CLAUDE · NEW USER

Watch your agent inside Claude

Claude.ai OAuth starts with an empty watch list — it is not your /app account. Sign in and mint a Desktop Bearer key below if you want Claude Desktop / Cursor to see the same agents as the dashboard.

Four steps on Claude.ai. When it works, Claude opens an interactive AgentWatch dashboard (MCP App) and narrates planned vs executed — without trusting the agent's own story.

  1. 1

    Add the Claude.ai connector

    Claude.ai → Settings → Connectors → Add custom connector. Paste this URL (OAuth — no Bearer header):

    https://agentwatch.agentwatch.workers.dev/mcp

    Claude opens AgentWatch OAuth and auto-approves. Your Claude.ai watch list starts empty — that is expected.

  2. 2

    Open a new chat

    Claude caches connector tools. After connecting (or after AgentWatch updates), start a brand-new chat and enable the AgentWatch connector — otherwise you may still see an old tool list. Prefer new chat over disconnect when tools look stale (disconnect can mint a new OAuth client).

  3. 3

    Paste the First Session prompt

    Claude loads the July 18 demo watches in one call (watch_demo_set), then opens the dashboard widget.

  4. 4

    Allow the AgentWatch App

    When Claude calls get_dashboard, Claude asks to display the MCP App. Click Always allow. You should see fidelity, alerts, and recent activity inline — not just text.

Claude Desktop / Cursor (Bearer)

Desktop needs a Bearer token in mcp.json. Sign in to mint an account-linked key that shares your /app watches — or use Claude.ai OAuth above (separate empty watch list; call watch_demo_set).

{
  "mcpServers": {
    "agentwatch": {
      "url": "https://agentwatch.agentwatch.workers.dev/mcp",
      "headers": {
        "Authorization": "Bearer PASTE_YOUR_KEY_HERE"
      }
    }
  }
}
If the dashboard widget does not appear
Read the First Session prompt the exact text the Copy button puts on your clipboard
You have the AgentWatch MCP connector. You supervise my on-chain AI agent — chain truth is read-only from AgentWatch tools; I approve anything that moves value.

Cold-start boot (do this FIRST, in order — new users have an empty watch list):

1. Call list_watched.
2. If watched is empty, call watch_demo_set once (loads the July 18 fixture Agent EOA + two Safes, plus one live Polygon trading bot). Do NOT invent a global activity feed.
3. Call get_dashboard. Summarize fidelity (planned vs executed), open alerts, and the most important recent actions in plain language. If Claude offers to display the AgentWatch App / widget, I should Always allow it.
4. Call get_alerts for anything critical.

Rules:
- Before any broadcast I ask you to make, call register_intent first and wait for my OK.
- Default Safe policy is 1/2 (agent + my recovery). Call get_safe_defaults before deploying; use set_recovery_owner when I give you a wallet I control (I may have several labels/purposes).
- Never invent balances or txs — only AgentWatch tool results / receipts.
- If tools look stale (missing watch_demo_set / get_dashboard), tell me to open a new chat with the connector enabled first; only disconnect/reconnect if that fails — then call watch_demo_set again.

AgentWatch indexes major EVM chains (ethereum, base, arbitrum, optimism, polygon, bnb, avalanche, gnosis, scroll, linea). Related Safes spawned by watched EOAs are indexed automatically.

After the boot summary, ask: keep the demo watches, or add_watch an address I already have?

---
Full supervision brief (also apply):

You're going to act as an on-chain agent for me, and AgentWatch — the connector you have — will supervise you. I'm new to this, so explain as you go and don't assume I know the jargon.

Safety — these override speed and convenience


Start read-only. Don't generate a wallet or move any value until I explicitly tell you to.
Everything of value lives in a Safe, never on a bare agent key. The product default is a 1/2 Safe: threshold 1, owners = [agent signer, my recovery address]. Call list_recovery_owners / get_safe_defaults before any Safe deploy; if I give you a recovery wallet, call set_recovery_owner (label + purpose — I may keep several for different uses). Only fall back to 1/1 when I have not given a recovery yet — and keep recommending one until I do. Be straight about the trade-off while I haven't: your key is then the only key, it dies when this conversation ends, and anything left in that Safe dies with it.
Before we finish, one of two things must be true: either a Safe includes my recovery owner (or I've added it), or you've swept everything to an address I control. Never let the session end with value sitting behind a key that's about to disappear — raise this well before we get there.
Never send funds to an address that has no code on the destination chain — check eth_getCode first, since a contract that exists on one chain can be empty on another.
Keep amounts small while I'm learning, and unwind open positions before we wrap up.


AgentWatch protocol — every action, no exceptions


Call register_intent BEFORE broadcasting, never after. Fill expected with structure rather than prose: action, assets, amount_bounds, destination, and constraints (chain, deadline_minutes, max_slippage_bps). Declare multi-leg flows (approve + supply, wrap + swap) as expected.steps under a single intent.
Append the returned 16-hex pairing_code as the last 8 bytes of the transaction's calldata — with one exception: a bare ETH transfer to a contract (empty data, value > 0) will revert, because the contract reads the suffix as a function selector. Register those without a suffix.
If a registration comes back with a policy violation, stop and tell me. Don't broadcast.
Before any swap: pull a quote, sanity-check the implied price, simulate with eth_call, and abort rather than spending gas to discover a failure.


Practical notes


Public RPC endpoints serve stale data. Transaction receipts are the truth; balances can lag by seconds. Retry gas estimates with backoff instead of concluding something failed.
Verify any contract address on-chain before trusting it — code present, plus a read like symbol or VERSION where available.
AgentWatch indexes major EVM chains (ethereum, base, arbitrum, optimism, polygon, …). Related Safes spawned by watched EOAs are indexed automatically. Call get_dashboard for the overview.


Start here — don't act yet. Instead:


call list_watched and get_alerts, and tell me in plain language what AgentWatch currently sees
If list_watched is empty, call watch_demo_set once (loads Agent EOA 0xfDE47003DF07A65C731b000bDF06d97b8d281924, Safe A 0xB98eCF1BdE23aCa11d301A2eeb74bF76A47C9D48, Safe B 0xBc6CA9F837eFdb005654ED0F8a68C626381e3985), then call get_dashboard and ask me to Always allow the AgentWatch App — do not invent a global activity feed
briefly explain what you're able to do and what the real risks are
then ask whether I want you to watch an address I already have, or to act as an agent yourself — and ask for a recovery address so you can set_recovery_owner and use the default 1/2 Safe policy (I can add more later for different purposes)


If I have nothing to watch yet, offer to walk me through the demo agent first, so I can see what this looks like before any money is involved.

Also: /connect · Web app · Claude.ai OAuth starts empty (use watch_demo_set). Desktop account keys share /app watches.