Skip to main content
Every MCP connection acts through a Sequenzy API key or OAuth grant with a specific set of permissions. This page explains which preset to pick, how to fix a missing permission mid-conversation, and what data your AI provider can see. To connect in the first place, start with Connect AI assistants.

Choose a permission preset

You pick a preset when you approve a remote connector, run npx @sequenzy/setup or create a key in AI Agent Setup. You can change it later on the same key. Under Account Settings → API Keys you can also choose Read-only, the data-ingest presets or individual scopes under Custom.

What Safer agent access covers

For MCP authorization and generated local MCP keys, Safer agent access is the default. It lets the agent inspect data, complete workspace setup (name, branding, mailing address, AI writing context), define lists and tags, apply tags to existing contacts, draft content, and edit sequence A/B variant copy (cart and browse abandonment included) without live delivery, destructive deletes, team changes, API key creation, or changes to your account-wide sending defaults. It cannot add contacts to a list or remove them from one; those operations need subscribers:write, while deleting a definition needs the matching *:delete permission. Choose Full access when you intentionally want the agent to use the complete MCP surface, including sending, deletes, and administration. Use sender presets or custom scopes when the agent should send only specific kinds of email. Your workspace role still applies on top of the key. A personal key never does more than you can do in the dashboard, and a viewer is read-only however wide the key is.

Recover from missing permissions

When a tool reports a missing scope such as campaigns:read or templates:write, call get_account first. Its apiKeyPermissions field shows the effective preset, full-access state, scope counts and description, exact scopes, common missing marketing read scopes, live delivery state, and a direct manageUrl for the matching API Keys page. On the standard MCP surface it also includes the non-secret active-key identity. The OpenAI-reviewed surface omits the account user ID and active-key identity because they are not needed to plan the request; use list_api_keys and its isCurrent marker when a company key must be managed. Personal keys open the account-level page; company keys open the selected workspace’s page. Each company also includes a settingsUrl. If the key does not include account:read, get_account cannot return that metadata; open the Sequenzy dashboard directly and use the MCP setup or Settings → API Keys instead. You do not need a new key. Permissions are editable in place on the key the client already holds, so you can widen them mid-session without touching the MCP configuration or restarting the client. Open manageUrl, edit the connected key in the dashboard, and enable every scope named in the error - either by switching preset (Safer agent access covers common drafting, setup, list/tag-definition work, and sequence A/B variant copy; Read-only covers discovery) or by adding the individual scopes under Custom. Then retry the same tool call: the API reloads the key’s permissions whenever a request is denied, so the retry succeeds immediately. The key value never changes. An agent using a company key that holds api_keys:manage can do this itself by calling list_api_keys, choosing the entry where isCurrent is true, and passing that entry’s id to update_api_key. Personal keys must be edited on the account-level API Keys page; update_api_key only manages company keys. scopes and preset replace the whole selection rather than merging into it, so send every scope from apiKeyPermissions.scopes plus the missing ones. The default Safer agent access preset deliberately withholds api_keys:manage, so agents on that preset ask the workspace owner to make the edit. api_keys:manage is the one scope an agent cannot work around: the permission needed to widen a key is the permission that is missing. That is deliberate - otherwise a leaked operational key could mint a full-access successor for itself. Instead of guessing at the dashboard, call request_api_key_handoff. It returns a link that opens the create-key form with the name and permissions you asked for already filled in, so the owner only has to review and confirm. Add replaceApiKeyId: "current" to rotate the key you are authenticated with, and the dashboard offers to revoke it once the replacement exists. Nothing is created until the owner clicks Create, and the new key appears in their browser rather than in the tool result - so hand over the URL and stop rather than polling for a key that will never arrive. Replacing the key still works if you prefer it: create a new key with wider permissions, update SEQUENZY_API_KEY, and restart the client. For hosted OAuth MCP, you can also disconnect the Sequenzy connection and reauthorize it with a preset or custom permissions that include every scope named in the error. Removed permissions can lag by up to five minutes while API caches expire. Widened permissions do not - they apply on the next retry.

Check whether the key can send before you compose

Drafting permission and delivery permission are separate on purpose. A key can hold transactional:write (create and update transactional email templates) and still lack transactional:send (deliver a live email), which is exactly how the Safer agent access and AI drafting presets are built - they let an agent author content without being able to mail anyone. get_account reports this up front so you find out before writing the email rather than when the send is denied:
  • apiKeyPermissions.canSendLive - false when the key holds no live-delivery scope at all, so it can draft and manage content but cannot deliver anything.
  • apiKeyPermissions.missingLiveDeliveryScopes - the specific delivery paths the key lacks, such as transactional:send for send_email, campaigns:send for send_campaign, or sequences:activate for activating a sequence.
  • apiKeyPermissions.liveDeliveryBlockedByRole - true when the workspace role blocks sending regardless of scopes. A personal key inherits the user’s role, and a viewer is read-only however wide the key is.
  • apiKeyPermissions.roleRestrictedScopes - scopes the workspace role cannot use through a personal key. A marketer can send campaigns and activate sequences but lists transactional:send, team:manage, and the other workspace-management scopes here; widening the key does not change this.
Check these before composing anything intended to be sent. If the scope you need is listed, widen the key in place using the recovery steps - the draft you already have stays valid. If liveDeliveryBlockedByRole is true, widening the key will not help: ask the workspace owner for owner or admin access instead, or use a company key issued for that workspace.

Data and privacy

An MCP client receives only the result of the tool you ask it to call, within the workspace and permission scopes you approved. Depending on that request, the result can contain workspace identifiers and names, subscriber contact and consent data, custom business or marketing attributes, events and engagement, campaign or automation content, replies, surveys, commerce data, analytics, and integration or webhook status. Review the Privacy Policy before connecting an AI provider. Do not put individual-level payment-card data, health or medical data, government identifiers such as Social Security or passport numbers, biometric or genetic data, passwords or authentication secrets, sensitive demographic data, or precise geolocation into custom attributes, events, notes, variables, form fields, webhook samples, feedback, or other open-ended inputs. The OpenAI-reviewed surface at /v1/mcp/openai states that restriction on relevant open-ended fields and rejects obvious restricted fields and credential patterns before an API call, including nested attribute paths such as profile.ssn, coordinate pairs such as lat/lng, labelled prose such as Religion: ... or GPS coordinates: ..., and a credential-bearing URL in any argument, whether the credential sits in the userinfo, path, query, or fragment (for example a form redirectUrl with an access token or URL signature). Restricted attribute selectors inside merge tags are rejected without blocking ordinary authored copy about the same topic. render_email accepts a policy-checked inline subscriber on this surface, but not subscriberId, so it cannot resolve uninspected stored custom attributes. Stored credential-bearing URLs are redacted from its responses as well. It removes restricted fields, raw payloads, request and trace IDs, debug data, and unnecessary account or credential identifiers from responses. It does not expose connect_integration, create_api_key, create_webhook, inbound-secret rotation, or raw outbound webhook delivery tools. Use request_api_key_handoff, the Sequenzy dashboard, or the local CLI for those workflows. Feedback remains available with a reduced schema for generalized, explicitly requested product feedback. What the reviewed surface guarantees is bounded. It recognizes restricted data by shape: English field-name words such as passport_id, user.ssn, or api_secret at any nesting depth, labelled prose such as Diagnosis: ..., known credential shapes, decimal coordinate pairs, and credential-bearing URLs inside any string, including HTML. It does not interpret unlabelled prose, non-English field names, or values a client deliberately obfuscates; those remain covered by the usage restriction above rather than by the filter. The standard /mcp and /v1/mcp endpoints and the local stdio package retain the complete MCP contract for trusted clients. On those standard surfaces, connect_integration accepts provider credentials the user explicitly supplies, while create_api_key, create_webhook, and inbound-webhook setup can return a one-time secret or credential-bearing URL. Treat those results like credentials and prefer the dashboard or local CLI when secrets should stay outside the AI conversation. The OpenAI-reviewed route omits raw API error bodies and nested diagnostics; standard MCP retains detailed API errors for trusted-client debugging. submit_feedback sends data to the Sequenzy team only when the user explicitly asks; never include unrelated subscriber data, message content, credentials, or raw API payloads.

Key security

  • Personal API keys are tied to your user account
  • Keys can only access companies you have access to
  • You can revoke keys anytime in Settings → API Keys
  • Keys are never shared between users