MCP server

Safety and limits

How keys, scopes, confirmations, rate limits and logging keep assistant access predictable.

Keys and scopes

ScopeTools advertisedUse it for
readRead tools onlyAnalysis, reporting, day-to-day questions.
writeRead plus action toolsSupervised production work.
*EverythingTrusted internal automation only.
  • Keys are stored hashed; the full value is shown once at creation.
  • Access is default-deny, a key with no scopes can do nothing.
  • Keys are scoped to specific clients, so an assistant cannot wander across your book of business.
  • Revoking a key takes effect immediately on the next tool call.

Actions that require confirmation

Anything that is visible outside your workspace is treated as destructive and is confirmed with a human before it runs, even with a write key.

  • deploy_article, publishes to the live site.
  • send_prospect_email, sends mail from your domain.
  • index_url, submits URLs to search engines.

Rate limits and long jobs

  • Limits are per key. A 429 response carries a retry hint; retry with exponential backoff rather than in a tight loop.
  • Audits, article generation and grid scans are asynchronous. The action returns an ID; poll the matching read tool.
  • Repeating an action with the same inputs can create a duplicate job. Pass your own idempotency key when the action supports it.

What gets logged

  • Every gateway call records the key used, the action, the client and the outcome.
  • Assistant-initiated work is auditable the same way as work done in the UI.
  • Nothing is logged that the key could not already read.

Frequently asked

Can the assistant see clients I did not grant?

No. The gateway checks the key against the client on every request and returns 403 otherwise.

Does my client data get used to train a model?

The MCP server sends data to whichever AI client you connect. Check that vendor's data policy. AgentixSEO does not train on your data.

Can I run it read-only for the whole team?

Yes, and it is the recommended default: one shared read key for analysis, separate write keys held by the people who publish.

What happens if the assistant hallucinates a client ID?

The gateway rejects unknown IDs with 400 or 403. No partial write happens.

Can I use this today?

Yes. Create an API key, add the server to your client as shown in Connect, and start asking.

Was this page helpful?