Skip to content

Manage authorized MCP apps

Guide for CitaPro administrators: how to view and remove access for AI assistants (Cursor, ChatGPT, Claude, etc.) connected to your account.

MCP (Model Context Protocol) lets AI tools use CitaPro on your behalf: look up clients, create bookings, and more, according to what you authorize.

When you connect an app for the first time, you sign in with your Admin account and approve access. That connection is saved on your profile. You can revoke it at any time.

  1. Sign in to CitaPro with your Admin user.
  2. Go to Account (your user profile / settings).
  3. Open the Security tab.
  4. Scroll to Authorized MCP applications (below active sessions).

Direct path: /account/security

For each connected app:

FieldMeaning
NameThe app you authorized (e.g. Cursor, ChatGPT)
Permissions / scopesWhat access it has (usually MCP use)
AuthorizedWhen you granted permission
ExpiresUntil when the current access is valid (may renew if the app stays connected)

If there are no connections, you’ll see: No authorized MCP applications.

  1. From Cursor, ChatGPT, or another compatible client, you configure the CitaPro MCP server.
  2. The client opens CitaPro sign-in.
  3. You sign in as Admin (and enter the 2FA code if enabled).
  4. On the authorization screen, you accept access.
  5. The app appears under Account → Security → Authorized MCP applications.

You don’t need to “add” the app manually in CitaPro: it shows up after you authorize it in the AI tool’s flow.

  1. Go to Account → Security.
  2. Under Authorized MCP applications, find the app.
  3. Click Revoke access (trash icon).
  4. Confirm in the dialog.

What happens when you revoke:

  • That app can no longer use CitaPro with your account immediately.
  • To use it again, you must authorize it again from the client (Cursor, ChatGPT, etc.).

Revoking MCP does not close your web sessions or change your password or 2FA.

SectionWhat it’s for
Password / 2FAHow you sign in to CitaPro
Active sessionsDevices or browsers where you’re logged in
Authorized MCP applicationsAI apps you granted access to via MCP

Who can see this list?
Each Admin sees only their authorized apps, not other users’.

Is revoking in CitaPro enough?
Yes. After revoke, the token stops working. If the app tries to connect again, it will ask for authorization again.

What if I never used MCP?
You’ll see the empty-list message. That’s normal.

Is this the same as Developers API Keys?
No. API Keys are for technical REST integrations. MCP uses OAuth with your Admin user; it’s managed here, under Security.

Where can I see what the AI did in my business?
In the business activity history, MCP actions usually appear with origin MCP and your user as the actor.

  • MCP setup — Connect Cursor, ChatGPT, and other clients