Pinloop

Connect an AI app to Pinloop

Last updated 22 September 2026.

Pinloop is a job search a person runs from an AI app. Pinloop holds job postings from employers all over the world, it stores the documents a person writes about themselves, and it has an AI read a posting against those documents and write down what it thinks. An AI app that a person already uses can be connected to their Pinloop account and then work with it on their behalf; the list further down this page says exactly what a connected app can do. This page is for whoever is setting that connection up.

The address an AI app talks to

Every connected app sends every request to one address: https://pinloop.ai/mcp. That address speaks the Model Context Protocol, which is the common language AI apps use to reach a service outside themselves. It answers nothing at all until a person has approved the app for their own Pinloop account.

How an app becomes known to Pinloop

An AI app registers itself the first time it connects. It sends Pinloop the name it wants a person to see and the address the person is returned to when they have finished, and Pinloop hands it back an identifier there and then. Some services give out an identifier and a secret in advance and ask a developer to fill them into a form. Pinloop gives out neither: there is no client id to enter and no secret to enter, and any form asking for them can be left empty. The standard name for registering this way is dynamic client registration.

Where the sign-in settings are published

Signing in runs on OAuth, which is the standard way one website lets a person sign in through another without handing over a password. An app reads how to do that from published settings that the standards call discovery documents, and Pinloop publishes them at the three addresses the standards name, at the root of the site:

  • /.well-known/oauth-authorization-server — the sign-in service: where an app registers itself, where the person’s browser is sent to approve it, and where the one-time code an approval ends with is traded for the pass the app then uses.
  • /.well-known/openid-configuration — the same settings under the older of the two names for them, for an app that looks for that name instead.
  • /.well-known/oauth-protected-resource — the description of the one address AI apps talk to, which names the sign-in service an app has to go through before that address will answer it.

Some apps write the path of the service after the well-known name, which gives /.well-known/oauth-authorization-server/connect, /.well-known/openid-configuration/connect and /.well-known/oauth-protected-resource/mcp. Each of those longer addresses answers exactly the same document as the short one above it, so either form works and an app can ask for whichever it prefers.

What the person is asked

An app that wants to connect sends the person’s browser to Pinloop’s own approval page. The person signs in there, with Google, with GitHub or with a code Pinloop emails them, and the page tells them which app is asking and asks them how much of their account it may reach. There are two answers, in these words: “Search and read only”, and “Search, read and make changes”. Whichever they choose, the app never sees their password and never sees their email sign-in. It is handed a pass of its own, which works for that one account and at that one address and nowhere else.

Ending a connection

Every AI app connected to an account is listed at pinloop.ai/account, with a Disconnect button beside each one. Disconnecting deletes the approval and every pass that was issued under it, so the app is refused on its very next request. Nothing has to be changed inside the app itself.

What a connected app can do

These are the actions an AI app may call once a person has approved it. Every one of them reads or writes that person’s own account and no other.

  • account_status — Answers with what this Pinloop account holds: the names of its stored documents, the routines it runs on a schedule and when each last ran, how much of its judging, meaning-based searching and job-posting allowances it has used and when each returns to zero, and whether it is on the free plan or the paid one.
  • search_postings — Searches every job posting Pinloop holds and answers with short cards: each posting’s id, job title, employer, locations, posted date, link, workplace type and employment type.
  • search_viewed_postings — Searches only the job postings this account has already been handed, with the same filters as search_postings, and answers with the same short cards.
  • read_posting — Answers with everything Pinloop stores about the named postings, including the job description, which no search card carries.
  • count_postings — Answers how many job postings match a set of filters, without handing any posting over and without counting anything against the posting allowance.
  • list_profile_documents — Answers with the name, kind, size and last write time of every document this account has stored, such as a resume or a written background.
  • read_profile_document — Answers with the text of one document this account has stored, chosen by the name field.
  • read_verdicts — Answers with the verdicts this account holds about job postings, newest first, each with the verdict, the reasoning behind it, who decided it and when.
  • list_tabs — Answers with every saved list this account has, in alphabetical order, each with what the person wrote about it, how many postings it holds and when it was last written to.
  • read_tab — Answers with the postings inside one saved list, chosen by the name field, as the same short cards a search answers with, a page at a time.
  • get_plan_page_link — Answers with one web address for the person to open in a browser: Pinloop’s payment page when this account is on the free plan, or the page for managing the subscription when it is on the paid plan.
  • how_to_use_pinloop — Answers with one short document about Pinloop: what each of its actions is for, what order they are usually worked in, how a page after the first one is read, what a search costs against the person’s allowance, and what Pinloop does not do.
  • save_profile_document — Stores one document in this account’s profile under the name in the name field, replacing whatever that name held before rather than adding to it.
  • delete_profile_document — Takes one document out of this account’s profile, chosen by the name field, and destroys the stored file behind it when that document held one.
  • collect_new_postings — Asks for job postings Pinloop does not hold yet, stores the ones that come back, and answers with the same short cards a search answers with, how many postings matched the conditions in all, and how much of this account’s posting allowance is left.
  • record_verdict — Stores this account’s own verdicts about job postings, as rows in the rows field: each row names the posting in id, the verdict in verdict as one of no, weak, fair or strong, and what it was based on in reasoning.
  • delete_verdict — Takes this account’s stored verdicts away for the postings named in the ids field.
  • create_tab — Makes a new saved list under the name in the name field, with what it is for in the description field.
  • add_to_tab — Puts postings into one of this account’s saved lists, chosen by the name field, with the posting ids in the ids field.
  • remove_from_tab — Takes postings out of one of this account’s saved lists, chosen by the name field, with the item ids in the item_ids field — the handles read_tab carries beside each posting in a list, rather than posting ids.
  • rename_tab — Gives one of this account’s saved lists another name: the list it has now in the name field, the name it gets in the to field.
  • delete_tab — Takes one of this account’s saved lists away, chosen by the name field, along with every posting in it, and answers with how many postings went with it.

How much an account may do is not written on this page. How many postings it may be handed, how many postings it may have judged, how many searches by meaning it may run: each of those is a figure held inside Pinloop that moves with the plan the person is on, and a figure copied onto a page stops being true the day it changes. The how_to_use_pinloop action answers with all of them, read out of Pinloop itself at the moment it is asked, along with what order the actions are usually worked in and what Pinloop does not do.

Apps that set a connection up by being told about it

Some AI apps, Meta’s Muse among them, do not show a form of fields. They ask the person to describe the connection in a sentence and then set it up themselves. This sentence works, word for word:

Create a custom connector named Pinloop. Its MCP server URL is https://pinloop.ai/mcp. It uses OAuth; register yourself with dynamic client registration, there is no client id to enter, and the discovery documents are at the standard well-known addresses on pinloop.ai.

Questions

Write to andrew@pinloop.ai.