How it works

Point any AI agent at your brand.

One bearer token connects Claude, Cursor, or any MCP client to a bounded, read-only cut of your Brand DNA, so an agent stops guessing your voice and reads it. That connection is one half of Jinn Agents. The other half is a roster of 25 marketing agents across four divisions, plus a growing catalog of installable skills, all sharper the moment they run on your brand. This page walks the mechanism and the honest boundary drawn in code, what a public token can read and everything it structurally cannot, and then the roster that reads through it. The projection an agent reads is a curated view of the same verified brand record as every Jinn product: how the record works.

A stranger’s agent can hold a demo token and read the showcase brands today, no signup and no card. The owned-brand path, where you mint keys for your own brand, is wired and waiting on its launch gates.

At a glance
What connects

Any MCP client. One bearer token is all an agent needs to reach your brand context, so Claude, Cursor, or your own tooling can read the same record instead of each hallucinating its own version of your brand.

What a demo token reads

A curated projection of your record: your identity, your voice rules including the words you never use, and your positioning. Five read-only tools, no more.

What it can never reach

Your competitive intelligence, your pricing, and your product internals are excluded from the public projection by omission, and tests assert they stay out. A self-serve token cannot see them at all.

What you can try today

The demo. A single request mints a token scoped to three showcase brands, with no account, that expires in sixty minutes. Real, unauthenticated, and live right now.

The connection

Token in, bounded brand context out.

Four steps, and the boundary is enforced on the server every time, not trusted to whatever a client sends. The demo path below is real and unauthenticated today.

  1. RequestA single request mints a bearer token. For the demo there's no signup and no card: the token is scoped to three showcase brands and expires in sixty minutes. This path is live today.
  2. IntrospectBefore it reads anything, an agent calls one tool to see its own permissions: which brands it may read and at what access. The agent learns its own limits from the token, rather than probing to find them.
  3. ReadIt reads the bounded public projection: the brand’s identity, voice rules, and positioning, plus the design system as markup and as tokens. Five read-only tools on the demo path, and nothing that writes.
  4. Stay boundedA brand outside the token’s allowlist reads back identical to a brand that doesn't exist, so a token cannot fish for what it wasn't granted. Escalation is impossible by construction, not by policy.

Every self-serve token is pinned to public audience and read-only scopes on the server, whatever a route forwards. There is no scope parameter for a client to forge.

The surface

Five tools, all read-only.

A demo token can call exactly these, and each one only reads. There is nothing here that changes your record or spends anything.

  • Check the connectionA ping tool confirms the agent is connected and the token is valid before it tries to read anything real.
  • Read its own permissionsA context tool tells the agent which brands the token may read and at what access, so it operates inside its limits by design.
  • Read the design systemTwo tools return your design system: one as agent-readable markup, one as raw design tokens, so a coding agent can build on-brand without a human pasting a style guide.
  • Read the public brand cutOne tool returns the bounded brand projection: identity, voice rules including banned words, and positioning. It is a curated view of the record, never the whole thing.

From the Connected rung up, a sixth tool joins the surface: ask_brand takes a natural-language question about your brand and answers with the canonical facts that bear on it, naming what your record cannot answer so an agent says so instead of guessing. Still read-only, and still only brands on the token allowlist.

The boundary

Bounded on purpose, and asserted by tests.

The interesting part of a public brand surface is what it refuses to expose. Here the refusal is structural.

A curated cut, not the recordThe public projection is an explicit allowlist of nineteen fields: identity, voice, positioning. Everything else is excluded simply by not being on the list, and a field rename upstream is a compile error rather than a silent leak.
The valuable parts are omittedCompetitive intelligence, pricing, and product internals don't appear in the projection, and tests assert their absence. They're not hidden behind a flag; they're simply not in the public cut.
Escalation is impossible by constructionEvery self-serve token is pinned to public audience and read-only scopes on the server, regardless of what a client or route forwards. There is no scope parameter to forge, so a token can never widen its own reach.
An ungranted brand looks like nothingReading a brand outside the token’s allowlist returns exactly what a nonexistent brand returns, so a token cannot even confirm which brands it wasn't given.
Honest edges

What a paid token adds, and what it doesn't.

At the Connected rung, bringing your own brand buys scope and permanence: a token pointed at your own record instead of the showcase brands, with no sixty-minute expiry. The mint panel for those keys is real, wired behind ownership and entitlement, and it's the next thing to go live rather than a demo you can run today.

Above Connected there is a real paid rung, enforced in code: Brand and Agency tokens also read the full Brand DNA record, the render-ready brand kit, and the product catalog, and a lower-tier token calling one of those gets a clear tier-required error carrying the upgrade path, never a silent failure. The finished deliverables and the deeper operator tools sit past every self-serve tier: internal-audience, minted by an operator, reachable by no token you can buy.

The roster

The other half: agents and skills that sharpen on your brand.

The gateway is one half of Jinn Agents. The other half is the work itself: a roster of 25 marketing agents across four divisions, and a growing catalog of installable skills. They're not extra tools bolted onto your token. They're agents and skills you run inside your own client, and they get sharper the moment they read your brand: point one at your brand over this same MCP connection and it works from your verified facts instead of the average of everyone else.

  • Marketing (7)Brand and go-to-market strategy, positioning, lifecycle, campaigns, audience insight, and launch. The agents that decide where the brand plays and how a launch is sequenced.
  • Brand (6)Guardian, voice steward, naming, architecture, rebrand, and storytelling. The agents that hold the brand’s register and keep every asset on-strategy.
  • Content (6)Strategy, copy, editing, social, email, and SEO. The agents that turn the plan into words that sound like you.
  • Design (6)Art direction, brand and systems design, packaging, web, and motion. The agents that carry the look across every surface.

An agent that reads your brand argues from your brand. A skill sharpens because it reads your record through the same bounded, read-only connection this page describes. The gateway surface stays read-only end to end, and the skills are yours to install.

Honest machinery

Bounded by construction, not by trust.

A demo needs no accountThe demo path is real and unauthenticated today: a request mints a short-lived token against three showcase brands, no signup and no card. You can point an agent at it right now.
Public means projection-onlyA public token can only read, and only the curated projection. It cannot write your record, cannot spend, and cannot reach the gated parts of your brand.
A token cannot widen itselfAudience and scopes are pinned server-side on every mint, with no client-supplied scope to forge, so a token’s reach is fixed the moment it is created.
The record underneathThe projection is a curated view of the same verified brand record that powers every Jinn product: 346 signals structured from your own site and evidence, of which only the public cut is exposed. Agents read the record. They don't invent one.
The substrate

Agents sit on the record.

The brand record an agent reads a curated cut of is shared substrate, documented once and linked here rather than re-explained on every product page. The terms this page leans on are defined in the dictionary.

Questions

The questions people ask.

Can a stranger really read my brand?
The demo reads showcase brands, not yours. Anyone can mint a sixty-minute demo token, with no account, scoped to three showcase brands, and point an agent at it. Your own brand is only ever readable through a token you own.
What can a token never see?
The public projection is a curated cut of your record: identity, voice, and positioning. Demo and Connected tokens cannot reach your competitive intelligence, pricing, or product internals — they are excluded by omission and tests assert they stay out. Your own Brand-tier or Agency token can read your full record; nobody else’s token ever can.
Do higher tiers add more tools?
Yes, from the Connected tier up. Connected buys scope and permanence, a token pointed at your own brand with no sixty-minute expiry, and adds ask_brand, which answers questions from your brand's canonical facts. Brand and Agency tokens also read the full Brand DNA record, the render-ready brand kit, and the product catalog. The wall is enforced on every call: a lower-tier token hitting a gated tool gets a clear tier-required error with the upgrade path, never a silent failure.
Can an agent get to my full Brand DNA or my deliverables?
Your full Brand DNA is readable only by your own Brand-tier or Agency token — never by a demo token, and never by anyone else’s. Deliverables and the deeper internal tools stay operator-only and are not reachable by any self-serve token.
Can I mint keys for my own brand yet?
The owner mint panel is built and wired behind ownership and entitlement, and it is finishing its launch gates. Until then, request early access and try the mechanism with the live demo token.

Give your agents the real brand, not a guess.

One token, a curated cut of your record, read-only tools, and a boundary enforced in code. Try it with a demo, then bring your own brand.