Skip to content

Privacy and access

This content is not available in your language yet.

Zenodot MCP is a read-only resource server for linked Pro accounts.

  • API keys are generated randomly and shown only once. Zenodot stores only a one-way SHA-256 digest and a short display prefix.
  • Each key is scoped to library:read and can be revoked independently.
  • Keys expire after the selected 30, 90, or 365 day period, or can be set to Never.
  • Each MCP request re-checks that the account is linked, Pro, and has a recent entitlement sync.
  • Search results, Page reads, and links are scoped to the authenticated account. Cursors are signed and bound to the account and grant.
  • Requests are denied when an account is deleted, merged, or no longer has Pro access. Keys can also be explicitly revoked.

The server does not grant access to Chute Notes, historical snapshots, or write endpoints. Standard service logs must redact API keys and Page body text.