What actually happens when you connect Basin.
Any AI tool that speaks MCP points at the same address. What it finds is a folder of markdown files and a permission system around them, and once you've handed someone a space, their assistants are working from the same files you are.
One endpoint, added to each tool you use
Basin is an MCP server. Any assistant that speaks MCP points at the same address: Claude, ChatGPT, Gemini, Cursor, Claude Code. You approve each connection inside that tool, with your own account.
Client access differs. On ChatGPT you add Basin yourself on a personal plan; on Business, Enterprise and Edu an admin publishes it for the workspace first. Gemini custom apps need Spark access, a personal Google account in the US, English, age 18 or over and Keep Activity on.
The address never changes and never carries a version number. Incompatible protocol changes are served at the same URL, so old connections keep working.
Your context is markdown, in folders, that you can read
A space is a folder. A file is markdown with a frontmatter block on top. There’s no proprietary format.
Four keys in that block are written by Basin and overwrite anything a client puts there. An assistant can title a file whatever it likes. It can’t claim a different author or a different time.
Sharing hands over a space, and their assistants get it too
A grant covers a whole space, so what you hand over is something you can picture. Per-file sharing sounds more careful and produces a permission set nobody can hold in their head.
A grant is read, or read and write, with an expiry if you want one. Whoever accepts gets a single-use code by email.
What happens on their end. They sign in and connect whichever assistant they already use. After that their tools read the space the way yours do: a different company, a different AI, nothing pasted either way. If you granted write as well, their assistants write back into the same files, stamped with their account rather than yours.
A share is yours to take back
Revocation takes effect on the next request. Nothing is cached on our side to go stale, so it reaches their assistants as fast as it reaches their browser.
An expiry does the same thing without you having to remember: set one when you share and access ends on its own.
What you do not get is a limit on how much they read. Someone you gave read access to can read what you gave them, as fast as they like — scope is the consent, not pace. What you get instead is the record: every whole-file read of a space you shared is in your log, with who and when, and the point is that you find out.
Every read is written down, including ours
The activity log records who read what and when: your assistants, anyone you’ve granted access to, and Basin itself. If support opened one of your files it would show up in the same list. There’s no second log.
Things you can check without trusting us
Every line here is either verifiable by you or something we are on the hook for.