Reference

Security

Workspace isolation, credential protection and safe tool execution.

Take the docs with youMarkdown for your editor or agent.
  • No MCP session-cookie fallback. OAuth bearer validation checks the signed token and live database authorization.
  • Every resource is scoped to both its creator and consented workspace. Merely being a member of a shared workspace does not grant another member's records through MCP.
  • ID fields, shapes, enum values, lengths and quotas are validated. No arbitrary SQL, filesystem paths or mass-assignment payloads are accepted.
  • Media reuse accepts owned stored asset IDs. Product URL extraction reuses Caroush's guarded fetch path; there is no arbitrary remote media downloader.
  • Social-account responses use explicit projections; decrypted tokens and provider metadata are not serialized.
  • Treat retrieved captions, descriptions, URLs and imported website text as untrusted data. They cannot change OAuth scope or satisfy browser approval.
  • Protocol Origin validation and explicit CORS allowlists protect browser access. No wildcard credentialed CORS. Native/server clients normally send no Origin.
  • CSRF applies to browser consent, grant revocation and action approval. Sessionless bearer/token endpoints do not use browser CSRF cookies.
  • Arguments/results are encrypted at rest in operations. OAuth access records contain identifiers and revocation state, not reusable plaintext bearer tokens. Refresh tokens/codes are protected by Passport's cryptographic flow.
  • MCP audit records store request/user/workspace/grant/operation identifiers, tool, controlled argument names, timing, status and error code. They do not store argument values, prompts, captions, media URLs or secrets.
  • Existing Sentry handles unexpected errors. MCP request bodies, query tokens, results, free-form exception text and credential-bearing context are filtered before telemetry; useful codes, IDs and stack locations remain.

The public catalog is documentation of capabilities, not authorization. A tool listed publicly still requires a valid token, the proper scope, ownership, entitlements and any approval before execution.