This article applies to client-side IT administrators and technical sponsors responsible for enabling PI's MCP connector during the current Pre Beta phase.
Have additional questions about PI's MCP that weren't answered in our configuration articles? Here are answers to some frequently asked questions.
Installation
What do we actually install?
What do we actually install?
Nothing to download or package. You register PI’s remote connector URL in a supported host, and each user signs in with their PI account.
Security & data privacy
How is data handled, and what about residency and retention?
How is data handled, and what about residency and retention?
Data handling follows PI’s standard platform security protocols; retention follows PI guidelines, and a purge can be requested at the completion of the Pre-Beta. For region-specific commitments and current certification detail, see the PI Trust Center.
Is the AI host trusted as part of our security?
Is the AI host trusted as part of our security?
No. Every request runs through PI’s own security pipeline server-side, regardless of the host. The host is explicitly not relied on as a security boundary.
Is PI’s behavioral-science IP exposed to the AI host?
Is PI’s behavioral-science IP exposed to the AI host?
No. PI’s science corpus is never sent to the host; the host only relays Obi’s finished answer.
Are users’ questions stored, and who can see them?
Are users’ questions stored, and who can see them?
Conversations are private to the individual user. The connector is stateless, so questions asked through it are not added to the user’s Obi chat history in the PI web app.
Does anyone train models on our data?
Does anyone train models on our data?
PI’s contracts with third-party AI hosts prohibit training on client data. For PI’s own data-handling and model practices, see the PI Trust Center or request the Obi AI Security and Trust Pack.
MCP & user permissions
Can the PI MCP change or delete anything in our PI data?
Can the PI MCP change or delete anything in our PI data?
No. All three tools (described here) are read-only. They can look up, explain, and generate content, but cannot send, email, invite, save, or modify anything in PI.
What data does the MCP have permission to see on behalf of the user?
What data does the MCP have permission to see on behalf of the user?
Obi (and by extension the MCP) always acts as the signed-in user. The connector forwards that user’s verified sign-in token to Obi; it never takes identity from anything typed into the AI host — not a prompt, not tool arguments. A prompt saying "act as the CFO" is just tool input.
The request still carries that user’s own token, and PI checks permissions server-side. Each user sees only the PI data they already have access to. Connecting an AI host does not widen anyone’s access.
Can a user leverage PI's MCP to see data they aren’t supposed to see?
Can a user leverage PI's MCP to see data they aren’t supposed to see?
No. Obi (and by extension the MCP) always acts as the signed-in user and returns only data that user already has access to in PI — the same scoping as the PI web app. Identity comes from the verified sign-in token, never from text typed into the AI host, so it cannot be spoofed by prompt input.
Sign-in & authentication
How does authentication work for PI's MCP?
How does authentication work for PI's MCP?
Authentication is handled by PI single sign-on using OAuth 2.1 (authorization code + PKCE). Users authenticate against PI’s login at login.predictiveindex.com and connect their PI user record.
Credentials are never entered in the AI host, even where sign-in begins in the chat window. PKCE binds the authorization code to the client that started the flow, so an intercepted code cannot be used elsewhere. Users may see a one-time consent dialog on first connect.
How and when do sessions refresh?
How and when do sessions refresh?
Sessions refresh automatically. Users are asked to sign in again either after 30 days of inactivity, or about every 180 days regardless of usage, when the refresh token expires.
Managing the MCP
How are updates delivered?
How are updates delivered?
Server-side. There is no package to redistribute. Users generally do not need to reconnect, though they will be asked to sign in again when their session expires.
How do you disconnect the MCP?
How do you disconnect the MCP?
To disconnect, remove the "Obi by PI" connector in the host’s connector settings. (The user can reconnect at any time while their PI account remains active with Obi access.)
Additional support
