> For the complete documentation index, see [llms.txt](https://docs.emseapea.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.emseapea.ai/builder-guide/your-workspace.md).

# Your workspace: repo, credential, connectors

The moment your request is approved, provisioning runs automatically. Ask `get_workspace` (or open the app in **My Apps**) and you receive three things:

* **Repo URL** — a repository created from your organization's approved template, in your company's GitHub. Clone it and build inside it; its CI already runs the same scanners the deploy gate enforces. It also comes with a generated `CONNECTORS.md` — ground truth for exactly which systems it may reach, **how** it reaches each one (only what the signed-in person can see, or a prepared account — see [The two kinds of access](/builder-guide/kinds-of-access.md)), and a copy-pasteable working example per system, so your AI tool doesn't have to guess an API shape from a generic vendor tutorial.
* **Credential handle** — an opaque `emcp_…` token. It is not a password to any system; it's redeemed *through your organization's gateway*, which checks it on every call. It's short-lived and re-issued automatically.
* **Approved connector list** — exactly which systems that handle unlocks.

If your request also asked for somewhere to keep the app's **own** files or records, `CONNECTORS.md` gains a section headed **"Where this app keeps its own data"** with worked examples for it, and an `emseapea.json` is committed alongside describing what you were granted. See [Storing files and data in your app](/builder-guide/storing-files-and-data.md).

## Using the credential

Point your app (and, while developing, your AI tool) at your organization's gateway and pass the handle as a Bearer token:

```
GET https://<your-org-gateway>/u/erp/invoices
Authorization: Bearer emcp_…
```

Calls to systems on your approved list are forwarded. Calls to anything else are refused with a pointer back to emseapea — request the extra system and an admin will review it. Every call, allowed or blocked, is recorded against your app.
