Privacy and access
This content is not available in your language yet.
Zenodot MCP is a read-only resource server for linked Pro accounts.
- API keys are generated randomly and shown only once. Zenodot stores only a one-way SHA-256 digest and a short display prefix.
- Each key is scoped to
library:readand can be revoked independently. - Keys expire after the selected 30, 90, or 365 day period, or can be set to Never.
- Each MCP request re-checks that the account is linked, Pro, and has a recent entitlement sync.
- Search results, Page reads, and links are scoped to the authenticated account. Cursors are signed and bound to the account and grant.
- Requests are denied when an account is deleted, merged, or no longer has Pro access. Keys can also be explicitly revoked.
The server does not grant access to Chute Notes, historical snapshots, or write endpoints. Standard service logs must redact API keys and Page body text.