# Security and limits

> What protects the community when an assistant operates through MCP. Authorization without a shared password, keys tied to the member and the community, revocation, the role checked on every call, the audit log, usage limits and what never appears in responses.

Connecting an assistant means giving it a key to act on your behalf. This article explains how that key is made, how far it opens, how it is cut off and what gets recorded.

## In short

| Question | Answer |
|---|---|
| Does the assistant know my password? | No. You sign in to Memberfy itself; the assistant only receives an access key |
| Can it do more than I can? | No. It uses your role, checked on every call |
| Does it see other communities? | No. One connection, one community |
| Does it touch money or delete things on its own? | No. Every money action and every deletion asks for your yes, with a summary |
| Can I cut off access? | Yes, instantly: you in **My Account › AI assistants**, or the owner and admins in **Settings** |
| Is it recorded? | Yes, every tool call |

## Authorization, in plain language

The connection uses **OAuth 2.1**, the same standard as "Sign in with Google":

1. The assistant asks for access and sends you to Memberfy.
2. You sign in **to Memberfy**, not to the assistant, and say yes on the [consent screen](/mcp/autorizar-e-desconectar#the-consent-screen).
3. Memberfy gives the assistant an **access key** that only works for that connection.

Your password never passes through the assistant. The exchange uses **PKCE**, which guarantees the key can only be collected by whoever started the request: someone who intercepts it along the way can't use it. The consent screen only sends you back to the address the assistant registered, and shows that address (*"Afterwards, you go back to…"*).

### The keys

| Key | Valid for | What happens |
|---|---|---|
| Authorization code | 10 minutes, once | Exchanged for the access key right after your yes |
| Access key | 1 hour | The assistant renews it on its own, without you noticing |
| Refresh key | 30 days | Replaced by a new one on every use. If a key that was already used shows up again, Memberfy assumes it leaked and shuts down the whole connection |

Memberfy stores the keys only as a *hash* (an irreversible fingerprint): not even Memberfy can read them once issued.

### One connection, one community, one person

Each connection is the combination of **you**, **one community** and **one assistant**. The key doesn't open another community, or someone else's. Connecting Claude and ChatGPT, or two communities, means separate connections, each of which can be disconnected on its own.

## The role, on every call

The assistant has no permissions of its own. Each tool calls Memberfy **as you**, with your role at that moment, and goes through the same checks as the screen:

- if your role changes in the dashboard, the assistant changes with it, on the next call;
- if you leave the community, or are removed, the assistant stops working there;
- each space's rules (visibility, **Who can post**) apply the same way.

The list of tools the assistant sees is already filtered by role, but Memberfy decides on every call. See [Tools](/mcp/ferramentas#how-many-each-role-sees).

## What never comes out

- **Internal payment processing costs**, their breakdown and margins. For amounts, the [platform fee](/pagamentos/taxa-da-plataforma) appears, as in the dashboard. Besides the routes not returning those fields, the MCP server has a second lock that strips them from any response.
- **What your role doesn't see.** A member doesn't read sales; a moderator doesn't read the statement.
- **Data from other communities.**

## Money

The money tools and the deletion tools (`delete_`, `remove_`, `revoke_`, `withdraw_`, `cancel_`) act in two steps: a summary with the amounts and a 10-minute, single-use code tied to those same amounts. See [Money and confirmation](/mcp/dinheiro-e-confirmacao).

## Revocation

| Who | Where | Effect |
|---|---|---|
| You | **My Account › AI assistants** (`/account?tab=assistants`), **Disconnect** | Cuts off your connection instantly |
| Owner and admins | **Settings › AI assistants**, **Disconnect** | Cuts off anyone's connection to that community |
| Memberfy | On its own | When you leave the community, when the refresh key goes 30 days unused, or when an already used key reappears |

Disconnecting invalidates every key on that connection: the assistant's next call is refused.

## Audit

Every tool call is recorded and linked to the connection: the tool, the values sent (without confirmation codes), the result (done, error, refused, awaiting confirmation, limit reached), Memberfy's response and how long it took. The connection's events are recorded too: when it was authorized, renewed and disconnected.

- **What the assistant did shows up in the dashboard**, in **Members › Logs**, source **AI assistant**: each connection, each tool used and each refused action, with the status, the duration and the summarized arguments (no tokens, images or secrets). Only the owner and admins see it. See [Activity logs](/membros/registros-de-atividades).
- The owner and admins can also look up the community's audit log through the API, at `GET /api/oauth/audit`, or through the assistant itself, with [`list_activity_logs`](/mcp/ferramentas-membros#list-activity-logs).
- Besides tool calls, the audit logs `session.initialize` (the assistant opened the connection), `tools.list` (it asked for the tool list) and `tool.unknown` (it called a tool that isn't on its list), with the assistant, the server version, the `tools_fingerprint` and the number of tools.
- For a single connection, [`GET /api/oauth/connections/{id}/diagnostics`](/api/referencia/mcp/get-oauth-connections-by-id-diagnostics) shows the last list delivered, the current one and, in `listUpToDate`, whether the assistant is up to date. Also owner and admins only.
- The conversation itself (what you wrote to the assistant) stays with the assistant, not with Memberfy.
- What the assistant creates appears in the dashboard under your name, as if you had done it; subscription cancellations also appear on the timeline in [subscription management](/pagamentos/gestao-de-assinaturas).

## Limits

| Limit | Value | What happens when exceeded |
|---|---|---|
| Tool calls per connection | 120 per minute | *"Too many calls in a short time. Wait a minute and try again."* |
| Assistant registrations per network address | 20 per hour | The registration is refused; try later |
| Key exchanges per network address | 60 per minute | The exchange is refused; the assistant tries again |
| Confirmation code lifetime | 10 minutes | The code expires; a new summary is generated |
| Items in the composite tools | Up to 30 modules per course, 50 lessons per module, 6 options per plan | The call is refused before anything is created |

## Good practices for the team

- **Connect with the smallest role that does the job.** For reports, a **finance** account; for content, a **moderator**.
- **Review the list from time to time.** **Settings › AI assistants** shows each connection's last use: disconnect what nobody uses.
- **When someone leaves the team**, demote or remove them: their assistant loses access along with them.
- **Read every money or deletion summary** before you say yes.
- **In the assistant, only set as always allowed the tools you don't need to review.** Invites and issuing certificates send e-mail on the first call; see [The assistant's permission](/mcp/dinheiro-e-confirmacao#the-assistant-s-permission).

## Related

- [Authorize and disconnect](/mcp/autorizar-e-desconectar)
- [Roles and permissions](/conceitos/papeis-e-permissoes)
- [Common problems](/mcp/problemas-comuns)
