Connected sources
A project can read from an address as well as from files you upload. Every chat in the project then answers with that context, and says that it did.
Open a project, then Connect a source. Give it a name and an https:// address.
Test fetches it once and tells you how much it read. A source can be switched off without being deleted; while it is off, nothing fetches it.
The text goes into the prompt as reference material, fenced and marked untrusted, the same as a file shared into the project. The model reads it. It does not take instructions from it — a page saying “ignore your previous instructions” is quoted content, not you speaking.
When a turn reads a source, the line above the answer names it. Sources that failed, or that did not fit the budget, are not named — the model did not see them.
Public internet addresses over https. Anything resolving inside a private network — loopback, private ranges, link-local, cloud metadata endpoints — is refused, whatever hostname points at it, and the address is checked again on every fetch.
- Up to six sources are read per message, in the order you added them.
- Each source contributes at most a few thousand characters, and all of them together at most eight thousand. A source that does not fit is skipped whole rather than cut mid-sentence.
- A source is read fresh on every message, so it costs prompt tokens on every message in that project.
- A source that does not answer within six seconds is left out. Your question is still answered, and the project panel shows the failure.
- Compressed responses are not read.
They are read while the prompt is being built, not called by the model while it answers. Nothing decides on its own to go and fetch something, and nothing writes anywhere.