All articles

API and AI Access: Decide Who Can Connect AI to Your Puree Account

By Andrew Hemphill · 3 October 2026

You can now connect Claude, ChatGPT, Grok or Gemini to your Puree account in under a minute, with no keys to copy and paste. Add Puree to your AI app as a connector, click Sign in to Puree, sign in, choose what to share and click Allow. That’s it: ask your assistant which quotes are expiring this fortnight, and it answers from your real data.

Behind that sits a single place, API and AI access, where the account owner decides exactly who can connect what, and can see everything that’s been done.

Why We Built It This Way

An assistant connected to your account can read your customers, orders, menu and staff rates and, if you allow it, change your items and packages. AI is clever but not perfect: it can misunderstand an instruction or act on something wrong. For a catering business that has real customers and real prices, you want three things:

  • Control. You choose who can connect, and what each person can share.
  • Visibility. You can see which apps are connected, what they did, and by whom.
  • Safety. Sensible checks, like two-factor authentication, sit in front of all of it.

Signing in, rather than pasting a key, helps with all three. There’s no long-lived password sitting in a chat window or a shared document, each connection gets only what you tick, and it shows up in Puree where you can switch it off.

Connecting an AI App With Sign in to Puree

  1. Add Puree as a connector in your AI app, using the address https://mcp.puree.app/mcp.
  2. Click Sign in to Puree on the page that opens, after checking it names the app you’re using.
  3. Sign in to Puree if you haven’t in the last 15 minutes, and enter a code from your authenticator app, unless you entered one in the last 5 minutes (when you’ve just signed in, for example).
  4. Choose the account and what to share. Every area the app asks for, reading and changing, is ticked; untick anything you’d rather keep back. Anything the owner hasn’t given you shows as not shared.
  5. Click Allow. You’re back in your AI app, connected.

A connection can do only what you ticked, and only within what the owner gave you: if you have write access to items and packages and leave those ticked, it can change them. It lasts up to 90 days, or until it goes 60 days unused, and then you simply sign in again. Our Connecting with an AI Agent page walks through every step.

What the Owner Does

Only the account owner controls who may connect. Admins don’t get access automatically. Here’s how to set it up.

  1. Open the page. Go to Settings → API and AI access. If you don’t see it, email email@puree.app and we’ll switch it on for your account.
  2. Accept the terms. Read the short risk acknowledgement and accept it. It covers things like connected tools acting on your behalf, AI making mistakes and Puree not being responsible for external AI systems. You’ll need 2FA and to enter a fresh code. A copy is emailed to you and to Puree.

    The API and AI access terms with the acceptance checkbox and the Accept and enable button

  3. Choose who gets access. You’ll see a grid of your people and five areas: Orders, Customers, Items and categories, Packages and Staff roles and rates. Tick Read (look only) or Write (make changes) for each person. Write is available for items and categories and packages. Start with read-only and add write only where it’s needed.

    The access grid: one row per person, with Read and Write boxes for orders, customers, items and categories, packages, and staff roles and rates

  4. People connect their apps. Each person with access can sign in to Puree from their AI app and share any of the access you’ve given them. The owner can connect too, and holds every area automatically.
  5. Review whenever you like. Narrow someone’s access and any connected app using what you took away is disconnected straight away. Their access tokens are narrowed, or revoked if nothing is left.

If the wording of the terms ever changes, nobody can connect a new app until you accept the new version. Apps and tokens already in use keep working for 30 days while you read it; after that, they’re paused (not disconnected) until you accept, and then work again straight away. The same goes if API and AI access is switched off for your account: connected apps and tokens pause, and resume when it’s switched back on.

See What’s Connected: Connected Apps

The Access tab lists every app connected to the account under Connected apps: the app and the address it connected from, who connected it, what it can do, when it was connected, when it was last used, when it ends, and whether it’s active or paused.

  • Disconnect stops an app straight away. People can disconnect their own apps; the owner can disconnect anyone’s.
  • Owners see every connected app. Everyone else sees their own.
  • Your connections on every account, at the bottom of the list, shows everything you’ve connected across all your Puree accounts, so you can still disconnect an app on an account you’ve since left.

Some things disconnect an app automatically: the owner removing the access it uses, removing the person from the account, a password change or reset, or the person’s login being deactivated.

See Everything: The Activity Log

The Activity log tab lists every action taken through a connected app or an access token, in plain English. For example: “Looked up kitchen sections (6 found)”, or “Changed the item Crispy pork belly: moved from position 24 to 16”. Each row shows the person, which connection, what was done and whether it worked.

  • Search and filter by person, connection, type and date range.
  • Click a row for the full details.
  • Owners see everyone’s activity. Everyone else sees their own.
  • Entries are kept for 13 months, and tokens and other secrets are never shown.

Two-Factor Authentication

2FA is required to give people access, to accept the terms, to connect an app and to create a token. Connecting an app asks for a code unless you entered one in the last 5 minutes. If someone turns 2FA off, their connected apps and tokens are paused, not deleted, and start working again as soon as they turn it back on. Turning 2FA off needs a current code, and too many wrong codes causes a short lockout. See Two-Factor Authentication to set it up.

Access Tokens: For Scripts and Zapier

Sign in to Puree is the easy way to connect an AI app, but access tokens are still here for everything else. A token is a long password a person creates on the same page, within what the owner has given them, and pastes into a script, a Zapier step or a custom GPT, or into an AI app that can’t sign in yet. The token is shown once, and you can edit or revoke any token yourself. The Developer API has the technical detail.

What About Existing Tokens?

If you already had access tokens, they keep working while you review things, but only for people with 2FA turned on. Open the page, accept the terms, set each person’s access and revoke anything you don’t recognise. If you’d connected an AI assistant by pasting a token into the Puree connector, that keeps working too, and you can switch to Sign in to Puree whenever suits you.

Switching It On

API and AI access is switched on account by account. Email email@puree.app and we’ll enable it. If you’d like a hand choosing the right permissions or connecting an assistant, just ask and we’ll help.