Mints the Configure link that fixes access for the current user — sign-in, app connect, or permission grant. This is the tool for two situations: a Configure tool result says authorization_required (the user is not signed in), or the user asks to sign in or connect an app. The user's data exists behind sign-in, so "I have nothing on you" would be inaccurate in that state; what serves the user is knowing sign-in is the blocker and having the returned link, on its own line where it is easy to click. Retrying the failed call returns the same result until the user has signed in. Links exist only as this tool mints them — a hand-built link fails — and when a tool result already carries a link, that link is the one the user needs (minting another creates a second, competing session). Not the first call of a conversation (that is configure_profile_read), and not the fix for error -32009 (that is configure_profile_commit). For a signed-in user: app (gmail, calendar, drive, notion, sheets) connects or reconnects that app — returns status connect_app, a link, and whether it is already connected — and capability (like gmail:send) covers a single missing permission (status permission_needed). Bringing memories in from another assistant is NOT a connect action: this tool does not do it, and a bare "connect Configure" from a signed-in user needs no argument at all — omit app unless the user names a specific app to connect. Configure derives the requester from authenticated agent metadata or MCP transport metadata; the client field is a legacy fallback hint for an unauthenticated headless client only.