Kolleno MCP uses OAuth authorization so users explicitly approve app access. Tokens are scoped to the authenticated user and their allowed companies.
Connected apps only receive the access your account already has. If your user cannot access a company or feature in Kolleno, MCP cannot bypass that restriction.
Access expires after 90 days and must be re-authorized. For ongoing hygiene, periodically review connected apps in MCP Connections, disconnect anything no longer in use, and re-authorize only trusted clients.
