Choose a permission preset
You pick a preset when you approve a remote connector, runnpx @sequenzy/setup
or create a key in AI Agent Setup. You can change it later on the same key.
Under Account Settings → API Keys you can also choose Read-only, the
data-ingest presets or individual scopes under Custom.
What Safer agent access covers
For MCP authorization and generated local MCP keys, Safer agent access is the default. It lets the agent inspect data, complete workspace setup (name, branding, mailing address, AI writing context), define lists and tags, apply tags to existing contacts, draft content, and edit sequence A/B variant copy (cart and browse abandonment included) without live delivery, destructive deletes, team changes, API key creation, or changes to your account-wide sending defaults. It cannot add contacts to a list or remove them from one; those operations needsubscribers:write, while deleting a definition needs the matching *:delete permission. Choose Full access when you intentionally want the agent to use the complete MCP surface, including sending, deletes, and administration. Use sender presets or custom scopes when the agent should send only specific kinds of email.
Your workspace role still applies on top of the key. A personal key never does more than you can do in the dashboard, and a viewer is read-only however wide the key is.
Recover from missing permissions
When a tool reports a missing scope such ascampaigns:read or
templates:write, call get_account first. Its apiKeyPermissions field shows
the effective preset, full-access state, scope counts and description, exact
scopes, common missing marketing read scopes, live delivery state, and a direct
manageUrl for the matching API Keys page. On the standard MCP surface it also
includes the non-secret active-key identity. The OpenAI-reviewed surface omits
the account user ID and active-key identity because they are not needed to plan
the request; use list_api_keys and its isCurrent marker when a company key
must be managed. Personal keys open the account-level page; company keys open
the selected workspace’s page. Each company also includes a settingsUrl. If
the key does not include account:read,
get_account cannot return that metadata; open the
Sequenzy dashboard directly and use the MCP
setup or Settings → API Keys instead.
You do not need a new key. Permissions are editable in place on the key the
client already holds, so you can widen them mid-session without touching the MCP
configuration or restarting the client.
Open manageUrl, edit the connected key in the dashboard, and enable every scope named in the error - either by
switching preset (Safer agent access covers common drafting, setup,
list/tag-definition work, and sequence A/B variant copy; Read-only covers discovery) or by adding the individual scopes
under Custom. Then retry the same tool call: the API reloads the key’s
permissions whenever a request is denied, so the retry succeeds immediately. The
key value never changes.
An agent using a company key that holds api_keys:manage can do this itself
by calling list_api_keys, choosing the entry where isCurrent is true, and
passing that entry’s id to update_api_key. Personal keys must be edited on
the account-level API Keys page; update_api_key only manages company keys.
scopes and preset replace the whole selection rather than merging into it, so
send every scope from apiKeyPermissions.scopes plus the missing ones. The
default Safer agent access preset deliberately withholds api_keys:manage,
so agents on that preset ask the workspace owner to make the edit.
api_keys:manage is the one scope an agent cannot work around: the permission
needed to widen a key is the permission that is missing. That is deliberate -
otherwise a leaked operational key could mint a full-access successor for
itself. Instead of guessing at the dashboard, call request_api_key_handoff. It
returns a link that opens the create-key form with the name and permissions you
asked for already filled in, so the owner only has to review and confirm. Add
replaceApiKeyId: "current" to rotate the key you are authenticated with, and
the dashboard offers to revoke it once the replacement exists. Nothing is
created until the owner clicks Create, and the new key appears in their browser
rather than in the tool result - so hand over the URL and stop rather than
polling for a key that will never arrive.
Replacing the key still works if you prefer it: create a new key with wider
permissions, update SEQUENZY_API_KEY, and restart the client. For hosted OAuth
MCP, you can also disconnect the Sequenzy connection and reauthorize it with a
preset or custom permissions that include every scope named in the error.
Removed permissions can lag by up to five minutes while API caches expire.
Widened permissions do not - they apply on the next retry.
Check whether the key can send before you compose
Drafting permission and delivery permission are separate on purpose. A key can holdtransactional:write (create and update transactional email templates) and
still lack transactional:send (deliver a live email), which is exactly how the
Safer agent access and AI drafting presets are built - they let an agent
author content without being able to mail anyone.
get_account reports this up front so you find out before writing the email
rather than when the send is denied:
apiKeyPermissions.canSendLive-falsewhen the key holds no live-delivery scope at all, so it can draft and manage content but cannot deliver anything.apiKeyPermissions.missingLiveDeliveryScopes- the specific delivery paths the key lacks, such astransactional:sendforsend_email,campaigns:sendforsend_campaign, orsequences:activatefor activating a sequence.apiKeyPermissions.liveDeliveryBlockedByRole-truewhen the workspace role blocks sending regardless of scopes. A personal key inherits the user’s role, and avieweris read-only however wide the key is.apiKeyPermissions.roleRestrictedScopes- scopes the workspace role cannot use through a personal key. Amarketercan send campaigns and activate sequences but liststransactional:send,team:manage, and the other workspace-management scopes here; widening the key does not change this.
liveDeliveryBlockedByRole is true, widening the key will
not help: ask the workspace owner for owner or admin access instead, or use a
company key issued for that workspace.
Data and privacy
An MCP client receives only the result of the tool you ask it to call, within the workspace and permission scopes you approved. Depending on that request, the result can contain workspace identifiers and names, subscriber contact and consent data, custom business or marketing attributes, events and engagement, campaign or automation content, replies, surveys, commerce data, analytics, and integration or webhook status. Review the Privacy Policy before connecting an AI provider. Do not put individual-level payment-card data, health or medical data, government identifiers such as Social Security or passport numbers, biometric or genetic data, passwords or authentication secrets, sensitive demographic data, or precise geolocation into custom attributes, events, notes, variables, form fields, webhook samples, feedback, or other open-ended inputs. The OpenAI-reviewed surface at/v1/mcp/openai states that restriction on
relevant open-ended fields and rejects obvious restricted fields and credential
patterns before an API call, including nested attribute paths such as
profile.ssn, coordinate pairs such as lat/lng, labelled prose such as
Religion: ... or GPS coordinates: ..., and a credential-bearing URL in any
argument, whether the credential sits in the userinfo, path, query, or fragment
(for example a form redirectUrl with an access token or URL signature).
Restricted attribute selectors inside merge tags are rejected without blocking
ordinary authored copy about the same topic. render_email accepts a
policy-checked inline subscriber on this surface, but not subscriberId, so
it cannot resolve uninspected stored custom attributes. Stored
credential-bearing URLs are redacted from its responses as well. It removes restricted fields, raw payloads,
request and trace IDs, debug data, and unnecessary account or credential
identifiers from responses. It does not expose connect_integration,
create_api_key, create_webhook, inbound-secret rotation, or raw outbound
webhook delivery tools. Use request_api_key_handoff, the Sequenzy dashboard,
or the local CLI for those workflows. Feedback remains available with a reduced
schema for generalized, explicitly requested product feedback.
What the reviewed surface guarantees is bounded. It recognizes restricted data
by shape: English field-name words such as passport_id, user.ssn, or
api_secret at any nesting depth, labelled prose such as Diagnosis: ...,
known credential shapes, decimal coordinate pairs, and credential-bearing URLs
inside any string, including HTML. It does not interpret unlabelled prose,
non-English field names, or values a client deliberately obfuscates; those
remain covered by the usage restriction above rather than by the filter.
The standard /mcp and /v1/mcp endpoints and the local stdio package retain
the complete MCP contract for trusted clients. On those standard surfaces,
connect_integration accepts provider credentials the user explicitly supplies,
while create_api_key, create_webhook, and inbound-webhook setup can return a
one-time secret or credential-bearing URL. Treat those results like credentials
and prefer the dashboard or local CLI when secrets should stay outside the AI
conversation. The OpenAI-reviewed route omits raw API error bodies and nested
diagnostics; standard MCP retains detailed API errors for trusted-client
debugging. submit_feedback sends data to the Sequenzy team only when the user
explicitly asks; never include unrelated subscriber data, message content,
credentials, or raw API payloads.
Key security
- Personal API keys are tied to your user account
- Keys can only access companies you have access to
- You can revoke keys anytime in Settings → API Keys
- Keys are never shared between users