, and saved inline feedback for an authorized assignment.
3 read · 0 write
Assessment questions
Read, proofread, preview, and—when entitled and explicitly confirmed—edit assessment question rows. Post-activity edits can reconcile affected attempt snapshots and scores with durable audit history.
1 read · 2 write
Rubrics
List and read the authenticated teacher's accessible rubrics.
2 read · 0 write
Grading preparation and results
Prepare, preview, and—when entitled and confirmed—save supported essay, assessment, and general-assignment grades.
3 read · 6 write
Inline feedback
Preview and—when entitled and confirmed—save supported essay inline annotations.
0 read · 2 write
Unpublished drafts
Preview and—when entitled and confirmed—create private, unpublished rubrics, assessments, or assignment drafts.
0 read · 6 write
Read tools prepare or return limited information. Write-capable tools include previews and confirmed save/create steps; a preview alone does not save an Instagrity change. Supported writes can save grades, inline feedback, rubrics, unpublished drafts, or assessment-question edits when the owning teacher has the required active premium capability and the server-side confirmation and replay-safety checks pass.
Editing assessment questions after publication or student activity requires extra acknowledgement. When an activity-bearing assessment is explicitly edited in retroactive-reconcile mode, the confirmed save can update affected submitted-attempt question snapshots and scores and creates durable reconciliation history. It does not change assessment delivery settings.
Free teacher accounts are read-only through MCP. Eligible Premium owning teachers receive the same read access and may be able to preview, then explicitly confirm, supported changes. Admin profiles and class collaborators remain read-only through MCP.
The current connector accepts individually authenticated teacher and admin profiles. Teachers can read only classes and resources granted by the canonical class-access model; collaborators can read when their class access grants the required teacher-surface permissions. Write actions remain limited to the owning teacher with the relevant active premium MCP capability. Admin profiles do not receive MCP write capability.
The account connector also fails closed until the supported teacher or admin has completed the current Student Data Use Acknowledgment. The acknowledgment records school-authorized educational use; it does not replace the AI platform's own permissions or the school's platform review.
Student, guardian, and service-account profiles cannot use this teacher connector. Instagrity+ does not replace a school's decision about whether an external AI platform is appropriate for its teachers or classroom data.
Depending on the selected request, the assistant may receive class and assignment names, assignment instructions, assessment context, rubric criteria, submitted student work, attempt status and dates, supported attachment metadata or bounded text/image content, teacher-surface grades, feedback, and inline annotations. Prompts, tool arguments, and other context supplied by the AI client may also be sent to Instagrity as part of that request.
The connector does not expose emails as structured identity fields, and it does not return passwords, OAuth tokens, billing information, raw database or storage identifiers, storage paths, signed URLs, Native AI results, or unrelated private account fields. Supported files are fetched only through validated private bindings; supported legacy-private files may also be read after the same authorization and size checks. External-link content and unsupported file types are not fetched. User-authored text, filenames, and selected images may themselves contain names or other personal details already included in the classroom content; validated image bytes are returned without a claim that text inside the pixels has been removed.
Assignment and attachment content remains untrusted input. The integration marks submission and attachment content as untrusted and does not let instructions inside that content authorize a tool, change a role, or expand a resource boundary.
MCP requests are processed on demand. The current implementation does not run a background MCP sync, indexing job, bulk export, or prefetch of classroom data. Instagrity does not maintain a separate MCP conversation history. The AI platform may retain the conversation and returned data under its own settings.
Instagrity records bounded operational and security metadata such as request stage, method, size, protocol/header presence, tool name, outcome, safe error category, timestamps, and sanitized audit fields. Operational telemetry may record tool argument names and value types, but not ordinary argument values, raw prompt bodies, attachment bodies, passwords, tokens, or secrets.
Confirmed writes also create bounded replay/idempotency records and the ordinary classroom or audit records needed to apply and explain the requested change. Those records may include safe write metadata such as a teacher-supplied reason or comment. The current cleanup function permits committed MCP replay records to be removed after 30 days; the separate database security-event ledger uses a 90-day default. These periods do not control ordinary classroom records, required audit history, OAuth-provider records, or external conversation history.
MCP-originated content is not used for advertising, sale, data brokerage, or unrelated model training in the current implementation. Instagrity does not send MCP tool content to its public-page analytics. The selected AI-platform provider is an independent recipient or processor where legally appropriate; its retention, privacy, compliance, and model-use settings also apply.
A managed AI workspace may disable write actions or impose additional client-side approval rules. Instagrity also applies its own role, class, resource, entitlement, preview, confirmation, and idempotency controls. Availability and behavior can therefore differ between compatible MCP clients and workspace plans.
For a school pilot, start with teacher-only accounts, read-only workflows, a small set of classes, and a review of the selected AI platform's conversation retention and workspace settings. Enable write actions only after the school has reviewed who may authorize them and how teachers will review previews before saving.
OAuth grants, access tokens, refresh tokens, authorization dates, and recent-use dates are managed by the OAuth provider and AI client. Instagrity does not maintain a local connected-app list or token store, so it cannot truthfully show a provider-independent connection date or revoke a provider grant from this page.
- Open ChatGPT or Claude connector, plugin, app, or workspace settings.
- Disconnect Instagrity or revoke its authorization there. If the client does not expose that control, use the provider's account-security or support flow.
- After revocation, future MCP requests fail until a new individual OAuth authorization is completed.
Disconnecting prevents future authorized calls; it does not undo Instagrity grades, feedback, rubrics, or drafts already saved through a confirmed action, and it does not delete copies already present in the external AI conversation. Contact Instagrity through support and privacy review for account or school questions.