Get started
Permissions & scopes
Give each connection just the capabilities it needs.
The complete scope map is included with the catalog. Read permissions cover profile, the authorized workspace, connected social accounts, content, media, products, schedules, automations, analytics and jobs. Separate create/manage/delete permissions cover content, products, carousels, captions and automations; publishing and scheduling have distinct permissions.
Tool discovery exposes only the tools allowed by the current access token. An attempted known tool requiring another scope returns HTTP 403 with an OAuth insufficient_scope challenge. The user must authorize the additional access; the agent cannot grant it to itself.
read:jobs is needed to poll generic operation IDs. Polling also requires the original tool's permission and the same connection, user and workspace. Plan entitlements and credits remain enforced in addition to OAuth scopes. Analytics currently requires Pro. No MCP operation upgrades subscriptions, grants credits, changes provider credentials or disconnects social accounts.
Scope reference
Exported from the same server configuration as the tool catalog.
| Scope | Permission |
|---|---|
read:profile | Read your profile and credit balance |
read:workspaces | Read the workspace you authorize |
read:social | List your connected social accounts (without credentials) |
read:content | Read and search your posts, drafts and carousels |
create:content | Create draft posts using text or existing media |
delete:content | Request deletion of your content (requires approval) |
read:media | Read your media library |
read:products | Read your products and editorial profiles |
create:products | Add products to your workspace |
manage:products | Create and update your products |
delete:products | Request deletion of products (requires approval) |
create:carousels | Generate carousels using your credits |
manage:carousels | Regenerate and approve carousels using your credits |
create:captions | Generate caption, hook and hashtag variations |
read:schedules | Read your publishing schedules |
publish:posts | Request publication to social accounts (requires approval) |
publish:schedules | Request scheduled publication (requires approval) |
read:automations | Read automation settings and run history |
create:automations | Create paused generation automations |
manage:automations | Edit or run automations (activation requires approval) |
delete:automations | Request deletion of automations (requires approval) |
read:analytics | Read stored real post analytics, subject to your plan |
read:jobs | Check requests made by this connection |