You authorize capabilities—not a new workspace role.
OAuth lets Claude, Codex, or ChatGPT act as the signed-in HumanDesign.ai user. It does not create access, change membership, or grant an agent ownership of a workspace.
What workspace selection means
The consent screen asks “Where should Claude work?” because a paid account may have both a personal library and one or more team or business workspaces. The choice sets the data boundary—it is not an extra membership permission. Every call still checks the user's membership, role, scopes, ownership, and product entitlements. Authorizing Builder applies to eligible projects inside that boundary; projects do not require separate OAuth grants.
Free accounts: there is no workspace selector. The connection is limited to the personal-account boundary and the user's own primary chart. Personal or Pro is required for other people's charts and wider platform tools.
Permission vocabulary
| Scope | Allows |
|---|---|
charts:read | Read authorized chart records |
charts:generate | Generate your own chart when permitted |
library:read | Search and retrieve permitted library items |
library:organize | Manage folders and item placement |
reports:read | Read templates, reports, and generation status |
reports:generate | Prepare credit-consuming report work when enabled |
reports:deliver | Prepare report delivery when enabled |
builder:read | Read entitled Builder projects and runs |
builder:write | Prepare Builder changes when enabled |
builder:publish | Prepare publishing handoff when enabled |
communications:send | Allow an explicitly confirmed external delivery |
account:usage | Read balances, quota, and summarized usage |
What appears in the agent
tools/list is filtered by the authenticated user's granted scopes, current membership, workspace role, and entitlements. Upgrades, downgrades, role changes, and revoked grants take effect after reconnect or token refresh.
Confirmation and external effects
Consequential tools return a preview or secure HumanDesign.ai handoff before execution. Confirmation is bound to the actor, workspace, action, arguments, destination, maximum charge, and expiry. Changing any of those details invalidates the confirmation.
Revoke access
Disconnect HumanDesign.ai in the client's connector settings or clear the MCP authentication. Revocation ends the delegated connection; it does not delete HumanDesign.ai data or change membership.