MCP Server

Security & Limits

How MCP Server protects your data and the usage limits that apply to connections.

Token Security

  • ●Your MCP Server URL contains a cryptographic token (68 characters)
  • ●The token is hashed with SHA-256 before storage — we never store your plaintext token
  • ●Tokens are shown only once at creation (or regeneration)
  • ●Token format: mcp_ followed by 64 hexadecimal characters

Access Control

  • ●Each connection is tied to your user account and organization
  • ●The AI app can only access content you own or that is shared within your organization
  • ●Plan eligibility is re-verified on every request — if you downgrade to a free plan, connections stop working

Rate Limiting

  • ●Each connection is limited to 60 requests per minute
  • ●Exceeding the limit returns a "Rate limit exceeded" error (HTTP 429)
  • ●The limit resets automatically after the window passes

Limits & Quotas

LimitValue
Max connections per organization5
Rate limit per connection60 requests per minute
Max search query length500 characters
Max search results per request20
Max list results per request50
Max content length per retrieval100,000 characters
Request timeout5 minutes
  • ●File conversions via MCP count against your plan's monthly conversion quota
  • ●Rate limits apply per connection, not per organization (each connection gets its own 60 req/min)
  • ●Rate limit windows reset automatically after 1 minute of no requests

Best Practices

Don't share your URL publicly

treat it like a password

Use separate connections

for different AI apps or use cases

Use minimal permissions

only grant what the AI needs

Regenerate immediately

if you suspect a URL has been compromised

Disable unused connections

rather than leaving them active