Security
Authentication, permissions, approval, auditing, and revoking access for the MCP connection.
Authentication
Solk MCP works only with OAuth 2.1 (or with an API key created by an admin). Your password is never given to the assistant or the client: the client redirects you to your Solk installation's own sign-in and consent pages, and once you grant access, it receives a short-lived access token.
| Access token | 1 hour |
| Refresh token | 60 days; rotated on every refresh |
| PKCE | Required (S256) |
| Redirect URIs | https:// and loopback only |
| Token storage | The server stores only a SHA-256 hash |
Permissions
The assistant works under your account:
- Your role (admin / sales), your module permissions, and record visibility all apply as is. If you connected as a sales rep, the assistant sees only what you can see.
- Email content is returned according to the mailbox owner's sharing settings; the text of messages you aren't allowed to see is never given to the assistant.
- Scopes are separate: if you grant only
crm.read, the assistant can't change any records. - No tool deletes records.
Approval
Claude asks for permission the first time it uses a tool. Because read tools are marked "read-only", you can grant them permanent permission; for write tools, we recommend having Claude ask for approval on every call. Organization owners can restrict which tools are available in Claude's admin settings.
Auditing
- Every tool call is recorded in the Solk audit log with the user, the tool name, and the connected app's name.
- Records created by write tools appear with their owner and timestamp, just as if they had been created in the web app; the same events are sent to integrations (Slack, webhooks…).
- Settings → App connections (Ayarlar → Uygulama bağlantıları) shows each app's connection date, last use, and operation count.
Revoking access
| Who | How |
|---|---|
| User | Settings → App connections → Remove access (Ayarlar → Uygulama bağlantıları → Erişimi kaldır) — all of that app's tokens are revoked immediately. |
| Admin | Deactivating the user cuts off all of their connections. |
| On the Claude side | Remove the connector from the Connectors list, or click Disconnect. |
Data processing
The MCP server runs inside your installation; there's no additional intermediary service. Data the assistant reads is sent to the AI service you use (for example, Anthropic) under that service's terms. Decide which users can connect based on your organization's AI usage policy.