Apps and access
An Instance can allow or block four client surfaces. You can change your own access in Settings → Apps → App access.
| Surface | Default | What it does |
|---|---|---|
| API | On | Lets external clients use the API with an App Password. |
| CLI | On | Lets the calternal CLI connect with its Installation token. |
| MCP | Off | Lets a remote AI client use MCP tools. |
| WebMCP | Off | Lets tools run in this signed-in browser when the browser supports WebMCP. |
Change access
Section titled “Change access”- Open Settings → Apps → App access.
- Turn a surface on or off.
An Owner or Admin can also open Settings → Admin → Apps → App access. This switch sets the limit for every User on the Instance. If an Admin turns a surface off, a User cannot turn it on.
The signed-in browser stays available if you turn off another surface. Each client still needs its own supported credential and access scope. An App Password does not replace a passkey.
Choose an App Password scope
Section titled “Choose an App Password scope”Open Settings → Apps → App Passwords to create or revoke an App Password. Use the matching protocol and grant only the access that the client needs. The AI assistant preset can view and change data by default; choose Can view when the assistant only needs to read. After creation, copy the setup fields for an MCP server, a CLI agent, or an mcp.json file.
Use an App Password for one client. Do not reuse it for another client. The API and CLI are on by default. Turn on MCP or WebMCP only when you need it.