Skip to content

Security and limits

What protects the community when an assistant operates through MCP. Authorization without a shared password, keys tied to the member and the community, revocation, the role checked on every call, the audit log, usage limits and what never appears in responses.

Connecting an assistant means giving it a key to act on your behalf. This article explains how that key is made, how far it opens, how it is cut off and what gets recorded.

In short

QuestionAnswer
Does the assistant know my password?No. You sign in to Memberfy itself; the assistant only receives an access key
Can it do more than I can?No. It uses your role, checked on every call
Does it see other communities?No. One connection, one community
Does it touch money or delete things on its own?No. Every money action and every deletion asks for your yes, with a summary
Can I cut off access?Yes, instantly: you in My Account › AI assistants, or the owner and admins in Settings
Is it recorded?Yes, every tool call

Authorization, in plain language

The connection uses OAuth 2.1, the same standard as "Sign in with Google":

  1. The assistant asks for access and sends you to Memberfy.
  2. You sign in to Memberfy, not to the assistant, and say yes on the consent screen.
  3. Memberfy gives the assistant an access key that only works for that connection.

Your password never passes through the assistant. The exchange uses PKCE, which guarantees the key can only be collected by whoever started the request: someone who intercepts it along the way can't use it. The consent screen only sends you back to the address the assistant registered, and shows that address ("Afterwards, you go back to…").

The keys

KeyValid forWhat happens
Authorization code10 minutes, onceExchanged for the access key right after your yes
Access key1 hourThe assistant renews it on its own, without you noticing
Refresh key30 daysReplaced by a new one on every use. If a key that was already used shows up again, Memberfy assumes it leaked and shuts down the whole connection

Memberfy stores the keys only as a hash (an irreversible fingerprint): not even Memberfy can read them once issued.

One connection, one community, one person

Each connection is the combination of you, one community and one assistant. The key doesn't open another community, or someone else's. Connecting Claude and ChatGPT, or two communities, means separate connections, each of which can be disconnected on its own.

The role, on every call

The assistant has no permissions of its own. Each tool calls Memberfy as you, with your role at that moment, and goes through the same checks as the screen:

  • if your role changes in the dashboard, the assistant changes with it, on the next call;
  • if you leave the community, or are removed, the assistant stops working there;
  • each space's rules (visibility, Who can post) apply the same way.

The list of tools the assistant sees is already filtered by role, but Memberfy decides on every call. See Tools.

What never comes out

  • Internal payment processing costs, their breakdown and margins. For amounts, the platform fee appears, as in the dashboard. Besides the routes not returning those fields, the MCP server has a second lock that strips them from any response.
  • What your role doesn't see. A member doesn't read sales; a moderator doesn't read the statement.
  • Data from other communities.

Money

The money tools and the deletion tools (delete_, remove_, revoke_, withdraw_, cancel_) act in two steps: a summary with the amounts and a 10-minute, single-use code tied to those same amounts. See Money and confirmation.

Revocation

WhoWhereEffect
YouMy Account › AI assistants (/account?tab=assistants), DisconnectCuts off your connection instantly
Owner and adminsSettings › AI assistants, DisconnectCuts off anyone's connection to that community
MemberfyOn its ownWhen you leave the community, when the refresh key goes 30 days unused, or when an already used key reappears

Disconnecting invalidates every key on that connection: the assistant's next call is refused.

Audit

Every tool call is recorded and linked to the connection: the tool, the values sent (without confirmation codes), the result (done, error, refused, awaiting confirmation, limit reached), Memberfy's response and how long it took. The connection's events are recorded too: when it was authorized, renewed and disconnected.

  • What the assistant did shows up in the dashboard, in Members › Logs, source AI assistant: each connection, each tool used and each refused action, with the status, the duration and the summarized arguments (no tokens, images or secrets). Only the owner and admins see it. See Activity logs.
  • The owner and admins can also look up the community's audit log through the API, at GET /api/oauth/audit, or through the assistant itself, with list_activity_logs.
  • Besides tool calls, the audit logs session.initialize (the assistant opened the connection), tools.list (it asked for the tool list) and tool.unknown (it called a tool that isn't on its list), with the assistant, the server version, the tools_fingerprint and the number of tools.
  • For a single connection, GET /api/oauth/connections/{id}/diagnostics shows the last list delivered, the current one and, in listUpToDate, whether the assistant is up to date. Also owner and admins only.
  • The conversation itself (what you wrote to the assistant) stays with the assistant, not with Memberfy.
  • What the assistant creates appears in the dashboard under your name, as if you had done it; subscription cancellations also appear on the timeline in subscription management.

Limits

LimitValueWhat happens when exceeded
Tool calls per connection120 per minute"Too many calls in a short time. Wait a minute and try again."
Assistant registrations per network address20 per hourThe registration is refused; try later
Key exchanges per network address60 per minuteThe exchange is refused; the assistant tries again
Confirmation code lifetime10 minutesThe code expires; a new summary is generated
Items in the composite toolsUp to 30 modules per course, 50 lessons per module, 6 options per planThe call is refused before anything is created

Good practices for the team

  • Connect with the smallest role that does the job. For reports, a finance account; for content, a moderator.
  • Review the list from time to time. Settings › AI assistants shows each connection's last use: disconnect what nobody uses.
  • When someone leaves the team, demote or remove them: their assistant loses access along with them.
  • Read every money or deletion summary before you say yes.
  • In the assistant, only set as always allowed the tools you don't need to review. Invites and issuing certificates send e-mail on the first call; see The assistant's permission.