Skip to content
SpecifyDocs

Specify MCP

Tokens and access policies

MCP token scopes, how to revoke tokens, and the workspace access policies available to admins.

Agents read only what your workspace permissions allow. This page explains personal token scopes and management, and the access policies admins apply to the whole workspace.

Token scopes

ScopeAllowed toolsDefault
mcp:readsearch, read_document, browseAlways included
mcp:writecreate_document, update_documentOptional (when Allow document creation and editing is checked)

The default is read-only. Allow write access only when the agent needs to create or edit docs. If you check Allow document creation and editing under Permissions for new connections before connecting, the token is issued with write access.

Access overview and Permissions for new connections at the top of the Connect editor tab
Admins also see active access permissions, workspace access, and calls in the last 24 hours at the top.

Manage your access permissions

In the Editor access list on Tools & skills → Connect editor, you can see the permissions you've issued.

  • Read only / Read and write: The scope of the issued permission
  • Last used: When this permission was last used for a call. If it has never been used, it shows Not used yet.
  • Revoke access: Ends a permission you no longer use. Editors connected with this permission need to be set up again.

If you switch laptops or a token may have been exposed, revoke the existing permission and connect again. A revoked permission is rejected starting with the next call. You can see revoked permissions with Show N revoked permissions.

Admin access policies

Admins and owners also see the Workspace access policy on the Tools & skills → Connect editor tab, where they manage external editor access for the whole workspace.

Allow access from external editors

Turning this off blocks access from every external editor connected to this workspace. You can use it as a switch to cut off access immediately during incident response or a policy review.

Allowed operations

Decide per tool whether it's allowed: Search, Read document, Browse tree, Create document, and Update document. For example, you can allow only reads and block creating and editing. This setting applies to every editor connection, and write operations also require write access to be allowed when connecting.

Token inventory

See the owner, label, scopes, last use, and status of every token issued in the workspace. Admins can Revoke other members' tokens here, and revoking immediately cuts off access for the connected editor.

Usage

See call counts and error counts per tool for the last 24 hours.

Members can manage only their own connections. For workspace-wide access policies, contact an admin.