Skip to main content

Who a connection acts as

  • A person, not a key. OAuth tokens and API keys belong to the person who created them. A connection reaches every enterprise that person belongs to, and nothing else; each call is checked against their membership, so it can never read or write another organization’s data.
  • Scopes. OAuth connections carry the scopes chosen at sign-in (read, build, sell, refer); API keys carry all four. A tool whose scope is missing is refused with insufficient_scope before it runs.
  • Hashed at rest. Keys and tokens are stored only as SHA-256 hashes. A key’s secret is shown once, when it is created.
  • Discovery is signed in. tools/list and tools/call need a valid credential; without one they answer 401 with the OAuth discovery header. initialize is open. The health check reveals nothing but whether the server is up.

Steps only a person takes

The server refuses these for every AI — Claude, ChatGPT, Grok, Cursor, or Earth Care Network’s own Jaguar — and answers {"error": "human_only", "detail": …, "portal_url": …} with the room where the person does it: Approve is not Publish: approve_outreach_draft without send marks a draft ready and sends nothing.

Drafts, and what applies at once

Much of what an AI writes waits for a person. Listing changes made with update_profile_draft wait for Publish. Site pages, sales funnels, articles, newsletter issues, social posts, outreach, invites, nominations and recruiting roles are drafts. A new form stays a draft until a person publishes it, and an automation stays off until a person switches it on in Routines. What an AI drafts is labelled seeded. compose_email is the one tool that can send at once, and only to members of your own team. To anyone else it becomes a draft in Approvals (/portal#approvals) and sends only when a person approves it there. Other writes take effect as soon as the tool runs. Grant build and sell only to an AI you trust with them. An AI cannot mark its own output verified, with one exception: set_brand_tokens marks the brand kit verified, because it is meant to carry colours a person chose.

Keys

An ecn_mcp_… key acts as you. Don’t commit it or paste it into a shared config; read it from an environment variable or a secret manager.
Remove the connector in your AI client to stop a connection at once. Revoke an API key in Settings → Developers (open it), or with DELETE /api/v1/mcp/keys/<key-id>/?organization_id=<org-id>. The portal does not list signed-in AI apps yet; to cut off an OAuth connection on our side too, write to hello@earthcare.network.

Reporting a vulnerability

Email security@earthcare.network — please don’t open a public issue with the details.