Security and privacy
Ploti MCP uses the same workspace authorization and data-access rules as the Ploti application. There is no separate trusted path for external assistants.Authentication
Remote assistants connect through OAuth 2.1 over HTTPS. Ploti supports dynamic client registration, authorization-code exchange with PKCE (S256), short-lived access tokens, and rotating refresh tokens.
- Redirect URLs must match the registered value exactly.
- Authorization codes are single-use.
- A refresh token is replaced every time it is used.
- The consent screen names the requesting client and workspace before access is granted.
- Ploti passwords and OAuth tokens are never returned through MCP tools.
Access boundaries
Every connection resolves to a Ploti user and workspace. Server-side checks apply that identity to every session and tool call.- A connection can access only the workspace approved during consent.
- Sessions are isolated by connection identity, not merely by workspace.
- Data queries are constrained to the session’s current map viewport.
- Plan entitlements and dataset permissions are enforced by the data service, not trusted to the assistant.
- Saved outputs use the same workspace authorization as other Ploti content.
What data passes through MCP
When you ask an assistant to use Ploti, the assistant provider sends the tool name and inputs needed for that request to Ploti. Ploti returns the requested result, such as a concise data preview, source reference, map metadata, or artifact link. Ploti does not request unrelated conversation history. The assistant provider controls what conversation context it sends with a tool call; review that provider’s privacy and data-use terms separately. Do not include passwords, complete payment-card data, protected health information, government identifiers, or other unnecessary sensitive data in prompts or files.Storage and retention
For complete handling and deletion terms, read the Ploti Privacy Policy, Terms of Service, Acceptable Use Policy, and Subprocessor List.