MCP, OAuth and permissions explained for your email
What the Approve button grants: OAuth sign-in with no password or key, four separate permissions, token lifetimes, instant revocation, and a checklist to reuse.

On this page(11 sections)
When you connect an assistant to your email, a page appears that says "Approve" or "Deny." Most people click Approve. This post is about what is behind that button: what you are actually handing over, how long it lasts, and how to take it back.
The short version is that OAuth lets you grant an app limited, revocable access without sharing your password. The longer version is worth knowing, because the quality of an integration shows in the details.
Why OAuth and not a password or a key
There are three ways an assistant could get into your mailbox.
| Method | Problem |
|---|---|
| Your email password | Gives away everything, forever, and cannot be limited or tracked |
| A long-lived API key you paste in | Easy to leak, hard to scope to one person, tends to live in config files |
| OAuth sign-in | You approve specific permissions on the service's own page, and the app gets a token you can revoke |
Koltrix's MCP server uses the third. There is no API key to create. The first time an app connects, it sends you to Koltrix to sign in and approve it, and you never type your Koltrix password into the assistant. Behind the scenes it is standard OAuth 2.1, so any compliant client works without special configuration.
What happens when you click Connect
Here is the sequence, in plain terms:
- You paste the server URL (
https://mcp.koltrix.com/mcp) into your assistant. - The assistant asks the server how to sign in. The server publishes standard discovery documents at well-known addresses, and it points to them when a request arrives unauthenticated.
- The assistant registers itself automatically. This is called dynamic client registration, and it is why you do not need to create anything in advance.
- The assistant sends you to Koltrix. It uses PKCE, a technique that stops a stolen sign-in code from being redeemed by anyone else.
- On the approval page you pick the workspace and review the permissions.
- You approve, and the assistant receives tokens.
You do not need to remember any of those names. They matter because they are the same pieces other well-known sign-in flows use, which means they have been scrutinized and are supported by many apps.
The approval page, line by line
The page at app.koltrix.com shows:
- The app's name and where it will send you back. Check that the app is the one you meant to connect. The page also refuses a redirect address that is not secure: an app that asks to send you somewhere that is not
https(or a local address) is rejected. - The workspace. If you belong to more than one, you choose. The connection belongs to that workspace only, and to use another you connect again.
- The permissions, in plain words.
- If an admin has allowed sending, an unticked box, Also allow sending email.
You can Deny, and nothing is connected.
The four permissions
| Permission | Plain meaning | Notes |
|---|---|---|
mail.read |
Search and read your mail; list mailboxes and labels | The assistant sees only what you can open |
mail.organize |
Labels, archive, read and unread, stars | All reversible in Koltrix |
mail.draft |
Save drafts to your Drafts folder | Cannot send on its own |
mail.send |
Send a draft that exists, after you confirm | Separate opt-in, never part of the default |
Apps ask for the first three by default. mail.send is its own checkbox, unchecked, and it appears only when an owner or admin has turned assistant sending on. If you do not tick it, the connection cannot send, whatever the app asks for. Existing connections keep the permissions they were approved with.
This is the shape you want from any integration: read, organize and draft are separable, sending is separable again, and each step up is a deliberate choice. If an app only offers "full access," ask why.
Your access, not more
The token is tied to you, the workspace, the app and the permissions you approved. Every call is checked against your access in Koltrix at the moment it happens. If an admin changes your mailbox access, or removes you from the workspace, the assistant's access changes with it. People who are removed or suspended lose access immediately.
That means an assistant is never more powerful than its owner. It cannot read the CEO's mailbox because you connected it, and it cannot see a teammate's mailbox you have no access to. Least privilege for AI email agents explains why this property matters so much.
How long it lasts
An access token lasts an hour and renews itself with a refresh token. The refresh token keeps working for up to 30 days of inactivity. In practice:
- An assistant you use every week stays connected without asking you again.
- A connection you forget about, and do not use for 30 days, lapses by itself.
- When it lapses, you reconnect from the assistant and approve again.
Koltrix stores only hashes of tokens, never the tokens themselves, so a database leak would not hand out working credentials. This is a baseline expectation for any service issuing tokens, and it is reasonable to ask a provider whether they do it.
Revoking, and the admin switch
You can see your connected apps in your Koltrix settings and click Revoke to cut one off. It stops working immediately, which is a property of checking the token on every call rather than trusting a stored session.
Workspace owners and admins have a bigger lever. They can turn AI assistants off for the whole workspace. Every connection stops working at once, and new ones cannot be made until it is turned back on. A second, separate switch controls sending, and it is off by default. Turning it off blocks the very next send, even for apps already allowed. Admin guide: turning assistants and sending on or off walks through the settings. For habits on reviewing, see Reviewing and revoking AI app connections.
What gets logged
Each connection, token renewal, revocation and tool call is recorded in the workspace audit log, with the name of the tool and none of your mail. Sends are logged as mcp.send, with the recipient count and their domains but not the message text or full addresses. Each connection also has its own request limit, so a runaway assistant cannot overload your account.
A checklist for any email integration
Use this when you evaluate Koltrix or anything else:
- Does it use OAuth, or does it ask for a password or a pasted key?
- Can you see exactly which permissions it asks for, in plain words?
- Are read, organize, draft and send separate?
- Is sending off by default, and controlled by an admin?
- Does access follow the user's own permissions on every call?
- Can you revoke it instantly, and can an admin switch it off for everyone?
- Are tokens short-lived and stored only as hashes?
- Is there an audit trail that does not copy your mail?
What OAuth does not protect against
OAuth controls who gets access and what they may do. It does not control what an assistant does with what it reads. An email can contain text written to manipulate an AI, and a connected assistant is reading it. That is why Koltrix keeps the toolset narrow, marks email content in results as untrusted, and puts sending behind several gates. Also remember that the parts of your mail an assistant reads go to that assistant's provider. What your AI provider sees covers that side.
Key takeaways
- Koltrix uses standard OAuth sign-in with PKCE and automatic app registration, so there is no password to share and no API key to manage.
- You approve four separate permissions; send is its own unchecked box and appears only when an admin allows it.
- Tokens are tied to you, one workspace, the app and the permissions you approved, and access is checked on every call.
- An access token lasts an hour and the connection lapses after 30 days of inactivity. You or an admin can revoke it instantly.
- See the docs for the details and the integration overview for the big picture.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

