Use the hosted MCP private alpha
Hosted MCP lets an approved remote MCP client connect without a local stdio server or a stored ToDoddle client secret. It is a private alpha for approved users. Clients must be pre-registered or publish a client metadata document at a trusted HTTPS origin. Public self-service and dynamic OAuth client registration are not available.
The authorization server identifies itself in every redirect to an approved client. Providers that support issuer-bound callbacks can use a stable HTTPS callback. The callback must still be registered exactly for each predefined OAuth client. For a metadata client, the callback must match a redirect URI in its approved metadata document.
Start the connection from the approved MCP client. The client opens ToDoddle so you can sign in, review the requested scopes and projects, and give consent. It uses a one-time authorization code with PKCE, then receives short-lived access and rotating refresh tokens.
Complete consent within 10 minutes and in the same browser profile that opened the request. Select one workspace and at least one accessible project shown under that workspace. ToDoddle gives a specific selection error when those choices are not valid. It keeps transaction, cookie, user, client, and expiry failures generic so it does not disclose authorization state.
The same three access boundaries still apply:
- Granted scopes permit a capability.
- Project grants permit the target project.
- Your current ToDoddle access permits the same action.
ToDoddle checks current access on every request. Removing project access, disabling a connection, or revoking it stops later use. Revocation is permanent for that connection; authorize a new one if access is needed again.
Workspace settings show the connected application, provider, authorizing user, projects, scopes, consent time, last use, and state. A disabled connection can be enabled again. A revoked connection cannot be edited or restored.
Hosted file uploads use a direct upload session. The client sends bytes from your device to the short-lived private storage destination, then asks ToDoddle to verify and finish the upload. The hosted gateway does not receive or stage the file body. Local paths and clipboard staging are available only through the local MCP.
If a client asks you to authorize again, confirm that the connection is enabled and that your workspace and project access still exist. A reused or invalid refresh token revokes its token family. Never paste access tokens, refresh tokens, authorization codes, or signed upload URLs into a ticket or support message.
Hosted MCP subscription allowances are listed in Subscription plans and usage limits. An allowance does not grant private-alpha access by itself.
Updated 2026-10-01. Owned by security.

