Reference
Security
Workspace isolation, credential protection and safe tool execution.
Take the docs with youMarkdown for your editor or agent.
- No MCP session-cookie fallback. OAuth bearer validation checks the signed token and live database authorization.
- Every resource is scoped to both its creator and consented workspace. Merely being a member of a shared workspace does not grant another member's records through MCP.
- ID fields, shapes, enum values, lengths and quotas are validated. No arbitrary SQL, filesystem paths or mass-assignment payloads are accepted.
- Media reuse accepts owned stored asset IDs. Product URL extraction reuses Caroush's guarded fetch path; there is no arbitrary remote media downloader.
- Social-account responses use explicit projections; decrypted tokens and provider metadata are not serialized.
- Treat retrieved captions, descriptions, URLs and imported website text as untrusted data. They cannot change OAuth scope or satisfy browser approval.
- Protocol Origin validation and explicit CORS allowlists protect browser access. No wildcard credentialed CORS. Native/server clients normally send no Origin.
- CSRF applies to browser consent, grant revocation and action approval. Sessionless bearer/token endpoints do not use browser CSRF cookies.
- Arguments/results are encrypted at rest in operations. OAuth access records contain identifiers and revocation state, not reusable plaintext bearer tokens. Refresh tokens/codes are protected by Passport's cryptographic flow.
- MCP audit records store request/user/workspace/grant/operation identifiers, tool, controlled argument names, timing, status and error code. They do not store argument values, prompts, captions, media URLs or secrets.
- Existing Sentry handles unexpected errors. MCP request bodies, query tokens, results, free-form exception text and credential-bearing context are filtered before telemetry; useful codes, IDs and stack locations remain.
The public catalog is documentation of capabilities, not authorization. A tool listed publicly still requires a valid token, the proper scope, ownership, entitlements and any approval before execution.