# Applicant MCP help | DSTI Application System Canonical HTML: https://application.dsti.school/mcp/help Language: en-GB This Markdown copy is generated from the same DSTI Application System build as the canonical HTML page. It is intended for machine readability and concise retrieval. ## Page summary Learn how the DSTI public applicant MCP protects identity, previews every change and hands protected actions back to the secure Web application. ## Page content Secure ChatGPT connection # Connect ChatGPT to your DSTI application safely Sign in to let ChatGPT use only the DSTI application permissions you approve. Your application remains governed by the DSTI backend and remains available through the secure Web portal. ## Why you need to sign in You need to sign in so DSTI can associate this ChatGPT connection with your verified email address, protect your application details and let you safely resume, update or submit your own application. Use the same email address that you use, or intend to use, for your DSTI application. If you already started an application with another address, continue in the secure DSTI Application Web Portal and use its recovery process instead of trying to claim it through chat. ## Who handles your sign-in Google is the primary sign-in choice. The native Cognito email-and-password option remains clearly available as a fallback. Sign-in is handled through Amazon Cognito, an AWS identity service operated for DSTI. Your Cognito password, Google password, verification code and recovery secret are entered only on the relevant Cognito or Google page. They are never shared with ChatGPT or the DSTI Application MCP. Authentication is powered and secured by Amazon Cognito. Your Google credentials, when Google sign-in is used, remain with Google. ## How your identity remains protected If a native Cognito account already uses the same verified mailbox, you must independently authenticate both that account and Google before they can be linked. DSTI will never merge accounts from email equality alone. If sign-in, account matching or ownership is unclear, no application is linked automatically. Use the secure DSTI Application Web Portal or contact DSTI support for recovery. DSTI governs application ownership and authorisation. Amazon Cognito or Google authenticates the account; ChatGPT invokes only the approved DSTI application operations. ## You control the permissions ChatGPT receives only the OAuth permissions you approve for the DSTI application service. Read, update and submission permissions remain distinct and are rechecked by the DSTI backend for every operation. ## Changes use preview and confirm Creating, changing or submitting an application requires two steps. First, the MCP validates and previews the exact proposed action without changing your record. It acts only after you explicitly confirm that exact preview. Concurrent changes, expired previews, repeated requests and attempts to alter a confirmed proposal are rejected safely. ## Protected actions stay on the Web Documents, identity verification and payments stay on the secure Web application. The MCP can provide a direct link to your application, but the link contains no access token. The Web application verifies your ownership before opening the requested record. ## Continue without MCP The Web application remains fully independent of MCP availability. You can always use the applicant portal to access your records directly. ## Meaningful public links - [Start an application](https://application.dsti.school/start) - [Open the applicant portal](https://application.dsti.school/portal) - [Machine-readable explanation](https://application.dsti.school/mcp/authentication.json)