Consent and permission updates to the DatoCMS MCP
If you're connected to Claude, ChatGPT, Cursor or any other AI tool using the DatoCMS MCP, we've rolled out a few updates that should make things easier.
The first big change is how you authenticate your AI against our MCP server:
The screen now tells you who is asking for permissions. The name of the app is right in the title, together with the address the login will be sent back to. If the app you're installing isn't the one we've verified, the page says "Authorize an Unverified app" and highlights the destination in red, so you can stop and verify which app you're installing.
You decide how much the app can do. Besides picking which projects the app can access, you can now choose a level of access:
Only read content: read content and media, never write or edit anything.
Read and edit content (recommended for editors): the app can also create, publish, and delete content and media. It can do nothing on schema, settings, users, or API tokens.
Anything you can (recommended for devs): whatever your account can do in DatoCMS, the MCP can as well.
⚠️ Whichever option you pick is still restricted by your own user permissions in each project.
If you choose one access level, you can always revisit the config screen to edit this.
If you're already using the MCP, you'll need to reconnect it once. We've changed how the MCP server handles tokens: the token your AI tool receives now only works with the MCP server and is tied to the app that requested it, and the authorization code you get after signing in works one time. During your next session, Claude and ChatGPT will ask you to log in again. Other clients may need you to remove and re-add the DatoCMS connector.
With this new approach, the connection also remains logged in until you revoke it, unlike before, where you had to re-authorize the connection every 30 days.