Skip to content

v1.4 Changelog ​

Released: October 2026

The "AI assistants" release: Claude, ChatGPT and other AI assistants can now work with your EOS data through EOS Hub's MCP server, always with your own rights and only where your organization allows it.

Highlights ​

  • New MCP server at /mcp: ask an AI assistant about your to-dos, Scorecard, Rocks and meetings, or let it add and update them
  • One-click connection from claude.ai, Claude Desktop and ChatGPT: sign in to EOS Hub (Google or password) and approve the access
  • Organizations opt in: AI assistants are off until an Owner or Admin allows them
  • Connected apps in Settings, with a disconnect button
  • Error messages of the REST API now say what was wrong

Features ​

AI Assistants (MCP) ​

  • 31 tools for the work of the week: to-dos, issues, Rocks and milestones, Scorecard values, meeting headlines, cascading messages and ratings, plus reading the V/TO, Accountability Chart, People Analyzer and documents. Platform operators get two more for reading organizations and users.
  • Read only or Read and change access, chosen on the consent screen. An assistant never gets more than the user's current roles.
  • A ready-made Prepare a Level 10 meeting prompt drafts the agenda from the Scorecard, Rocks, overdue to-dos and open issues.
  • Tools for scripts and other tools can use an API key on /mcp instead of signing in.

See AI Assistants (MCP).

Switches ​

  • Organization settings > General > Allow AI assistants (MCP): off by default, for new and existing organizations. While it is off, assistants don't see the organization.
  • Platform > MCP: the platform operator can switch MCP off for everyone and sees how many organizations allow it, the active connections and the registered apps.

Connections ​

  • Settings > AI assistants (MCP) shows the server URL, short instructions for Claude, ChatGPT and Claude Code, the organizations where assistants are still off, and the Connected apps with their access and last use.
  • Platform > Users shows each account's connection count; the operator can disconnect a connection.

Security ​

  • OAuth 2.1 with PKCE and dynamic client registration; access tokens are valid for one hour, refresh tokens for 30 days and are replaced on every renewal.
  • A reused authorization code or refresh token ends the connection.
  • MCP tokens work only on /mcp, never on the REST API; only their hashes are stored.

Improvements ​

  • REST API errors 422 invalid now explain the reason, for example "The owner must be a member of the team" or the invalid field.
  • The login page returns to the page you came from (for example the consent screen) after signing in.

Upgrade Notes ​

  • Two database migrations run automatically on start: the MCP switches and the OAuth tables.
  • MCP is off in every organization after the upgrade; Owners and Admins switch it on in the organization settings.

Built with VitePress