Skip to documentation
Browse documentation

Scoped OAuth access

Restrict connectors below full account access.

View raw

Planned. Not available today. The current OAuth scope is mcp, which grants the connector full MCP access for the authorized account.

Intended outcome

Future authorization should support narrower consent, such as read-only discovery, selected platforms or capabilities, and explicit execution permission.

The design must preserve audience binding, refresh-token rotation, revocation, existing API-key behavior, and private-module visibility rules.

Current safe choice

Only authorize MCP clients you trust with the account's published capability access and credit balance. Revoke clients that no longer need access.