The four access boundaries
An MCP request must pass all four:- Your workspace membership — you must still be able to reach the workspace.
- MCP seat — the member must have an active seat for that workspace.
- Connection grant — the OAuth session must include that workspace.
- Scope and workspace policy — the requested tool must fit the granted scope, effective role, provider access, guardrails, and approvals.
Scope tiers
Marketer caps a connection to the most restrictive effective role across all granted workspaces. If any selected workspace is Viewer-only, the connection remains read-only across that combined grant.
Connect to Claude
Open Settings → MCP connect. Under Connect to Claude, choose the visible setup tab.Claude Code
- Copy the displayed
claude mcp add --transport http marketer …command. - Run it in your terminal.
- Complete the browser OAuth authorization.
- Review scopes and choose only the required workspaces.
Claude Desktop or Cowork
- In Claude Desktop, open Settings → Integrations → Add.
- Copy and paste the MCP server URL shown in Marketer.
- Complete OAuth.
claude.ai
- Open claude.ai → Settings → Connectors → Add Custom Connector.
- Paste the MCP URL shown in Marketer.
- Complete OAuth and workspace selection.
Verify Connected agents
Under Connected agents, each session shows:- client name;
- granted scope names;
- Last used or the connected time;
- granted workspace chips; and
- Disconnect.
Safe first test
- Grant one test workspace.
- Start with
readonly. - Ask for a small result with a named account and completed date range.
- Confirm an ungranted workspace is not reachable.
- Add proposal or mutation use only after scope and workspace boundaries are correct.
Change workspace grants
Editing a connection’s workspace list does not require reconnecting the client.- Adding a workspace requires your membership and seat there.
- Removing a workspace stops that OAuth session from reaching it.
- If your role becomes more restrictive, effective scopes are capped accordingly.
- If a seat is removed, the connection becomes unusable for that workspace even if the old chip remains visible until the page refreshes.
Disconnect or rotate
Select Disconnect to revoke one connected-agent session. Use it for an unrecognized, obsolete, or compromised client. Eligible account Owners and Admins also see Account → MCP, which summarizes sessions reaching that account. It can converge account connections to read-only or read-write subject to role caps. The account page can regenerate credentials for existing sessions. Regeneration invalidates the old tokens and shows new access and refresh tokens once.Seats and billing
MCP seats are managed in Settings → Members.- The account Owner’s seat is implicit.
- Teammate seats are per member and workspace.
- Only the account Owner can make paid seat changes.
- Account Admins can manage membership but not paid MCP seats.
- A seat cannot be granted before workspace access.
- Seat removal revokes that workspace’s MCP entitlement; the confirmation explains applicable billing or credit.