Skip to content

Guides

Connections and security

How Spec connects to systems outside Parcel, what the trust model is for a custom MCP server, and how Spec is turned off.

Spec can read from and, with your approval, write to systems outside Parcel. Every one of those systems is something your workspace connected on purpose.

Workspace connections

A connection belongs to the workspace, not to the member who created it. Once a connection exists, the tools it exposes are available to Spec for that workspace, subject to the same approval rules as everything else.

Connecting a system is a three-step act, and each step is yours:

  1. Choose the system from the connector catalog.
  2. Complete that system’s own authorization flow in your browser.
  3. Approve the specific tools you want Spec to be able to use.

Removing a connection removes its tools. Deleting a connected account also asks the provider to delete the account it holds for you.

Custom MCP servers

You can point Spec at your own MCP server.

What Parcel enforces:

  • Public HTTPS only. A custom MCP endpoint must be a public HTTPS URL. Loopback addresses, private network addresses, and plain HTTP are refused at registration and again on every call.
  • No redirect escape. A redirect that would leave the allowed host is refused, and a hostname that resolves to a private address after registration is refused at call time, not just at registration time.
  • Schema quarantine. If a server changes a tool’s schema, the changed tool is quarantined rather than called with arguments shaped for the old schema.
  • A circuit breaker. A server that keeps failing is taken out of the loop and retried on a backoff, so one unhealthy server cannot stall a conversation.

Approvals apply everywhere

The approval gate is not a property of a surface. A write proposed through the full page, the follow panel, an API key, or the Developer MCP grant meets the same gate and produces the same audit record.

An action whose target changed since Spec read it is refused as stale. Spec re-reads and asks again.

Secrets you send

Spec scans what you send it, before it is stored and before any model sees it. If the text contains something shaped like a credential, the message is refused with a reason naming the KIND of secret found and nothing else. The secret is not stored, not logged, and not sent onward.

Ordinary business data is not a secret. Names, emails, phone numbers, addresses, and the rest of normal CRM content pass through untouched. The scanner looks for credential shapes: private keys, cloud access keys, provider API keys, OAuth codes and client secrets, bearer tokens, and session tokens.

How Spec is turned off

Spec has a server-authoritative state with three positions, and it is set by Parcel, not by a client.

StateWhat it means
offSpec is hidden. New runs, model calls, and tool execution are refused.
read_onlyHistory, event streams, cancels, and deletions keep working. Every new run and every tool call is refused.
onNormal operation, still subject to every individual control below.

Underneath the state are ten independent controls, each of which can be turned off on its own without touching the others: new runs, model calls, tool execution, native writes, remote MCP, skill loading, skill writes, credit purchases, free grants, and trial starts.

Narrower controls exist too: a single connection, a single connector, a single model configuration, a single tool, or a whole tool group can be blocked without affecting anything else.

Every one of those changes is audited with who made it, what changed, the value before and after, a reason, and a change reference. None of them can carry conversation content, because the audit record has nowhere to put it.

Deleting history is never blocked by any of this. The privacy API keeps working in every state: deleting one conversation, deleting everything you have sent, an admin purging a departing member, and changing the retention window all answer while Spec is off or read_only, and the queued deletion still runs. The privacy settings panel in the app appears once Spec is on.