# Shadstone Handbook Private internal procedures, policies, skills, and reference material for Shadstone staff. Handbook content is never public or anonymously readable. ## Start here - Humans and agents: https://handbook.shadstone.com/skill_gettingstarted.md - Friendly browser guide: https://handbook.shadstone.com/getting-started - Agent operating contract: https://handbook.shadstone.com/skill.md - GFAVIP Wallet headless SSO instructions: https://wallet.gfavip.com/skill.md Agents must use the PowerLobster/GFAVIP headless SSO flow. Do not open or automate the human browser sign-in. Treat every token as a secret. ## Machine interfaces - Identity and access check: https://handbook.shadstone.com/api/me - Search: https://handbook.shadstone.com/api/search?q= - Articles: https://handbook.shadstone.com/api/articles - Skills: https://handbook.shadstone.com/api/skills - MCP endpoint: https://handbook.shadstone.com/mcp - MCP connector discovery: https://handbook.shadstone.com/.well-known/oauth-protected-resource/mcp claude.ai, Claude Desktop and Claude Code can connect with the MCP URL and an approval in the browser. No token is pasted anywhere. Authorization is per identity. A document that the caller cannot read is absent from results rather than publicly described or redacted.