# MCP permissions

Grant only the Beacon permissions that an AI client needs for its tasks.

Beacon uses OAuth browser sign-in for hosted MCP connections. OAuth is a standard process for approved account access.

## Available access

| Permission             | Allowed task                                            |
| ---------------------- | ------------------------------------------------------- |
| `beacon:channels:read` | Read channels and provider requirements.                |
| `beacon:calendar:read` | Read scheduled and attention-required posts.            |
| `beacon:media:read`    | List and inspect workspace media.                       |
| `beacon:posts:read`    | Read post details.                                      |
| `beacon:posts:write`   | Create drafts, scheduled posts, and immediate requests. |
| `beacon:ai:generate`   | Generate post drafts and images with AI credits.        |

Identity access can also include `openid` and `profile`. `offline_access` lets a compatible client refresh access.

## Limit access

1. Identify the required Beacon task.
2. Grant only the permissions for that task.
3. Review the selected workspace.
4. Complete browser sign-in.

Write access has a 15-minute lifetime. A compatible client can refresh it after user-approved sign-in.

## Revoke a connection

1. Open **Settings** in Beacon.
2. Select **Developer**.
3. Find **Connected applications**.
4. Disconnect the required application.

Revocation takes effect immediately.
