Control what your AI assistant can access
Your AI assistant signs in to Chat Thing as you. It can never do more than your own account can, and you can cut off its access at any time from the Connect agent page.
There are two ways to connect:
| Method | Best for | How it works |
|---|---|---|
| Browser approval (OAuth) | Claude, ChatGPT, Cursor, Codex, VS Code and other assistants you use yourself | Your assistant opens a Chat Thing page, you click Approve, and it's issued a token automatically. Nothing to copy or store. |
| API key | Scripts, CI jobs, scheduled tasks and assistants that can't open a browser | You generate a key on the Connect agent page and add it to your client's config as a bearer token. |
Both methods give the same access.
What your assistant can access
Access follows your role in each team:
| Your role in a team | What your assistant can do in that team |
|---|---|
| Owner or Admin | Read and change bots, data sources, power-ups, channels, webhooks and tests |
| Any other role | Read bots, conversations and data sources, and chat with bots to test them |
This covers every team you belong to. There's no per-team choice when you approve: the approval page lists the teams the assistant will be able to reach.
Chatting with a bot uses tokens
When your assistant tests a bot by sending it messages, the replies use your team's message tokens, just like any other conversation. See Message tokens.
Approve an assistant in your browser
When an assistant connects for the first time, it finds Chat Thing's sign-in details on its own, registers itself and opens a page titled Authorize followed by the assistant's name. The page shows:
- which assistant is asking (for example, Claude or Cursor)
- what it will be able to do: read your bots, conversations and data sources, and create and edit bots in teams you own or administer
- the teams it will be able to reach
- the address it will return you to
Click Approve to connect, or Deny to refuse. If you deny, no access is granted.
Only approve connections you started
Any MCP client can ask for access, so the approval page is your safety check. Only approve a request you started yourself, from an assistant you recognise. If an approval page appears that you didn't expect, click Deny.
Use an API key
Use an API key when a browser approval isn't possible: CI pipelines, scripts, scheduled jobs or headless agents.
- In Chat Thing, open Connect agent from the sidebar (or go to Account and click Connect an agent).
- Under API key (CI / headless), click Generate API key.
- Copy the key straight away. You won't be able to see it again after you leave the page.
- Add it to your client's MCP config as a bearer token in the
Authorizationheader:
{
"mcpServers": {
"chatthing": {
"type": "http",
"url": "https://app.chatthing.ai/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}
The key is sent with every request, so there's no browser step. Each account has one MCP API key, and it belongs to you rather than to a single bot or team.
Treat the key like a password
Anyone with the key can act as you. Keep it in a secret manager or environment variable, never commit it to a repository, and regenerate it if it's ever exposed.
To replace the key, click Regenerate: the old key stops working. This MCP key is separate from the API channel secret key used by the REST Chat API.
Revoke access
On the Connect agent page:
- Connected agents lists every assistant you've approved in your browser. Click Revoke next to one to cut it off. It can't renew its access, and loses access completely when its current token expires, within an hour. You can reconnect it later.
- Under API key (CI / headless), click Revoke to disable your API key. Anything using it loses access immediately. You can generate a new key at any time.
Revoke an assistant whenever you stop using it.
Which should I use?
| Situation | Use |
|---|---|
| An assistant on your own computer or in your browser | Browser approval |
| A CI pipeline or scheduled job | API key |
| A client that can't open a browser | API key |
| You want to revoke one assistant without affecting others | Browser approval |
Troubleshooting
My assistant gets "Unauthorized"
The key or token wasn't accepted. If you use an API key, check it's sent as Authorization: Bearer <key> and hasn't been regenerated or revoked. If you connected in the browser, reconnect and approve again.
My assistant gets "Too many failed authentication attempts"
After 10 failed attempts within a minute from the same address, Chat Thing blocks further attempts from it for the rest of that minute. Fix the key, wait a minute and try again.
Related
- Connect your AI assistant to Chat Thing
Add the Chat Thing MCP server to Claude, ChatGPT, Cursor, Codex, VS Code, Windsurf, Zed or Cline and approve access in your browser.
- Manage your team and roles
Create a team, invite members, choose the right role (Owner, Admin, Responder or Viewer), remove people, and move bots between teams.
Last updated