Security

This page explains how Dokpod hosted MCP handles your vault: what the server can access, the least permissions required, how to disconnect, how team access is revoked, and what screenshot indexing keeps versus loses.

Hosted MCP URL: https://mcp.dokpod.io/mcp

Share this page

Copy a link to this security overview, or markdown that links to it from a README or review write-up.

https://dokpod.io/security

Operational checklist

Use this when evaluating Dokpod as an external knowledge vault for Cursor, Claude, or similar MCP clients.

  • Data range is explicit

    Hosted MCP only sees your Dokpod cloud vault and any team allowlist you enable. It does not request Google Drive or GitHub scopes by itself. Optional Drive or GitHub imports are separate connections you turn on in Settings.

  • Minimum permissions

    You need a Dokpod account, a rotatable connection key, and HTTPS access to mcp.dokpod.io. Vault search does not require a broad “read all cloud files” grant.

  • Disconnect before handoff

    Rotate your connection key from Connect or Settings so old Bearer keys stop working immediately. For a full wipe, export first, then use Disconnect MCP and purge vault.

  • Team revoke is live

    Removing a member or narrowing their MCP access scope updates the allowlist on the next search. No client restart is required for revoked documents to drop out of results.

  • Screenshot indexing limits

    Indexed screenshots keep OCR text and coarse layout labels. They do not store pixel click maps or full UI accessibility trees. Prefer vault search over re-uploading raw images every session.

  • Chunk cite-backs

    MCP returns small sections (about 400 to 800 tokens each). In Documents you can open a file and review the indexed headings your AI can retrieve.

Connect your editor

Set up MCP and manage your connection key.

Settings

Rotate keys, export data, or disconnect and purge.

Privacy Policy

How we collect and handle account and vault data.

Company

Business description, founder, and products.

Security questions: support@dokpod.io