---
name: werealm-ai-guide
description: Connect an AI assistant to the intended WeRealm environment as a creator or platform operator, verify access, and hand off to the live role-specific Skill.
---

# WeRealm AI Access Guide

Use this public guide for both creator and platform-operator access. It owns connection setup
and verification; the authorized role's Task Contract and specialist Skills own execution.
Resolve this guide's relative resource links under `/ai-guide/` on the same service.

## Select the Intended Connection

1. Use the environment and role already supplied by the user. Creator work concerns the user's
   products and AI characters; operator work concerns authorized platform administration.
   Ask only when the intended role or environment is unclear. Available tools alone do not
   authorize a different role, environment, or action.
2. Read `/ai/connection` on this guide's service Origin. Require WeRealm identity, Streamable HTTP,
   OAuth, and Authorization-header credential placement. Choose its exact `mcpUrl` for creator
   work or `operatorMcpUrl` for operator work. Metadata describes connection capabilities;
   it does not grant access or prove that this session can use tools.
3. Require HTTPS except for explicit loopback development. Reject user info, queries, and
   fragments. Never guess another endpoint or substitute an operator connection for creator work.
   Before reusing loaded tools, match their native client's public server URL to the selected
   endpoint. A matching tool name alone does not identify the intended environment.

## Connect and Verify

1. Check for `start_creator_task` and `read_creator_skill` on the selected creator connection,
   or `start_operator_task` and `read_operator_skill` on the selected operator connection.
   If tools are absent or authorization fails, follow [client setup](references/client-setup.md).
2. Use metadata's `creatorVerificationTool` or `operatorVerificationTool` for the selected role
   and call it with empty input. Confirm access only after
   this call succeeds. Saved configuration, browser consent, and previous access are separate
   evidence and do not verify this session. Verification does not execute a business operation.
3. Read the exact role entry using the returned `entrySkillId`, `entrySkillContentSha256`, and
   that role's Skill-reading tool. Reuse the successful bootstrap response; do not repeat setup.
4. Follow that entry and the live Task Contract. Preserve the user's known goal and authorization.
   Use only tools granted to this connection and treat `tools/list` as live schema authority.
   Operator Skills remain protected and are never read through public Creator resource paths.

## Human Handoff

The user personally signs in and approves access. Never request or read credentials or approve
consent for them. Explain a blocker and one necessary next action in their language. Respect
client restrictions and platform permission decisions. When the goal is already clear, continue
after verification without asking the user to restate it. When no goal was supplied, briefly
describe the outcomes returned by the role's live task menu and ask what they want to do.
