AI assistants (MCP)
MCP security & troubleshooting
How access works, and how to fix common connection issues.
- Connections use OAuth 2.1 with PKCE; the assistant gets a token tied to your account.
- Every tool acts as you — it can only see your own saved reports and plan.
- Tokens refresh automatically; revoke access by removing the connector in your assistant.
Troubleshooting
| Problem | Fix |
|---|---|
| Sign-in page loops back to the homepage | Start the connection again from your assistant and sign in on the page it opens. |
| “Not authenticated” | Reconnect the connector to get a fresh sign-in. |
| “No public report exists” | Run the audit on instapect.com first, then ask again. |