Skip to main content

Permissions and credits

What an app can access​

A connected app uses your HolyShift identity. It can list your own projects and projects shared with you. Project permissions still apply: reading a shared project's answer does not give the app permission to start work in it.

MCP currently has one permission scope, mcp. There is no separate read-only connection. Connect apps you trust with your business information and the ability to request work.

HolyShift answers questions through its own agent. The MCP interface does not provide direct file downloads or an export of all your project files.

What spends credits​

Asking HolyShift, creating a project and running experiments can spend your account's HolyShift credits. A question about existing information still starts an agent run.

You can ask your app to check your HolyShift credits before starting several questions. This shows your balance, plan, renewal information and credits expiring soon. Billing is managed in Settings → Billing in HolyShift.

When billing is enforced, an ended plan can prevent new work, and a lack of credits can prevent a question from running. The app should explain the refusal instead of claiming the work was completed.

Approvals and questions​

Some work needs you to approve an action or answer a question. The connected app receives a waiting_for_you status and a HolyShift conversation link.

  1. Open the link.
  2. Review the action or question in HolyShift.
  3. Approve, decline or answer there.
  4. Let the connected app check again once the work continues.

Approving actions and answering these requests over MCP is not supported. Retrying a failed experiment step and cancelling an experiment also stay in HolyShift.

Revoke access​

Disconnect the app under Settings → Connected apps. Revocation stops new authenticated calls immediately; it does not cancel work already submitted or retract data the app has received.