Skip to main content
This page describes access controls for MCP links created in Craft’s Connections tab.

Security Layers

1. Space-Based MCP Server Management

MCP servers are tied to spaces, so only logged-in Craft users with access to a given space can manage its MCP settings. On an individual plan, you’re the only one who can manage your MCP servers. Every MCP link contains a cryptographically secure random, non-guessable string. This works automatically without any configuration. Even without password protection (i.e. ‘public’ access), your MCP connections can only be used by people you explicitly share the URL with or those who can access the given space.

3. Optional Password Protection (OAuth 2.0)

Set a password on the Connections page to require it when connecting an MCP client through that link.
Some MCP clients ask for an “OAuth Client ID” and “OAuth Client Secret.” You can leave these fields empty for Craft MCPs. Our password protection uses OAuth 2.0 with dynamic client registration, so no pre-configured credentials are needed other than the URL and the password.

4. Read/Write Permissions

You can restrict agents to read-only or write-only operations, limiting what actions they can perform.

5. Scope Limitations

You can limit an agent’s access to:
  • A predefined set of documents
  • Daily notes and tasks within a space
  • All documents in your space (v3.3.5+)
  • Documents matching search criteria (v3.3.5+)

Protection for Embedded Content

These security layers also protect content within your documents, including links to files and images. While files and images don’t have separate authentication (due to limited MCP client support), their unguessable links can only be retrieved after authenticating to your MCP server. File and image links are rotated whenever you change your MCP server’s password, ensuring that any previously shared links become invalid.

Best Practices

  • Use password protection for MCP connections that access sensitive content
  • Regularly review and rotate MCP passwords
  • Limit connection scope to only the documents needed
  • Use read-only permissions when write access isn’t required
  • Monitor MCP connection usage in your space settings