docs(TSP-1356): document MCP run-only access and Viewer role MCP support#733
docs(TSP-1356): document MCP run-only access and Viewer role MCP support#733claude[bot] wants to merge 1 commit into
Conversation
Expands the MCP server authentication section to document the OAuth consent flow and new Run-only access toggle introduced in PR #16022. Adds a roles & access levels table showing that Viewer-role users can now connect via MCP (locked to run-only mode) and that higher-privilege users can opt into run-only voluntarily. Updates the FAQ to mention the toggle alongside project separation as a way to restrict tool access. Updates the RBAC permissions table to reflect that Viewers can mint personal API keys for MCP OAuth connections, with a footnote explaining the MCP-specific scope and run-only restriction. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Workflows to automatically generate PRs for you. |
🎯 Vibe checkReviewed: 2 files (2 with issues, 0 clean) Scores
Score key: 🟢 9–10, 🟡 6–8, 🔴 1–5. ✨ Overall vibe: The core content is solid — the new Viewer MCP access and run-only toggle are documented accurately and the two files are consistent with each other. The main cleanup is mechanical: sentence case on two headings, retiring two accordion titles that use the banned word "powerful", and capitalizing Relevance AI product terms (Agents, Tools, Workforces, Knowledge) throughout 🔧 Issues (13)enterprise/rbac.mdx
integrations/mcp/mcp-server.mdx
🏗️ Page structure (1)
|
| Item | Count |
|---|---|
| Files reviewed | 2 |
| Context pages read | 2 |
| Total lines processed | ~1,060 |
Files read: enterprise/rbac.mdx (380 lines), integrations/mcp/mcp-server.mdx (357 lines), enterprise/user-level-authentication.mdx (220 lines), integrations/mcp/mcp-client.mdx (103 lines)
Summary
integrations/mcp/mcp-server.mdx): Expanded the Authentication section to document the OAuth consent flow and the new Run-only access toggle. Added a Roles & access levels table showing that Viewer-role users can now connect via MCP (locked to run-only) while Member/Editor/Admin users default to full access but can opt into run-only. Updated the FAQ answer for "Can I restrict which tools are available via MCP?" to mention the toggle alongside project separation.enterprise/rbac.mdx): Updated the project-level permissions table to show Viewers can mint a personal API key (✅†) for MCP OAuth connections. Added a footnote Note explaining this is MCP-specific and that Viewers connecting via MCP are automatically placed in run-only mode. Updated the Viewer role description to mention MCP run-only execution.Context
Implements documentation for PR #16022, which introduces:
Linear: https://linear.app/relevance/issue/TSP-1356/