3
Add admin controls for MCP tools when using OAuth
Source: outline/outline#12899 · opened by @HesamZamanpour
Problem When MCP uses OAuth, each user connects with their own Outline permissions. This means an MCP client may be able to create, edit, move, delete, comment, or attach files if the user normally has those permissions in Outline. Restricted API keys do not solve this OAuth case, because API keys are not used. I have searched for similar issues/discussions and found #11805, which asks for read-only MCP access. However, that discussion suggests restricted API keys as a workaround, which does not solve OAuth-based MCP access. Request Please add admin controls for MCP tool permissions when OAuth is used. For example, admins should be able to: • Enable read/search MCP tools • Disable write tools such as create, update, move, delete, comments, and attachments • Or manage these as separate MCP tools, so each capability can be enabled or disabled individually Why this matters This would let admins safely enable MCP for knowledge retrieval witho…
No pledges yet. Be the first to back this.
Comments
Similar requests
Add `get_attachment` MCP tool for downloading attachment content
2 votes · 0 comments
MCP: Allow API-key auth other than just OAuth
2 votes · 0 comments
A batch moving mcp tool
1 vote · 0 comments
Allow configurable session expiration for MCP server authentication
2 votes · 0 comments
MCP — support end-to-end attachment upload (not just presign) so clients don't need a separate API key
1 vote · 0 comments
No comments yet.