AI connections (MCP)
MCP permissions
Grant only the Beacon permissions that an AI client needs for its tasks.
Beacon uses OAuth browser sign-in for hosted MCP connections. OAuth is a standard process for approved account access.
Available access
| Permission | Allowed task |
|---|---|
beacon:channels:read | Read channels and provider requirements. |
beacon:calendar:read | Read scheduled and attention-required posts. |
beacon:media:read | List and inspect workspace media. |
beacon:posts:read | Read post details. |
beacon:posts:write | Create drafts, scheduled posts, and immediate requests. |
beacon:ai:generate | Generate post drafts and images with AI credits. |
Identity access can also include openid and profile. offline_access lets a compatible client refresh access.
Limit access
- Identify the required Beacon task.
- Grant only the permissions for that task.
- Review the selected workspace.
- Complete browser sign-in.
Write access has a 15-minute lifetime. A compatible client can refresh it after user-approved sign-in.
Revoke a connection
- Open Settings in Beacon.
- Select Developer.
- Find Connected applications.
- Disconnect the required application.
Revocation takes effect immediately.