Generate a token
mcp plan, mcp apply, or mcp list as MCP_ID. The token field in the response is the execution token.
Anything absent from allow is denied. Omit the scope to grant every operation exposed by the MCP server.
Bind the token to a connected user
A fixed binding pins the token to a service, auth scheme, and connected-user reference. Add a resource UUID when the provider connection exposes selectable resources.--fixed-binding or add more objects to bindings when the agent uses multiple services. The stored binding remains authoritative if a request supplies a different selector.
List or revoke tokens
app.tokens.manage.
Tokens for OAuth services
Choose between fixed and caller-selected connected users.