# What permissions does a DunSocial MCP connection need? > A full MCP connection asks for workspace:read, drafts:write, posts:schedule, posts:publish, content:delete, memory:write, media:write & offline_access. Publishing needs posts:publish, deleting needs content:delete, & the connection is locked to the workspace you approved. Updated: 2026-10-05. ## Scopes are the permission list When an assistant connects, DunSocial asks you to approve a list of scopes. Each scope unlocks a specific group of tools & nothing more. | Scope | What it allows | |-------|----------------| | `workspace:read` | List & view posts, drafts, media, memories, accounts & workspace details | | `drafts:write` | Create & edit drafts (not publish) | | `posts:schedule` | Schedule, reschedule & cancel posts | | `posts:publish` | Publish immediately | | `content:delete` | Delete posts, drafts, memories or media | | `memory:write` | Create collections & save or update memories | | `media:write` | Upload to the gallery | | `offline_access` | Stay connected with refresh tokens | Updating the workspace's AI voice through `update_personalization` also needs `workspace:write`, & only owners & admins can use it. ## Why publishing needs its own scope Scheduling & publishing are separate on purpose. An assistant with only `posts:schedule` can queue a post for later but can't push one live this second. That split lets you give an assistant enough access to draft & schedule while keeping the immediate-publish power off. ## What a read-only grant looks like If the approval screen only mentions viewing workspace content, the assistant got read access alone. Every publish tool then fails with `insufficient_scope`. Disconnect & reconnect so the full set is requested. Connections created before `workspace:write` shipped need one reconnect to use `update_personalization`. ## Workspace binding An OAuth connection is bound to the single workspace you chose at approval. Asking the assistant to act on another workspace fails until you reconnect for that one. This is a safety property, not a limitation to work around. A leaked assistant session can only ever touch the one workspace it was approved for. DunSocial enforces that binding on the server, so the assistant can't switch workspaces on its own. ## What isn't a permission here DunSocial's roles still apply. Scopes say what the assistant may attempt, & the workspace's rules decide what your account may do. A billing state also sits above scopes: if the workspace isn't on a paid plan, product tools return a `subscription_required` error whatever scopes were granted. Only listing workspaces & reading workspace details always work. ## Choosing a minimal set For an assistant that only drafts, `workspace:read` & `drafts:write` is enough. Add `posts:schedule` when you want it to queue posts for your review in the calendar, & add `posts:publish` only if you really want immediate publishing. DunSocial's consent screen currently requests the full set by default for remote hosts, so if you want a narrower grant, check what the screen shows before approving. ## Related guides - [Why can't my AI assistant publish through DunSocial MCP?](https://www.dunsocial.com/hub/dunsocial-mcp-guides/why-cant-my-ai-assistant-publish-through-dunsocial-mcp.md) - [How to revoke an AI assistant's access to your social accounts](https://www.dunsocial.com/hub/dunsocial-mcp-guides/how-to-revoke-an-ai-assistants-access-to-your-social-accounts.md) - [What is a personal access token & how does it secure API access?](https://www.dunsocial.com/hub/social-media-automation-for-developers/what-is-a-personal-access-token-and-how-does-it-secure-api-access.md) - [How to connect an AI agent to your social accounts safely](https://www.dunsocial.com/hub/social-media-automation-for-developers/how-to-connect-an-ai-agent-to-your-social-media-accounts-safely.md) ## About this document This is the Markdown representation of https://www.dunsocial.com/hub/dunsocial-mcp-guides/what-permissions-does-a-dunsocial-mcp-connection-need. The HTML version of the same page is at the same URL. You can also request Markdown from any page by sending `Accept: text/markdown`. Machine-readable summary of the whole site: https://www.dunsocial.com/llms.txt ## Company - Product: DunSocial, https://www.dunsocial.com - Legal entity: THISUX PRIVATE LIMITED, Chennai, Tamil Nadu, India - Support: support@dunsocial.com - Open the app: https://app.dunsocial.com/login