Log in

Control what your AI assistant can access

Your AI assistant signs in to Chat Thing as you. It can never do more than your own account can, and you can cut off its access at any time from the Connect agent page.

There are two ways to connect:

MethodBest forHow it works
Browser approval (OAuth)Claude, ChatGPT, Cursor, Codex, VS Code and other assistants you use yourselfYour assistant opens a Chat Thing page, you click Approve, and it's issued a token automatically. Nothing to copy or store.
API keyScripts, CI jobs, scheduled tasks and assistants that can't open a browserYou generate a key on the Connect agent page and add it to your client's config as a bearer token.

Both methods give the same access.

What your assistant can access

Access follows your role in each team:

Your role in a teamWhat your assistant can do in that team
Owner or AdminRead and change bots, data sources, power-ups, channels, webhooks and tests
Any other roleRead bots, conversations and data sources, and chat with bots to test them

This covers every team you belong to. There's no per-team choice when you approve: the approval page lists the teams the assistant will be able to reach.

🚨

Chatting with a bot uses tokens

When your assistant tests a bot by sending it messages, the replies use your team's message tokens, just like any other conversation. See Message tokens.

Approve an assistant in your browser

When an assistant connects for the first time, it finds Chat Thing's sign-in details on its own, registers itself and opens a page titled Authorize followed by the assistant's name. The page shows:

  • which assistant is asking (for example, Claude or Cursor)
  • what it will be able to do: read your bots, conversations and data sources, and create and edit bots in teams you own or administer
  • the teams it will be able to reach
  • the address it will return you to

Click Approve to connect, or Deny to refuse. If you deny, no access is granted.

🚨

Only approve connections you started

Any MCP client can ask for access, so the approval page is your safety check. Only approve a request you started yourself, from an assistant you recognise. If an approval page appears that you didn't expect, click Deny.

Use an API key

Use an API key when a browser approval isn't possible: CI pipelines, scripts, scheduled jobs or headless agents.

  1. In Chat Thing, open Connect agent from the sidebar (or go to Account and click Connect an agent).
  2. Under API key (CI / headless), click Generate API key.
  3. Copy the key straight away. You won't be able to see it again after you leave the page.
  4. Add it to your client's MCP config as a bearer token in the Authorization header:
{
  "mcpServers": {
    "chatthing": {
      "type": "http",
      "url": "https://app.chatthing.ai/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

The key is sent with every request, so there's no browser step. Each account has one MCP API key, and it belongs to you rather than to a single bot or team.

🚨

Treat the key like a password

Anyone with the key can act as you. Keep it in a secret manager or environment variable, never commit it to a repository, and regenerate it if it's ever exposed.

To replace the key, click Regenerate: the old key stops working. This MCP key is separate from the API channel secret key used by the REST Chat API.

Revoke access

On the Connect agent page:

  • Connected agents lists every assistant you've approved in your browser. Click Revoke next to one to cut it off. It can't renew its access, and loses access completely when its current token expires, within an hour. You can reconnect it later.
  • Under API key (CI / headless), click Revoke to disable your API key. Anything using it loses access immediately. You can generate a new key at any time.

Revoke an assistant whenever you stop using it.

Which should I use?

SituationUse
An assistant on your own computer or in your browserBrowser approval
A CI pipeline or scheduled jobAPI key
A client that can't open a browserAPI key
You want to revoke one assistant without affecting othersBrowser approval

Troubleshooting

My assistant gets "Unauthorized"

The key or token wasn't accepted. If you use an API key, check it's sent as Authorization: Bearer <key> and hasn't been regenerated or revoked. If you connected in the browser, reconnect and approve again.

My assistant gets "Too many failed authentication attempts"

After 10 failed attempts within a minute from the same address, Chat Thing blocks further attempts from it for the rest of that minute. Fix the key, wait a minute and try again.

  • Connect your AI assistant to Chat Thing

    Add the Chat Thing MCP server to Claude, ChatGPT, Cursor, Codex, VS Code, Windsurf, Zed or Cline and approve access in your browser.

  • Manage your team and roles

    Create a team, invite members, choose the right role (Owner, Admin, Responder or Viewer), remove people, and move bots between teams.

Last updated