> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sequenzy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP Permissions and Privacy

> Choose what your AI assistant can do in Sequenzy, widen permissions without reconnecting, and understand what data MCP clients receive

Every MCP connection acts through a Sequenzy API key or OAuth grant with a
specific set of permissions. This page explains which preset to pick, how to
fix a missing permission mid-conversation, and what data your AI provider can
see. To connect in the first place, start with [Connect AI assistants](/concepts/mcp).

## Choose a permission preset

You pick a preset when you approve a remote connector, run `npx @sequenzy/setup`
or create a key in **AI Agent Setup**. You can change it later on the same key.

| Preset | What the assistant can do |
| - | - |
| **Safer agent access** (default) | Inspect data, define lists and tags, tag existing contacts, complete workspace setup and draft content. No live delivery, list membership changes, deletes, team changes or API key creation |
| **AI drafting** | Inspect data, build subscriber lists, complete workspace setup and draft campaigns, sequences and templates. No live delivery |
| **Marketing sender** | Complete workspace setup, and manage and send campaigns and live sequences |
| **Transactional sender** | Manage transactional templates and send through the transactional API |
| **Full access** | Everything, including sending, settings, API keys and deletes |

Under **Account Settings → API Keys** you can also choose **Read-only**, the
data-ingest presets or individual scopes under **Custom**.

### What Safer agent access covers

For MCP authorization and generated local MCP keys, **Safer agent access** is the default. It lets the agent inspect data, complete workspace setup (name, branding, mailing address, AI writing context), define lists and tags, apply tags to existing contacts, draft content, and edit sequence A/B variant copy (cart and browse abandonment included) without live delivery, destructive deletes, team changes, API key creation, or changes to your account-wide sending defaults. It cannot add contacts to a list or remove them from one; those operations need `subscribers:write`, while deleting a definition needs the matching `*:delete` permission. Choose **Full access** when you intentionally want the agent to use the complete MCP surface, including sending, deletes, and administration. Use sender presets or custom scopes when the agent should send only specific kinds of email.

Your workspace role still applies on top of the key. A personal key never does more than you can do in the dashboard, and a `viewer` is read-only however wide the key is.

## Recover from missing permissions

When a tool reports a missing scope such as `campaigns:read` or
`templates:write`, call `get_account` first. Its `apiKeyPermissions` field shows
the effective preset, full-access state, scope counts and description, exact
scopes, common missing marketing read scopes, live delivery state, and a direct
`manageUrl` for the matching API Keys page. On the standard MCP surface it also
includes the non-secret active-key identity. The OpenAI-reviewed surface omits
the account user ID and active-key identity because they are not needed to plan
the request; use `list_api_keys` and its `isCurrent` marker when a company key
must be managed. Personal keys open the account-level page; company keys open
the selected workspace's page. Each company also includes a `settingsUrl`. If
the key does not include `account:read`,
`get_account` cannot return that metadata; open the
[Sequenzy dashboard](https://sequenzy.com/dashboard) directly and use the MCP
setup or **Settings → API Keys** instead.

You do not need a new key. Permissions are editable in place on the key the
client already holds, so you can widen them mid-session without touching the MCP
configuration or restarting the client.

Open `manageUrl`, edit the connected key in the dashboard, and enable every scope named in the error - either by
switching preset (**Safer agent access** covers common drafting, setup,
list/tag-definition work, and sequence A/B variant copy; **Read-only** covers discovery) or by adding the individual scopes
under **Custom**. Then retry the same tool call: the API reloads the key's
permissions whenever a request is denied, so the retry succeeds immediately. The
key value never changes.

An agent using a `company` key that holds `api_keys:manage` can do this itself
by calling `list_api_keys`, choosing the entry where `isCurrent` is true, and
passing that entry's `id` to `update_api_key`. Personal keys must be edited on
the account-level API Keys page; `update_api_key` only manages company keys.
`scopes` and `preset` replace the whole selection rather than merging into it, so
send every scope from `apiKeyPermissions.scopes` plus the missing ones. The
default **Safer agent access** preset deliberately withholds `api_keys:manage`,
so agents on that preset ask the workspace owner to make the edit.

`api_keys:manage` is the one scope an agent cannot work around: the permission
needed to widen a key is the permission that is missing. That is deliberate -
otherwise a leaked operational key could mint a full-access successor for
itself. Instead of guessing at the dashboard, call `request_api_key_handoff`. It
returns a link that opens the create-key form with the name and permissions you
asked for already filled in, so the owner only has to review and confirm. Add
`replaceApiKeyId: "current"` to rotate the key you are authenticated with, and
the dashboard offers to revoke it once the replacement exists. Nothing is
created until the owner clicks Create, and the new key appears in their browser
rather than in the tool result - so hand over the URL and stop rather than
polling for a key that will never arrive.

Replacing the key still works if you prefer it: create a new key with wider
permissions, update `SEQUENZY_API_KEY`, and restart the client. For hosted OAuth
MCP, you can also disconnect the Sequenzy connection and reauthorize it with a
preset or custom permissions that include every scope named in the error.

Removed permissions can lag by up to five minutes while API caches expire.
Widened permissions do not - they apply on the next retry.

## Check whether the key can send before you compose

Drafting permission and delivery permission are separate on purpose. A key can
hold `transactional:write` (create and update transactional email templates) and
still lack `transactional:send` (deliver a live email), which is exactly how the
**Safer agent access** and **AI drafting** presets are built - they let an agent
author content without being able to mail anyone.

`get_account` reports this up front so you find out before writing the email
rather than when the send is denied:

* `apiKeyPermissions.canSendLive` - `false` when the key holds no live-delivery
  scope at all, so it can draft and manage content but cannot deliver anything.
* `apiKeyPermissions.missingLiveDeliveryScopes` - the specific delivery paths
  the key lacks, such as `transactional:send` for `send_email`, `campaigns:send`
  for `send_campaign`, or `sequences:activate` for activating a sequence.
* `apiKeyPermissions.liveDeliveryBlockedByRole` - `true` when the workspace role
  blocks sending regardless of scopes. A personal key inherits the user's role,
  and a `viewer` is read-only however wide the key is.
* `apiKeyPermissions.roleRestrictedScopes` - scopes the workspace role cannot
  use through a personal key. A `marketer` can send campaigns and activate
  sequences but lists `transactional:send`, `team:manage`, and the other
  workspace-management scopes here; widening the key does not change this.

Check these before composing anything intended to be sent. If the scope you need
is listed, widen the key in place using the [recovery steps](#recover-from-missing-permissions) - the draft you already
have stays valid. If `liveDeliveryBlockedByRole` is `true`, widening the key will
not help: ask the workspace owner for owner or admin access instead, or use a
company key issued for that workspace.

## Data and privacy

An MCP client receives only the result of the tool you ask it to call, within
the workspace and permission scopes you approved. Depending on that request,
the result can contain workspace identifiers and names, subscriber contact and
consent data, custom business or marketing attributes, events and engagement,
campaign or automation content, replies, surveys, commerce data, analytics, and
integration or webhook status. Review the [Privacy Policy](https://www.sequenzy.com/privacy)
before connecting an AI provider.

Do not put individual-level payment-card data, health or medical data,
government identifiers such as Social Security or passport numbers, biometric
or genetic data, passwords or authentication secrets, sensitive demographic
data, or precise geolocation into custom attributes, events, notes, variables,
form fields, webhook samples, feedback, or other open-ended inputs.

The OpenAI-reviewed surface at `/v1/mcp/openai` states that restriction on
relevant open-ended fields and rejects obvious restricted fields and credential
patterns before an API call, including nested attribute paths such as
`profile.ssn`, coordinate pairs such as `lat`/`lng`, labelled prose such as
`Religion: ...` or `GPS coordinates: ...`, and a credential-bearing URL in any
argument, whether the credential sits in the userinfo, path, query, or fragment
(for example a form `redirectUrl` with an access token or URL signature).
Restricted attribute selectors inside merge tags are rejected without blocking
ordinary authored copy about the same topic. `render_email` accepts a
policy-checked inline `subscriber` on this surface, but not `subscriberId`, so
it cannot resolve uninspected stored custom attributes. Stored
credential-bearing URLs are redacted from its responses as well. It removes restricted fields, raw payloads,
request and trace IDs, debug data, and unnecessary account or credential
identifiers from responses. It does not expose `connect_integration`,
`create_api_key`, `create_webhook`, inbound-secret rotation, or raw outbound
webhook delivery tools. Use `request_api_key_handoff`, the Sequenzy dashboard,
or the local CLI for those workflows. Feedback remains available with a reduced
schema for generalized, explicitly requested product feedback.

What the reviewed surface guarantees is bounded. It recognizes restricted data
by shape: English field-name words such as `passport_id`, `user.ssn`, or
`api_secret` at any nesting depth, labelled prose such as `Diagnosis: ...`,
known credential shapes, decimal coordinate pairs, and credential-bearing URLs
inside any string, including HTML. It does not interpret unlabelled prose,
non-English field names, or values a client deliberately obfuscates; those
remain covered by the usage restriction above rather than by the filter.

The standard `/mcp` and `/v1/mcp` endpoints and the local stdio package retain
the complete MCP contract for trusted clients. On those standard surfaces,
`connect_integration` accepts provider credentials the user explicitly supplies,
while `create_api_key`, `create_webhook`, and inbound-webhook setup can return a
one-time secret or credential-bearing URL. Treat those results like credentials
and prefer the dashboard or local CLI when secrets should stay outside the AI
conversation. The OpenAI-reviewed route omits raw API error bodies and nested
diagnostics; standard MCP retains detailed API errors for trusted-client
debugging. `submit_feedback` sends data to the Sequenzy team only when the user
explicitly asks; never include unrelated subscriber data, message content,
credentials, or raw API payloads.

## Key security

* Personal API keys are tied to your user account
* Keys can only access companies you have access to
* You can revoke keys anytime in Settings → API Keys
* Keys are never shared between users


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.