Skip to main content
Every MCP connection acts as one Floral user in one workspace. Floral checks the user’s active membership and current access again when each tool runs.

Personal access token scopes

Token creation offers these scope pairs: New keys start with the available read scopes selected. Remove any read area the client does not need. Add a write scope only for an intended write workflow.

Write behavior

MCP writes do not pause for the approval dialog used by the in-app Assistant. The MCP client decides whether to ask before a change and can execute any tool allowed by the connection and the user’s current permissions.
An OAuth connection receives the same capability scope as the in-app Assistant after the user explicitly grants read and write access. Floral still checks active membership, role, feature permissions, Work access, and workspace ownership on every call. Connections created before write access was introduced remain read-only until the user reconnects and reviews the updated consent. Use OAuth only with a client you trust to follow the user’s intent and handle confirmation appropriately. Disconnect the client immediately if its behavior is unexpected. Use a personal access token when you need narrower credential scopes. Create a separate key per client, give it a short expiry, and avoid “no expiry” unless the environment has its own rotation process. Test with read-only scopes first.

Credential handling

  • Store the full key in the client’s secret storage.
  • Never put it in source control, a prompt, a Source, or ordinary logs.
  • Revoke it immediately if it appears in copied output or screenshots.
  • Disconnect unused OAuth clients and revoke keys for retired devices.

Audit use

Open Settings > Assistants > Logs, or Settings > Floral Agent > Logs if your settings menu shows Floral Agent. Administrators see workspace-wide tool use; members see their own. Review the tool name, access type, surface, status, and time. Also inspect the changed record after a sensitive write.