Skip to main content

Access model

  • You choose the workspace. Every connection is bound to one Evermuse workspace, chosen on the consent screen. Tools can’t read or write any other workspace, even ones you belong to.
  • The agent acts as you. Tools reach only data in the workspace you authorized, and every write is attributed to you.
  • Access is checked on every call. The server verifies on each tool call that you’re still a member of the workspace, and that every product, project, source, signal or note id passed in belongs to it. Ids from another workspace are treated as not found.
  • Evermuse data only. The standard tools work only on data inside Evermuse (openWorldHint: false on all 27). They don’t browse the web or call third-party tools connected to your workspace. The only outbound fetch is optional: if you pass a recording URL to add_source, Evermuse downloads that file to process it. Workspaces in early-access programs may see additional tools, which are annotated accordingly.
  • Reads and writes are labelled. On a standard workspace, 22 of the 27 tools are read-only. The five write tools are annotated, so your client can ask for confirmation before running them, and update_signals and update_shaping_note are marked destructive. See Tools reference.

Credentials

  • OAuth 2.1 with PKCE. Only the authorization code grant with S256 PKCE is accepted. Redirect URIs must exactly match the client’s registration, and dynamically registered clients may only use HTTPS or loopback redirect URIs.
  • No secrets in the browser. Clients are public OAuth clients. You sign in on Evermuse’s own pages, never inside the AI client.
  • Short-lived, hashed tokens. Access tokens expire after one hour. Refresh tokens rotate on every use, and a reused refresh token revokes the whole token family. Evermuse stores only SHA-256 hashes of tokens, authorization codes and API keys, never the raw values.
  • Automatic revocation. Removing someone from a workspace or deleting their account invalidates their tokens. Tool calls are refused at once, and any cached validation expires within a minute. See Revoking access for the other options.
  • Visibility. The first time a new application connects to a workspace, Evermuse emails you, and you can reply to have our team revoke it.

Transport security

  • All traffic is served over HTTPS with HSTS.
  • Cross-origin browser requests are accepted only from known MCP client origins.
  • Responses carry strict security headers, including a locked-down Content Security Policy.
  • Rate limits apply per access token, per API key, to client registration and token requests, and per IP address. See Limits & errors.

How your data is used

Evermuse doesn’t use the conversation in your AI client. The server only sees the tool calls your client sends.

Logging and analytics

To operate and improve the service, Evermuse records:
  • Request logs: method, full URL (including query string), status code, duration and response size for each request. Request bodies of MCP calls aren’t logged.
  • Security events: client registrations, authorizations, consent decisions, and token issuance, refresh and revocation, with the client, workspace and user ids involved.
  • Usage analytics: for each tool call, the tool name, success or failure, duration, result size, the optional workflow label, and the MCP client’s name, version and user agent, keyed to your internal user and workspace ids. Analytics are processed by PostHog. Tool results, and arguments other than the workflow label, aren’t included in analytics.
  • Billing records: the workspace, user and tool for each successful call, to meter credits.

Content from your sources

Search results and transcripts contain text your customers and colleagues wrote. That text is returned as data. Like any MCP tool output, it shouldn’t be treated as instructions. Evermuse’s tool descriptions and skills tell agents to quote and cite evidence, not to act on it.

Policies and contact