What is the connection key?
When you go to Account → Your AI, bernard gives you a setup prompt to paste into your AI — and inside it is a connection key. It's worth knowing exactly what that key can do, because that is the whole safety story.
What the key allows
The key lets your AI read your sites' pages, write changes to a draft, and — when you ask it to — make that draft live. It is scoped to your own sites and only yours, and it stays valid until you replace it.
That third power is the one worth being clear about, because it's the one people assume isn't there. A connected AI acts with your authority: it can publish, exactly as you can. It is instructed to do so only when you ask in plain words, and never on its own initiative — but that is an instruction it follows, not a wall it cannot climb.
The wall is somewhere better. Every publish is written into your version history with what changed, when, and that it came from your connected assistant. bernard keeps a full year of that history, so anything that goes live can be put back. Your protection isn't that the AI is unable to act — it's that nothing it does is hidden, and nothing it does is permanent.
If you want the stricter arrangement
Bernard in your dashboard works differently. He edits the same drafts, but he cannot publish at all — the Approve button is yours alone, pressed on the preview page while signed in to your account. If you want the version where nothing reaches the public without you, that's the one to use.
Replacing the key is your kill switch
Only one connection key is active per account at a time — one setup covers all your sites. Replacing it in Account → Your AI mints a fresh key and the old one stops working immediately.
Treat the key like a password rather than a bookmark: anyone holding it can do what your AI can do, publishing included. If you think it has leaked, replace it — that revokes it on the spot, and the history means anything done with it can be undone.
Usage is capped at 60 requests per minute and 1,000 writes per day, generous enough that a real editing session never notices.
The prompt
“Explain what you can and can't do on my sites with the connection I've set up — including whether you're able to publish — and how I replace it.”
The [bracketed] parts are yours to fill in. First time? Connect bernard to your AI over MCP — a one-time setup in bernard → your site → Use your own AI — then paste the prompt above.
Questions people ask
- What is the connection key bernard gives my AI?
- It's the key inside the setup prompt you paste when you connect your AI in Account → Your AI. It lets your AI read your sites, edit them on a draft, and — when you ask it to — make that draft live. It covers all your bernard sites and stays valid until you replace it.
- Can my AI publish to my live site?
- Yes, when you ask it to. A connected AI acts with your authority — that's the point of connecting it — so it can make a draft live the same way you would by pressing Approve. It's instructed never to publish on its own initiative, and every publish is recorded in your version history and can be put back. Bernard in your bernard dashboard is different: he can't publish at all, only you can.
- Do I need this key if I use Claude on the web?
- No. Claude on the web connects with a one-click sign-in instead of a pasted key — you press Connect to Claude in Account → Your AI, sign in and press Allow. There's no key to copy, and you disconnect it any time from the same place. Some other assistants (like ChatGPT on Business or Enterprise plans) can also sign in this way; the pasted key described here is mainly for desktop apps such as Claude Desktop and Cursor. Either way the connection can do the same things.
- How do I change or revoke my connection?
- Go to Account → Your AI, open 'Want to change your connection key?' and press Replace key — the old key stops working instantly and bernard gives you a fresh setup prompt to paste back into your assistant. Any draft it was working on is safe and waiting.
- What if someone else gets hold of my key?
- Treat it like a password: whoever holds it can edit drafts of your sites and publish them. Replacing it in Account → Your AI kills the old one instantly — that's your kill switch. Nothing is unrecoverable either way: bernard keeps a full year of history, every publish is recorded with what changed and when, and any version of any page can be restored.
- Are there limits on what the AI can do with the key?
- Yes — fair-usage limits of 60 requests per minute and 1,000 writes per day. A long, productive editing session uses a small fraction of that; the caps exist to stop a malfunctioning agent looping, not to meter your enthusiasm.