> **Planned. Not available today.** The current OAuth scope is `mcp`, which grants the connector full MCP access for the authorized account.

## Intended outcome

Future authorization should support narrower consent, such as read-only discovery, selected platforms or capabilities, and explicit execution permission.

The design must preserve audience binding, refresh-token rotation, revocation, existing API-key behavior, and private-module visibility rules.

## Current safe choice

Only authorize MCP clients you trust with the account's published capability access and credit balance. Revoke clients that no longer need access.
