Skip to content

Apps and access

An Instance can allow or block four client surfaces. You can change your own access in Settings → Apps → App access.

Surface Default What it does
API On Lets external clients use the API with an App Password.
CLI On Lets the calternal CLI connect with its Installation token.
MCP Off Lets a remote AI client use MCP tools.
WebMCP Off Lets tools run in this signed-in browser when the browser supports WebMCP.
  1. Open Settings → Apps → App access.
  2. Turn a surface on or off.

An Owner or Admin can also open Settings → Admin → Apps → App access. This switch sets the limit for every User on the Instance. If an Admin turns a surface off, a User cannot turn it on.

The signed-in browser stays available if you turn off another surface. Each client still needs its own supported credential and access scope. An App Password does not replace a passkey.

Open Settings → Apps → App Passwords to create or revoke an App Password. Use the matching protocol and grant only the access that the client needs. The AI assistant preset can view and change data by default; choose Can view when the assistant only needs to read. After creation, copy the setup fields for an MCP server, a CLI agent, or an mcp.json file.

Use an App Password for one client. Do not reuse it for another client. The API and CLI are on by default. Turn on MCP or WebMCP only when you need it.