Security model
The authenticated user and barn come from the access token, never from tool arguments. Read and write scopes are explicit. You can revoke every connection or API key from the dashboard.
POST /mcp
Authorization: Bearer mb_••••••••
MCP-Protocol-Version: 2025-03-26