What it means
An agent that cannot open a shell still needs a way in. Loam gives it one door: the MCP, the protocol Claude and other assistants speak. No home-grown API, no admin panel behind it — the same files underneath, with the rights, limits and history that a door needs.
How loam does it
- A key per actor. The agent presents a key; the site holds only its fingerprint. Rights are checked per verb and per kind of file.
- Nothing goes straight in. Every write lands in a holding area first, passes the check on what may exist in the site, and only then becomes a draft. Publishing runs the full check over the site as it would be.
- A small, honest vocabulary. Read a file, search a folder, create or update a draft, look at the difference, publish, take back. Destructive steps are deliberate: taking something back is never bulk.
- Answers an agent can act on. Every reply has the same envelope — did it work, a code from a closed set, what to do next. A refusal names the right that was missing.
- The manual through the same door. An agent reads how loam works, and this site's own rules, through the MCP — the docs that travel with the engine it is talking to.
- Everything on the record. Every change ends as a line in the journal: what was done, by which key, and what was asked, in the caller's words.
- Guessing is slow. Repeated failed attempts from one address are throttled.
What it costs
The trust is in the key, and in the account behind the agent that holds it: whoever can use your agent can use its key. Keep keys to the least rights that do the job, rotate them, and drop them the day someone leaves. And the MCP does only what it says: no shell, no fetching of web pages for you, no editing an image in place.