MCP

MCP security model

How the bridge stays safe: bearer-token auth, per-workspace scoping, audited tool calls, and no path around approval.

Last updated June 14, 2026

The MCP bridge has its own security model, separate from your browser session. It authenticates with a scoped bearer token, scopes every query to that token's workspace, audits every call, and never exposes a path that publishes without approval.

Controls

  • ·Bearer token, not a cookie — the bridge never rides your browser session.
  • ·Workspace scoping — a token can only touch its own workspace's data.
  • ·Audit trail — every tool call is recorded.
  • ·Approval preserved — actions that publish still require the human gate.