Before connecting an AI assistant to your Craft.io data, you may want to understand how access, permissions, and data are handled. This article walks through how the Craft.io MCP server handles identity, permissions, administrative control, activity records, and data, so your security and IT teams have what they need to review it.
In this article:
What MCP changes and what it does not
The MCP server does not create any new access rights. It allows your AI assistant to work within your existing Craft.io permissions. Admins can restrict that access further. Anything done through MCP is the same as doing it yourself in the Craft.io UI.
Two points matter most for a security review:
Works within existing permissions. An MCP connection can only read or write what you can already read or write in the Craft.io UI.
No local installation. The Craft.io MCP server is hosted by Craft.io. There is nothing to install, and no software runs on your own systems.
What does change is that your AI assistant can take actions in Craft.io on your behalf, including creating and updating items. These actions always stay within your existing permissions and the admin controls described below.
Actions taken through MCP are recorded in the relevant item’s activity log, distinguishing them from actions performed directly by the user.
Identity and authentication
Each MCP connection uses OAuth and is tied to a specific Craft.io user. Users authenticate using their standard Craft.io sign-in. If your account requires SSO or SAML, the same requirement applies when connecting through MCP. This ensures that every connection is associated with an identifiable user.
MCP does not support shared credentials, or anonymous access. It does support service accounts for Server-to-Server (Machine-to-Machine) connections. They can be requested through your Customer Success Manager.
Session lifetime and revocation
MCP access tokens are valid for one hour. A rotating refresh token allows the connection to remain active for up to 90 days of inactivity.
Deactivating a user or removing their Craft.io seat ends their MCP access. Account admins can also disable MCP for the entire organization at any time. Changes take effect on the user’s next AI request.
Availability and requirements
MCP is available for Enterprise accounts and trials:
For Enterprise accounts, MCP is disabled by default and must be enabled by an account admin.
For trials, MCP is enabled automatically.
Users must have an editor seat. Contributor seats do not include MCP access.
Permissions and access scope
MCP follows the existing permissions of the connected Craft.io user. It cannot access data that the user does not already have permission to view or edit.
By default, the MCP connection provides read and write access to the workspaces, portfolios, and feedback portals available to that user.
Account admins can apply additional restrictions for individual users from the Account Manager:
Access level: Choose between read and write access or read-only access.
Scope: Allow access to all available spaces or limit it to selected workspaces, portfolios, and feedback portals.
Any changes take effect with the user’s next AI request.
Admin controls
Account admins manage MCP from Account Manager → Account settings. Control works at two levels:
Per account. Turn MCP on or off for your whole organization at any time. Changes take effect on the user's next AI request.
Per user. Grant or remove MCP access for individual users.
How MCP activity is recorded
Every action taken through MCP is recorded in the activity log on the item it affected, which you can see in the item panel in Craft.io.
Each entry shows:
The user the action was taken on behalf of
The action that was taken
A Via Agent label, which shows the action came from an AI assistant rather than directly from the user
The Via Agent label is worth highlighting for governance reviews. When an AI assistant acts on someone's behalf, that action is not hidden: it is fully attributable to the user and clearly marked as AI-initiated, right on the item.
How data is handled when using MCP
The MCP server is currently separate from Guru AI. It allows an AI tool selected by your organization - such as Claude, ChatGPT, Cursor, or VS Code - to access Craft.io through authenticated requests. Craft.io only returns data that the connected user has permission to access.
Once data is returned through MCP, it is processed by the selected AI provider according to its terms, retention policy, and data processing agreement. If your organization has an enterprise agreement with the provider, that agreement applies. If users connect through consumer accounts, the provider’s consumer terms apply.
We recommend reviewing your AI provider’s data-handling practices as part of your organization’s security assessment.
Data residency
Craft.io hosts your data in two regions, the US and the EU. Your MCP endpoint matches your hosting region:
If you connect to the endpoint for the wrong region, the connection simply fails. Your requests are never quietly routed to another region.
If you have specific data residency requirements, contact support@craft.io.
One thing to keep in mind: your hosting region controls where Craft.io stores and serves your data. It does not control where your AI provider processes that data once it reaches their tool. Both are worth covering in a residency review.
What an AI assistant can and cannot do
Through MCP, an AI assistant can read and write your product data within your permissions. Some actions are intentionally off-limits, no matter who is connected.
What MCP cannot do
Add, remove, or change users
Change account settings
Change billing or plan settings
Activity limits
MCP requests are subject to rate limits, which help prevent excessive or unexpected activity. These are separate from the account-level fair use policy, which is a commercial limit rather than a safety measure.
Shared responsibility
Security when using MCP is shared between Craft.io and your organization.
Craft.io is responsible for:
Authenticating each MCP connection to a specific Craft.io user, including enforcing SSO when it is required
Enforcing the user’s Craft.io permissions and any MCP-specific access restrictions
Identifying actions performed through MCP in the item activity log using the Via Agent label
Providing account-level and per-user controls for managing MCP access
Serving data from your organization’s Craft.io hosting region
Your organization is responsible for:
Deciding which AI tools users are permitted to connect
Reviewing the terms, retention policies, and data processing agreements of the selected AI providers
Determining which users should have MCP access and ensuring they have the appropriate Craft.io seats and permissions
Reviewing MCP activity as part of your regular access and security reviews
Quick reference for security reviewers
Question | Answer |
Is there a local agent or installed component? | No. The MCP server is hosted by Craft.io. |
How is the connection authenticated? | With OAuth and your own Craft.io session. |
Does SSO or SAML apply? | Yes. MCP uses the same sign-in as the Craft.io application. |
How long is a session valid? | Access tokens last one hour. Continued access is available for up to 90 days of inactivity. |
Can MCP access more than the user can? | No. It uses your existing permissions, and admins can narrow them further. |
What is the default access level? | Read and write, matching your UI permissions. Admins can set read-only access or limit scope to selected spaces for specific users. |
Can an admin disable MCP? | Yes, per account and per user, from the Account Manager. Changes take effect on the user's next AI request. |
Is MCP on by default? | Off by default for Enterprise accounts, and on automatically for trials. |
Are AI actions attributable? | Yes. They are recorded in the item activity log with a Via Agent label. |
Can an assistant change users or account settings? | No. |
Are there limits on how much an assistant can do? | Yes. Rate limits help prevent excessive or unexpected activity. |
Where is data hosted? | In the US or EU, matching your Craft.io region. Cross-region requests fail. |
Whose terms govern the AI side? | Your AI provider's terms, not Craft.io's. |
What comes next
Need more guidance? 🙋 Our LIVE support team (at the bottom right corner of your screen) replies to ANY question!

