API & MCP reference / MCP server

Scopes & consent

You approve a scope when you connect, and a client only ever sees the tools its grant covers — a read-only connection has no publish tools to call by mistake.

ScopeGrantsTools
readView posts, accounts, media, analytics6
publishCreate, update, delete, sync5

Revoke any connected app from Dashboard → API Keys → Connected apps. Revocation kills the refresh token immediately; the client's current access token stops working within the hour.