Security and limits
Your key is the boundary
Headless Context MCP accepts only MCP Studio API keys (msk_live_). Each tool
runs under that key exactly as the MCP Studio API would, so the key
decides what the assistant can reach:
- An account-wide key can manage every server on your account.
- A key limited to specific servers sees only those servers. It cannot create new servers or delete custom tools, because a custom tool belongs to the whole account. See Authentication.
A server access token (mcps_live_) is not accepted. It lets a client query
one private server and nothing more.
To give an assistant less, create a separate key for it and limit that key to the servers it should manage. To cut it off, delete the key in Account > API Keys; the next request is refused.
Deletions are confirmed
delete_server, remove_source, delete_custom_tool, and
delete_retrieval_rule run only when called with confirm set to true, and
their descriptions tell the assistant to set it only after you agree. Clients
that ask before running a destructive tool will also ask you. A deleted server can
be restored from the dashboard for 7 days.
Secrets stay out of the chat
add_sourcehas no field for a credential. Add sources that need an API key in the Context MCP Studio dashboard, so the key is never typed into a conversation.- A private server's access token is returned once, when it is issued. Store it when your assistant shows it to you.
- Your API key is sent in a header and is never part of a tool's arguments or results.
Limits
| Limit | Value |
|---|---|
| Requests to Headless Context MCP | 120 per minute |
| Plan limits | The same as the API and the dashboard: servers, sources per server, and MCP requests per month |
| Request time | Up to 5 minutes, which build_custom_tool can need |
The limits of the endpoint behind each tool also apply; see Errors and limits. Each tool call is audit-logged with the tool's name and outcome, never its arguments.