-
-
Notifications
You must be signed in to change notification settings - Fork 3
AI Assistants
Kinboard has a built-in MCP endpoint at
/api/mcp. Claude, ChatGPT and other MCP clients connect to it and can then,
depending on what you allow, read the family's day and keep its lists:
calendar, tasks, shopping list, notes, meal plan and recipes, timers,
birthdays, countdowns and screen messages. They can also read the energy
sensors and the cars' charge level, ask to book pocket money, and control the
Home Assistant devices you have put in Kinboard's device catalogue.
Anything that opens the house (a lock, an alarm, a garage door, a scene or a script) and every pocket-money booking waits for a family member to allow it on a Kinboard screen with the settings PIN. Anyone at a screen can deny it.
Nothing is reachable until you switch it on, and each connection gets only the permissions you tick when you connect it.
| Page | What's in it |
|---|---|
| AI assistants (this page) | Overview, quick start, forgotten PIN |
| Connecting an assistant | ChatGPT, Claude (web, desktop, mobile), Claude Code, other MCP clients; the consent page step by step; the settings PIN; the switch |
| What assistants can do | Every tool, grouped by area, with the permission it needs and example requests in English and German |
| Permissions and safety | Every permission, the PIN confirmation on the screens, the limits, what is hidden, what is never possible, revoking |
| Troubleshooting | A new permission never gets asked for, 404s, the page never loads, sign-in expired, "slow down", energy figures, devices the assistant can't see |
| Self-hosting notes | For whoever runs the server: public HTTPS, reverse proxies, the address Kinboard advertises, upgrading, the Integration API |
You need a Kinboard that is reachable over HTTPS on a public hostname (through a reverse proxy, Cloudflare Tunnel or Tailscale Funnel). Claude and ChatGPT connect from their own servers on the internet, not from your network. Claude Code is the exception: it runs on your computer and can use a LAN address. See Self-hosting notes.
- Open Kinboard at its public address on a device joined to your family, go to Settings → Integration tokens (the page is headed Integrations) and switch on Allow AI assistants.
- Under AI assistants on the same page, copy the assistant address
(Copy the assistant address). It looks like
https://kinboard.example.com/api/mcp. - Add that address to your assistant as a custom connector. How, for each assistant: Connecting an assistant.
- A Kinboard page opens: Connect Claude to Kinboard. Untick anything the assistant should not be allowed to do, enter your Settings PIN and select Allow. If your family has no settings PIN yet, you set one here.
- Ask something. "What's on the calendar tomorrow?" or "Was steht morgen im Kalender?"
The connection now appears under Settings → Integration tokens with an Assistant label, its name and its permissions. Revoke there disconnects it.
You can connect more than one assistant, and more than one connection of the same assistant (Claude on the web and Claude Code, say). Each one is its own row, with its own permissions, revoked on its own.
- Assistants act through Kinboard, not around it. Every tool calls the same Integration API route Home Assistant uses, with the assistant's own token, so the permission checks, family scoping and limits are the same ones.
- Home control stops at your catalogue. An assistant sees and controls only the devices you added under Settings → Things in your house, and only a fixed set of actions per kind of device. There is no "run any Home Assistant service" tool. See Permissions and safety.
- Switching it off disconnects everyone. Turning Allow AI assistants off revokes every assistant connection the family has. Tokens you created by hand for Home Assistant keep working; the Integration API is not behind this switch.
The settings PIN protects the settings pages, connecting an assistant and
allowing an assistant's request on a screen. Kinboard checks it on the
server, so there is no way around it from a browser. If nobody remembers it,
remove it from the database on the machine running Kinboard (the container
is kinboard-db unless you changed PROJECT_NAME):
docker exec -i kinboard-db psql -U postgres -d postgres -c "DELETE FROM integration_secrets WHERE key = 'settings_pin';"
That removes the PIN for every family on this Kinboard. Open Settings and set a new one.
- Home Assistant: the Integration API tokens Home Assistant uses, and the device catalogue's background
- Security and threat model
- Pocket Money, Vehicles, Timers, Messages, Recycle bin
Kinboard on GitHub · Sponsor · Buy me a coffee · Report a bug · Free for noncommercial use
Getting started
Operations
Integrations
AI assistants
- Overview & quick start
- Connecting
- What they can do
- Permissions & safety
- Troubleshooting
- Self-hosting notes
Kiosk hardware
Built-in features
- Dashboard
- Calendar
- Shopping
- Recipes & meal planning
- Tasks & todos
- Notes
- Messages
- Timers
- Photos
- News
- Birthdays
- School schedule
- Smart home & energy
- Screensaver
- People & devices
- Recycle bin
- Notifications
- Themes
Plugins (per-family on/off)
Contributing