Skip to content

MCP connections

Connect an app such as Claude to your Avaloi account through the hosted MCP server, see what each connection may do, and revoke it.

A connection is an app, such as an AI assistant, that you allowed to use your Avaloi account through MCP. It signs in as you, so it can never do more than you can, and you choose its access when you approve it.

Connect an app

  1. In an app that supports remote MCP servers, add a server with the address https://mcp.avaloi.com/mcp. In Claude, this is a custom connector.
  2. The app opens an Avaloi sign in page. Sign in, pick the company, and review the access the app asks for. Untick anything you do not want it to have.
  3. Approve. The app is connected and appears on the Connections page.

An app that only supports local servers can use the stdio server with an API key instead. See Connect an AI agent with the MCP server.

The Connections page

Open Settings, then Connections. The page shows one table of connected apps:

  • App: the app's name. If a teammate added it, the name of that person shows under it.
  • Access: "Full access" when the app holds every permission, or the first two by name. Hover or focus "+N more" to see the rest.
  • Last used: how long ago the app last made a call. Hover it for the exact time.
  • Added: the date you approved it.

On a phone, Access and Last used fold under the app name, and the table never scrolls sideways.

Owners, admins, and developers see every connection in the company. Other members see the ones they approved.

Revoke a connection

Select Revoke on the row, then confirm. The app stops working with your account at once: its tokens and the API key behind it are deleted, and the row leaves the list. To use the app again, connect it and approve it again.

If the revoke fails, the row comes back and the page says why. Try again.

Owners, admins, and developers can revoke anyone's connection. Other members can revoke only their own.

Expired connections. A connection whose grant ran out shows a small "Expired" note and a Remove button. Removing it deletes the API key behind it and takes it off the list.

Revoked connections never show on this page. The activity log keeps the record of who revoked what and when.

Quick answers

Can a connection do more than I can? No. It acts as you, with at most the access you approved, and never above your role.

How do I see what an app did? Open the activity log. Its calls appear under the app's name.

I revoked an app by mistake. Can I undo it? No. Connect the app again and approve it.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.