Manage authorized MCP apps
Guide for CitaPro administrators: how to view and remove access for AI assistants (Cursor, ChatGPT, Claude, etc.) connected to your account.
What is this?
Section titled “What is this?”MCP (Model Context Protocol) lets AI tools use CitaPro on your behalf: look up clients, create bookings, and more, according to what you authorize.
When you connect an app for the first time, you sign in with your Admin account and approve access. That connection is saved on your profile. You can revoke it at any time.
Where to find it
Section titled “Where to find it”- Sign in to CitaPro with your Admin user.
- Go to Account (your user profile / settings).
- Open the Security tab.
- Scroll to Authorized MCP applications (below active sessions).
Direct path: /account/security
What you’ll see in the list
Section titled “What you’ll see in the list”For each connected app:
| Field | Meaning |
|---|---|
| Name | The app you authorized (e.g. Cursor, ChatGPT) |
| Permissions / scopes | What access it has (usually MCP use) |
| Authorized | When you granted permission |
| Expires | Until when the current access is valid (may renew if the app stays connected) |
If there are no connections, you’ll see: No authorized MCP applications.
How an app is authorized (first time)
Section titled “How an app is authorized (first time)”- From Cursor, ChatGPT, or another compatible client, you configure the CitaPro MCP server.
- The client opens CitaPro sign-in.
- You sign in as Admin (and enter the 2FA code if enabled).
- On the authorization screen, you accept access.
- The app appears under Account → Security → Authorized MCP applications.
You don’t need to “add” the app manually in CitaPro: it shows up after you authorize it in the AI tool’s flow.
How to revoke access
Section titled “How to revoke access”- Go to Account → Security.
- Under Authorized MCP applications, find the app.
- Click Revoke access (trash icon).
- Confirm in the dialog.
What happens when you revoke:
- That app can no longer use CitaPro with your account immediately.
- To use it again, you must authorize it again from the client (Cursor, ChatGPT, etc.).
Revoking MCP does not close your web sessions or change your password or 2FA.
Difference from other Security sections
Section titled “Difference from other Security sections”| Section | What it’s for |
|---|---|
| Password / 2FA | How you sign in to CitaPro |
| Active sessions | Devices or browsers where you’re logged in |
| Authorized MCP applications | AI apps you granted access to via MCP |
Who can see this list?
Each Admin sees only their authorized apps, not other users’.
Is revoking in CitaPro enough?
Yes. After revoke, the token stops working. If the app tries to connect again, it will ask for authorization again.
What if I never used MCP?
You’ll see the empty-list message. That’s normal.
Is this the same as Developers API Keys?
No. API Keys are for technical REST integrations. MCP uses OAuth with your Admin user; it’s managed here, under Security.
Where can I see what the AI did in my business?
In the business activity history, MCP actions usually appear with origin MCP and your user as the actor.
Related
Section titled “Related”- MCP setup — Connect Cursor, ChatGPT, and other clients