---
title: "Control what your AI assistant can access"
description: "How AI assistants sign in to Chat Thing, what they can read and change, how to use an API key for scripts and CI, and how to revoke access."
canonical_url: "https://chatthing.ai/docs/mcp/authentication"
last_updated: "2026-09-25"
---

# Control what your AI assistant can access

Your AI assistant signs in to Chat Thing as you. It can never do more than your own account can, and you can cut off its access at any time from the **Connect agent** page.

There are two ways to connect:

| Method | Best for | How it works |
| --- | --- | --- |
| **Browser approval** (OAuth) | Claude, ChatGPT, Cursor, Codex, VS Code and other assistants you use yourself | Your assistant opens a Chat Thing page, you click **Approve**, and it's issued a token automatically. Nothing to copy or store. |
| **API key** | Scripts, CI jobs, scheduled tasks and assistants that can't open a browser | You generate a key on the **Connect agent** page and add it to your client's config as a bearer token. |

Both methods give the same access.

## What your assistant can access

Access follows your role in each [team](https://chatthing.ai/docs/account/teams):

| Your role in a team | What your assistant can do in that team |
| --- | --- |
| **Owner** or **Admin** | Read and change bots, data sources, power-ups, channels, webhooks and tests |
| Any other role | Read bots, conversations and data sources, and chat with bots to test them |

This covers every team you belong to. There's no per-team choice when you approve: the approval page lists the teams the assistant will be able to reach.

> **Chatting with a bot uses tokens**
>
> When your assistant tests a bot by sending it messages, the replies use your team's message tokens, just like any other conversation. See [Message tokens](https://chatthing.ai/docs/account/message-tokens).

## Approve an assistant in your browser

When an assistant connects for the first time, it finds Chat Thing's sign-in details on its own, registers itself and opens a page titled **Authorize** followed by the assistant's name. The page shows:

- which assistant is asking (for example, Claude or Cursor)
- what it will be able to do: read your bots, conversations and data sources, and create and edit bots in teams you own or administer
- the teams it will be able to reach
- the address it will return you to

Click **Approve** to connect, or **Deny** to refuse. If you deny, no access is granted.

> **Only approve connections you started**
>
> Any MCP client can ask for access, so the approval page is your safety check. Only approve a request you started yourself, from an assistant you recognise. If an approval page appears that you didn't expect, click **Deny**.

## Use an API key

Use an API key when a browser approval isn't possible: CI pipelines, scripts, scheduled jobs or headless agents.

1. In Chat Thing, open **Connect agent** from the sidebar (or go to **Account** and click **Connect an agent**).
2. Under **API key (CI / headless)**, click **Generate API key**.
3. Copy the key straight away. You won't be able to see it again after you leave the page.
4. Add it to your client's MCP config as a bearer token in the `Authorization` header:

```json
{
  "mcpServers": {
    "chatthing": {
      "type": "http",
      "url": "https://app.chatthing.ai/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}
```

The key is sent with every request, so there's no browser step. Each account has one MCP API key, and it belongs to you rather than to a single bot or team.

> **Treat the key like a password**
>
> Anyone with the key can act as you. Keep it in a secret manager or environment variable, never commit it to a repository, and regenerate it if it's ever exposed.

To replace the key, click **Regenerate**: the old key stops working. This MCP key is separate from the [API channel secret key](https://chatthing.ai/docs/developers/api-overview#authentication) used by the REST Chat API.

## Revoke access

On the **Connect agent** page:

- **Connected agents** lists every assistant you've approved in your browser. Click **Revoke** next to one to cut it off. It can't renew its access, and loses access completely when its current token expires, within an hour. You can reconnect it later.
- Under **API key (CI / headless)**, click **Revoke** to disable your API key. Anything using it loses access immediately. You can generate a new key at any time.

Revoke an assistant whenever you stop using it.

## Which should I use?

| Situation | Use |
| --- | --- |
| An assistant on your own computer or in your browser | Browser approval |
| A CI pipeline or scheduled job | API key |
| A client that can't open a browser | API key |
| You want to revoke one assistant without affecting others | Browser approval |

## Troubleshooting

### My assistant gets "Unauthorized"

The key or token wasn't accepted. If you use an API key, check it's sent as `Authorization: Bearer <key>` and hasn't been regenerated or revoked. If you connected in the browser, reconnect and approve again.

### My assistant gets "Too many failed authentication attempts"

After 10 failed attempts within a minute from the same address, Chat Thing blocks further attempts from it for the rest of that minute. Fix the key, wait a minute and try again.

## Related

- [Connect your AI assistant to Chat Thing](https://chatthing.ai/docs/mcp/connect): Add the Chat Thing MCP server to Claude, ChatGPT, Cursor, Codex, VS Code, Windsurf, Zed or Cline and approve access in your browser.
- [Manage your team and roles](https://chatthing.ai/docs/account/teams): Create a team, invite members, choose the right role (Owner, Admin, Responder or Viewer), remove people, and move bots between teams.
