MCP

Permissions and scopes

The capability vocabulary, the consent presets, the project roles that cap every connection, and how the two are intersected on each call.


Reblog answers two questions on every MCP call, independently, and the call proceeds only if both say yes.

QuestionAnswered byChanges when
What was this app allowed to ask for?The grant's scopes, chosen on the consent screen.You revoke the connection or reconnect with a different level.
What is this person allowed to do here?Your role on the target project, re-read live.Immediately, when your role changes -- no token to revoke.

The effective capability is the intersection. A connection can never do more than the person who authorized it.

Denied tools are absent, not broken

A tool that fails both gates is not advertised at all: it never appears in tools/list, so an agent is never tempted to try it. That is why "the tool does not exist" usually means "you were not granted it".

Consent presets#

The consent screen offers three shorthand levels plus a custom mode. A preset expands against the live vocabulary every time it is evaluated, so it stays current; a custom grant is frozen at exactly what you ticked.

PresetGrants
Read-onlyread
articles.readagents.readassets.readaccount.projects.read
Read + create/edit articleseditor
articles.readarticles.createarticles.editagents.readagents.runassets.readassets.createaccount.projects.read
Full accessfull
articles.readarticles.createarticles.editarticles.deleteagents.readagents.runassets.readassets.createassets.deleteaccount.projects.read

Sensitive capabilities are never in a preset

Some capabilities can only be granted by an explicit, itemized consent -- not even by "Full access". Automation routines are one today, because a routine publishes on its own and spends credits on a schedule. Billing, project deletion, membership management and integration secrets are reserved the same way, ahead of the features existing, so they can never arrive silently in an old grant.

The scope vocabulary#

Each scope is a capability, not a place. Which projects a connection reaches is a separate choice made at consent time.

ScopeWhat it allowsAccessToolsIn presets
articles.readView your articlesread14read, editor, full
articles.createCreate articles and add ideas to the backlogwrite2editor, full
articles.editEdit articles, and publish, schedule or unpublish themwrite16editor, full
articles.deleteDelete articlesdelete1full
agents.readSee your AI agents and their job queueread4read, editor, full
agents.runLaunch agent runs and change how the agents are configured: write articles, translate them, generate images (spends AI credits)write10editor, full
assets.readSee the images and files in your projectsread1read, editor, full
assets.createAdd images and files to your projectswrite1editor, full
assets.deleteDelete images and files, including ones your published articles usedelete1full
automation.managesensitiveManage automation routines: list, run, pause (a routine can publish articles autonomously and spends credits)write3custom consent only
account.projects.readSee which projects and workspaces this app can accessread3read, editor, full

Project roles#

Your role on a project is the ceiling. The table shows the most a connection can ever do on a project for each role, no matter what the app was granted.

Scopecontributorpublishereditoradvanced editoradministrator
articles.readyesyesyesyesyes
articles.createyesyesyesyesyes
articles.editnonoyesyesyes
articles.deletenononoyesyes
agents.readnononoyesyes
agents.runnononoyesyes
assets.readnonoyesyesyes
assets.createyesyesyesyesyes
assets.deletenononoyesyes
automation.managenononoyesyes

Same rules as the dashboard

Each tool is mapped to the permission the equivalent dashboard action requires, and an unmapped tool falls back to administrator-only. So an MCP connection can do exactly what you could do by clicking, never more.

API keys map onto the same vocabulary#

A project API key has two coarse levels instead of per-capability scopes. They translate as follows, on the single project the key belongs to.

LevelNameEquivalent scopes
2Read-only
articles.readagents.readassets.readaccount.projects.read
3Read + write
articles.readarticles.createarticles.editarticles.deleteagents.readagents.runassets.readassets.createassets.deleteaccount.projects.read

Ask the server what you have#

get_my_capabilities returns the resolved answer for the connection making the call: the granted scopes, the reachable projects with your role on each, and which tools that combination actually allows. It is the fastest way to diagnose a refusal.

tools/call
{
  "jsonrpc": "2.0",
  "id": 2,
  "method": "tools/call",
  "params": { "name": "get_my_capabilities", "arguments": {} }
}

Seeing what a connection did#

Settings -> Connected apps shows what each app *may* do. Settings -> MCP activity shows what it *did*: every call with its tool, project, arguments, outcome and duration, including refusals and rejected credentials. Narrow a grant and the next tools/list in the log immediately reports a smaller catalogue -- the permission model is observable, not just documented.