Skip to main content

MCP Security & Privacy

Off by default, read-only first, local-only, revocable - exactly how AI access to your chats stays safe.

Giving an AI access to your chats sounds scary. It shouldn't be - the mssgs MCP was designed so you stay in control at every step.

The six guarantees

Off by default

Nothing runs until you explicitly switch on AI / MCP access in Settings → Integrations.

Read-only first

Sending messages is a separate switch. Until you flip it, the AI can only look.

Local only

The server binds to 127.0.0.1 - unreachable from the network or internet - with protection against DNS-rebinding tricks.

Granular permissions

Per-channel picker, separate toggles for sending, DM requests, all-DM access, profile & story access and keep-computer-awake.

Revocable tokens

Tokens are named, per-tool, and revocable in one click - with a per-token activity sparkline so you can see exactly when each was used.

Only while you're there

The server runs only while the desktop app is open and you're signed in. Close the app, access ends.

Good hygiene: create one token per AI tool, name them clearly, and review the activity sparklines occasionally. Lost laptop? Revoke its token and it's useless.

Was this article helpful?

Didn’t find what you were looking for? We’re happy to help.

Ask your question

Still need help?

Our support team usually replies within 24 hours.

Contact support