Codonic

Souvenir · Optional AI access

Connect Souvenir to Claude or ChatGPT

Souvenir has a hosted remote connector, so using it does not depend on a desktop relay. You choose whether to create a Souvenir account, whether to enable AI access, and which requested permissions to approve.

Availability: the connector is being prepared for provider review. A searchable directory listing is not guaranteed until OpenAI or Anthropic accepts it. Custom connector entry also depends on the features available in your provider account and app. Claude's connector directory can be browsed and connected directly in supported mobile beta clients; custom connector setup may still need a browser or web app. ChatGPT custom MCP availability can be web-, plan- or workspace-limited. A reviewed directory app may have different availability later. The shared-trip connector uses Souvenir's hosted canonical Bridge service directly; no phone or desktop needs to remain online after setup.

Before you connect

Update Souvenir on the phone or tablet where you use it. In Souvenir, create or recover an optional account and store the recovery code somewhere safe. The recovery code is the only way to recover that account on another device: Codonic never receives it and cannot reset it for you.

Then enable Claude and ChatGPT access in Souvenir. Access is account-wide: every current or future shared Bridge trip with a valid binding for your account becomes eligible. The account authority fixes the participant identity used for attribution; it does not expose another participant’s identity or a trip the account cannot access.

Connect from Claude or ChatGPT

  1. Find Souvenir in the provider’s connector directory once it is listed, or add the custom MCP endpoint below when your plan and client support custom connectors.
  2. The provider opens an authorization page. Choose Continue in Souvenir. The installed Souvenir app opens the request using a souvenir:// link. Depending on provider UI, initial custom-connector setup may still need the provider’s web app.
  3. Review the provider, requested read or write permissions, and the Souvenir account that will be connected. Approve or decline explicitly in the app.
  4. Return to the provider. Its authorization window completes automatically.
Remote MCP endpoint https://integrations.codonic.dev/mcp

Never approve a request you did not start. Souvenir uses OAuth 2.1 authorization-code flow with PKCE. Access tokens last about 15 minutes; refresh credentials rotate and can last up to 90 days. Disconnecting at the provider does not necessarily disable the Souvenir-side AI grant, so use the in-app switch when you want to stop both.

What the connector can do

A connection covers the account’s currently granted trips; it is not limited to one trip. With read access, Claude or ChatGPT can list trips and participants, summarize or search expenses, and retrieve a specific expense. With write access it can create, update or delete an expense. Local and private-iCloud trips are not exposed because they do not have an always-on server source. Shared-trip reads and writes go directly through Souvenir's canonical Bridge service; no enrolled device has to relay or apply a tool call. The provider decides when to ask you for confirmation according to its own interface and settings.

Enabling the connector makes every current and future trip reachable through this account eligible; it is not a per-trip picker. In a shared trip, the limited projection includes the display names and shared expenses of other participants, including people who did not create a Souvenir account or connect an AI provider. Only enable it when you have authority to share that group data, and notify the group when appropriate.

Every write is attributed to the exact trip participant linked to your Souvenir account. The payer is a separate field and may be any current trip member. Choosing a payer never changes who performed the AI action.

What leaves the device

Ordinary use

With the optional account and AI connector off, journal content remains on devices, private iCloud storage, or end-to-end encrypted shared-trip transport. Codonic cannot read it.

Account only

The service stores pseudonymous but linkable account, device and trip-binding identifiers, public signing keys, statuses and timestamps, plus encrypted recovery envelopes. These operational indexes are not anonymous. An account binds identity across devices; it is not a second copy of the trip journal.

AI enabled

For each granted shared trip, Souvenir stores its trip key encrypted at rest plus an expiring, revocable AI signing key. The service verifies and decrypts the canonical Bridge history for each tool call, returns only the limited fields below, and commits attributed writes directly. This opt-in path is not end-to-end encrypted from Codonic or the selected provider, and no phone needs to stay online.

The AI projection can include the trip name, currency, dates, member IDs and display names, and expense IDs, dates, amounts, currencies, categories, short descriptions, payer and split information. It excludes private notes, exact coordinates, card identifiers, nicknames and last four digits, attachments, photos, receipts and other media.

For a shared trip, those names and expense details can describe other participants who never made a Souvenir account or enabled the connector themselves. The participant who opts in is responsible for having authority to send the shared ledger to the selected provider.

The selected provider receives tool inputs and results and may retain them under its own terms, privacy policy, plan and conversation controls. Read the provider’s settings before sending sensitive questions.

Disable, disconnect or delete

  • Disable AI access in Souvenir to invalidate provider access immediately, prevent new tool actions and revoke reachable trip grants. Encrypted projection and terminal-action records can remain in the account service until replacement, their retention cleanup, trip-binding revocation or account deletion. Already returned provider content is outside Souvenir’s control.
  • Sign out or remove one device without deleting the account or its other devices. Keep the recovery code if you may return.
  • Delete the optional account in Souvenir to revoke its devices and OAuth access and purge its account, binding, grant, projection and action records. The app first removes its account authority from reachable trips. Canonical shared-trip history remains with the trip, including pseudonymous security operations needed by other participants.
  • Delete a trip separately in Souvenir when you want to remove that trip from your own devices and iCloud scope. Deleting the app alone does not delete an account, shared-trip history, or copies already held by an AI provider.

See the full Souvenir privacy policy and terms of use for the authoritative details.

Cost and service limits

Codonic currently charges no separate fee for the Souvenir account or connector and does not buy model API calls on your behalf. You bring your own Claude or ChatGPT access; that provider may require a paid plan or impose its own message, connector and regional limits.

As of 13 August 2026, Claude Free permits one custom remote connector, but a custom entry is unverified and not searchable. Anthropic currently requires a Team or Enterprise organization to submit to its searchable directory and documents no free submission waiver or guarantee that a listing remains after cancellation. Directory discovery is therefore not promised as part of Codonic's no-cost launch; custom hosted access remains the available no-desktop path where the provider account supports it.

The hosted service is designed around the free allowances of Cloudflare and Apple CloudKit. Those allowances are finite, not a promise of unlimited service. During heavy use the connector may rate-limit requests, return a temporary error, or ask a device to retry later. Normal mobile-data and provider charges still apply.

Troubleshooting

  • If the authorization page cannot open Souvenir, install or update the app on that mobile device, then start the connection again before the short-lived request expires.
  • If no trips appear, confirm that the same Souvenir account is active, AI access is enabled, and the shared trip has a current account binding and AI grant.
  • If a write fails, read the expense again before retrying an update or delete. Souvenir uses exact revisions and will reject a stale or revoked request rather than queueing it.
  • If account recovery fails, re-enter the complete recovery code exactly. Support cannot reconstruct or bypass it.

Still stuck? Email support@codonic.dev and tell us which provider and app version you used. Do not send your recovery code, access token or trip secrets.