# Fuzzbucket MCP access

Only dedicated MCP personal access tokens are accepted. Browser cookies and app JWTs are not MCP credentials. OAuth is not available. Tokens are scoped, expiring and revocable in Settings. Authentication uses stored hashes. New tokens also have an encrypted setup copy retrievable only through their owner’s active first-party session. Older hash-only tokens cannot be recovered. An inactive account cannot use MCP.

Discovery exposes only authorized action variants; execution checks scopes again. Brand, workspace, node, asset, conversation and run ownership remain enforced. Existing tokens never receive new write permissions automatically. Create a new token to choose the current scopes.

Saving drafts and connections does not generate. Chat and generation can spend credits under the normal app limits. MCP does not expose internal agent tools, system prompts, social publishing, administration or billing mutations.

Transfer grants expire after 15 minutes and stop working when their token expires or is revoked. They authorize a specific workspace and request. Keep token and transfer headers private.
