Skip to main content

Access levels: full vs read-only

What full and read-only MCP connections can do, how to choose the level, and how to change it per connection at any time.

Every MCP connection to Koongo carries an access level that decides what the AI agent may do on your account. You pick it when you connect, and you can change it anytime — it applies immediately and is set per connection.

Full vs Read-only

Level

What the agent can do

Full

Read and make changes — create and configure feeds, marketplaces and ads, map attributes and categories, and export or submit to your channels.

Read-only

Read only — list, get, preview, verify and validate. Every write tool is refused, so nothing on your feeds, rules or channels can be changed through the connection.

Read-only is the safe way to try the assistant, or to connect a client you only want for reporting and inspection.

Choosing the level when you connect

  • OAuth (browser login): on the consent screen, choose Full or Read-only before you click Allow.

  • Static token: in My Account → MCP, set the Read-only switch the way you want, then click Generate token.

Changing the level later

Open My Account → MCP. Your static token and every connected app have a Read-only switch — flip it and it takes effect on the next call. You do not need to reconnect or generate a new token.

One level per connection

The level belongs to the connection, not the account, so different clients can have different levels — for example ChatGPT read-only while Claude Code keeps full access. Connect twice (or generate two tokens) to run both at once.

What a read-only connection sees

Read tools work as normal. A write tool returns a short error saying the connection is read-only. To make changes, switch that connection to Full in My Account → MCP, or use a full-access connection.

Did this answer your question?