Dynamic permissions#
Discovered MCP tools participate in the ordinary registry, RBAC and approval pipeline. The exact permission pattern is:
mcp.<server_token>.tool.<remote_token>Tokens derive from the normalized local action. Inspect the discovered permission rather than constructing an identifier from an assumed remote spelling. When discovered definitions exist, they replace the static fallback mcp.use declaration.
Allow, deny and approval#
Role effects are allow, deny and require_approval. Deny takes precedence; approval requirements can raise execution policy. Different users can therefore receive different execution decisions for the same tool.
Visibility is different from execution#
Personal credentials#
On a per_user HTTP profile, execution resolves the current actor's OAuth credential. Missing or failed personal credentials do not fall back to a shared administrator bearer. Profile discovery still has the limitations described in MCP servers.
Approval metadata#
Operator-configured read-only servers use READ/POLICY metadata. Other MCP tools use CHANGE/ALWAYS and request approval. RBAC can deny either type or add approval requirements.
Read Roles & Permissions for scopes, precedence and the full static permission matrix.