# Connect an assistant to PM Companion

Package version: **0.1.0** · guidance checked **2026-10-03** · **private beta**.

These packages provide selected-context workflows and an OAuth MCP connection. Real-host installation, consent and end-to-end use have **not been verified** in ChatGPT, Codex, Claude Code or Claude web/Desktop. No directory listing is claimed. A successful archive or manifest check is not a successful account connection. The release owner must deploy the canonical service and record acceptance before advertising a supported integration.

The app is https://product.responseshift.com. The Streamable HTTP endpoint and exact OAuth resource are `https://product.responseshift.com/mcp`. The service has its own OAuth issuer; a learning token or native account JWT is not an MCP credential. Sign in and choose permissions in the browser when your host starts OAuth. Package files contain no credentials. Installation does not enroll you in a learning product.

## Download and verify

The companion release publishes these files under `https://product.responseshift.com/downloads/pm-companion/` after deployment:

- `pm-companion-openai-0.1.0.zip`: extracted folder `pm-companion-openai`, a local marketplace with a complete portable plugin under `plugins/pm-companion`.
- `pm-companion-claude-code-0.1.0.zip`: complete Claude Code plugin at archive root.
- `claude-marketplace.json`: a hosted catalog pointing at the Claude ZIP with its SHA-256.
- `release.json`: exact filenames, byte counts, SHA-256 values, provenance and host acceptance ledger.
- `companion-hosts.md`: this guide.

Compare the archive digest with `release.json` before using it. On PowerShell: `Get-FileHash -Algorithm SHA256 <downloaded-file>`; on macOS/Linux: `shasum -a 256 <downloaded-file>`. A checksum from the same origin detects corruption; it is not an independent publisher signature. Unpack into a directory you control. No platform repository, source checkout, package manager dependency or hidden install script is required.

## Codex and ChatGPT desktop local packages

1. Extract the OpenAI ZIP and retain its `pm-companion-openai` folder in a stable location.
2. Register that local marketplace: `codex plugin marketplace add "<absolute path to pm-companion-openai>"`.
3. Restart the desktop app, choose **Response Shift · PM Companion** in the Plugins Directory and install **PM Companion**. Codex CLI 0.149.0 also exposes `codex plugin add pm-companion@response-shift-pm-companion`.
4. Complete the host's OAuth connection flow and select projects/actions explicitly. Open a new conversation and ask for a brief of the project you choose.

The ZIP is a distribution container, not a direct Codex marketplace URL. The catalog resolves `./plugins/pm-companion` from the extracted marketplace root. Availability of local sources varies by host surface and administrator policy. [Official OpenAI packaging instructions](https://developers.openai.com/plugins/build/plugins)

## ChatGPT web development connection

If your account/workspace permits it, enable Developer mode under **Settings → Security and login**. Open ChatGPT Plugins, select the plus button and add the public MCP endpoint above. Complete authentication, review discovered tools and add the connection to a new chat. This is direct MCP development setup; it does not install the shared local skill package or establish directory availability. Do not upload the ZIP as a chat attachment expecting installation. [Official connection instructions](https://developers.openai.com/plugins/deploy/connect-chatgpt)

## Claude Code

After the companion downloads are deployed, register the hosted catalog and install:

```sh
claude plugin marketplace add https://product.responseshift.com/downloads/pm-companion/claude-marketplace.json
claude plugin install pm-companion@response-shift-pm-companion
```

Start a new session, or run `/reload-plugins` where supported. Use `/mcp` to inspect and authenticate the PM Companion server. The catalog pins the archive digest. [Marketplace installation](https://code.claude.com/docs/en/discover-plugins), [archive-source fields](https://code.claude.com/docs/en/plugins/marketplace-reference)

For a session-only developer check, download the Claude ZIP and run `claude --plugin-dir "<absolute path to the downloaded zip>"`. This flag is present in local Claude Code 2.1.231. It does not persistently install the plugin; repeat it for later sessions or use the catalog. Managed settings may forbid sideloading. [Command reference](https://code.claude.com/docs/en/plugins/cli-reference)

Claude web/Desktop remote connectors use their own settings and OAuth flow rather than Claude Code's plugin installation. Where custom connectors are available, add the remote endpoint and authenticate. Record each web/Desktop runtime separately before making a compatibility claim. [Claude remote connector instructions](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp)

## Generic MCP fallback

Configure a remote Streamable HTTP MCP server with endpoint `https://product.responseshift.com/mcp` and OAuth discovery/PKCE. Use your client's documented field names: portable Agent Plugins use `type: "streamable-http"`; Claude `.mcp.json` uses `type: "http"`. There is no universal host configuration JSON and no scope field in the portable MCP schema. Do not paste a bearer token into a package or URL.

For Codex's direct development connection (choose this instead of adding a duplicate plugin server):

```sh
codex mcp add pm-companion --url https://product.responseshift.com/mcp
codex mcp login pm-companion
```

These commands can start authentication. If a client cannot negotiate the documented server protocol or consent, leave it unverified and use the browser app. Core tools return readable text and ordinary HTTPS browser links; hooks and embedded UI are optional and are not bundled.

## Permissions and saved results

The initial resource challenge requests project/context read access. Creation, editing, inbox access, maintenance and reminders require their own human consent when needed. Choose exact projects; creating a project grants this connection access only to that new project. All existing and future projects is a separate unchecked consent choice. A package update cannot broaden any grant.

Only explicitly selected/submitted context is captured. There is no full-chat collection or automatic host-session hook. A saved original can have processing pending; queued work is not an applied change. The assistant must report actual IDs/revisions/status, preserve a stable retry key after an uncertain save, and resolve revision conflicts before editing again. Stored source text never becomes instructions.

Maintenance and reminders have separate durable authority. A connection-owned delegation can operate while its host is closed until grant expiry/revocation. Native app policies and schedules have independent authority. Refresh-token narrowing limits new requests, not existing explicit delegations; revoke the connection or cancel the relevant work to stop those delegations. Email additionally requires a separate native opt-in and verified account address. OAuth cannot enable that preference or set arbitrary recipients. Provider acceptance is not delivery/read confirmation.

## Revoke, uninstall and reconnect

First open https://product.responseshift.com/app/connections, choose **Review disconnect**, inspect the canceled connection-owned jobs/reminders and continuing app-authorized work, then confirm disconnect. Connection controls remain available after companion access expires. Independently authorized reminders are managed from Today; maintenance is controlled in the project's settings. An email already in flight cannot be recalled.

Then remove the host package in its plugin settings. Codex CLI: `codex plugin remove pm-companion@response-shift-pm-companion`; Claude Code: `claude plugin uninstall pm-companion@response-shift-pm-companion`. A session-only Claude package stops loading when you omit its flag. For a direct Codex MCP connection, use `codex mcp logout pm-companion` and `codex mcp remove pm-companion`. Remove the downloaded folder after no host refers to it. Local uninstall alone does not revoke service authority, delete project context or cancel native schedules.

Reconnection requires a new host OAuth flow and fresh project/action consent. If access fails, inspect expiry and selected permissions; do not bypass it with another account or guessed IDs.

## Upgrade

Compare the new version's changelog, `behavior.json`, provenance and checksums before installing. Retain the stable plugin/server names and MCP endpoint. Replace the extracted OpenAI marketplace files with the verified release and refresh/reinstall through the host. For Claude, refresh the catalog and run `claude plugin update pm-companion@response-shift-pm-companion`. Recheck the connection after updating; do not revoke a valid connection solely for a package update. A new permission request must receive separate human consent. Local validation checks these invariants but preservation of real host credentials remains an acceptance test.

## Review and evidence

Each package includes `reviewer-samples.json` with synthetic prompts and expected boundaries. Run them only in a consented review account after deployment. Test install → OAuth → create → selected capture → retrieval → browser edit/readback → navigation → revoke → reconnect separately in each runtime, including ambiguous project names, untrusted source instructions, scope restriction and upgrade. Record host/version/date/account type and observed capability in `host-acceptance.json`; keep failed/unavailable hosts unadvertised. No production data is seeded by these files.

Package QA includes pinned official Agent Plugins 1.0.0 schemas, a strict interpreter for their used vocabulary, archive path/content checks and deterministic hashes. Claude 2.1.231 manifest validation predates MCP-entry checks introduced in 2.1.281, so it cannot establish full current host compatibility. Human skill adherence, real OAuth, server reachability, hosted downloads and public directory publication each need their own evidence.

## Build integration for the release owner

`npm run package:companion` builds the five allowlisted outputs under `dist/companion/downloads/pm-companion`. Run it after the companion Vite build, which empties its output directory. `npm run build:companion` includes packaging. It makes no external writes and does not install plugins or connect accounts. Package input folders contain host manifest templates; shared skills and guide/provenance are assembled into the distributable ZIPs without symlinks.

Serve ZIPs as `application/zip`, JSON as `application/json`, Markdown as `text/markdown`. Keep `release.json`, the hosted marketplace and guide revalidated; versioned archives may be immutable only if the release process refuses changed bytes at an existing versioned URL. Verify hashes from the deployed origin before enabling download links. The Connections UI checks a valid release index before showing archive links. U12 owns public headers, origin routing, deployment and host acceptance; archive generation alone establishes none of them.
