Skip to content
AI ACCESS, BUILT AROUND CONTROL

Your assistant.
Your workspace rules.

A private MCP adapter is being built to let approved AI assistants work through Suparko’s authenticated API, with an independent identity for each workspace and agent.

In development · production access disabledDiscuss your integration

Separate by workspace.
Specific to the agent.

Workspace A / CodexKey 01
Workspace A / QA assistantKey 02
Workspace B / CodexKey 03

Illustrative identity model. No credentials are displayed or generated here.

THE ACCESS PATH

Business actions through one trusted service layer.

01Approved AI assistant
02Private MCP adapter
03Authenticated Suparko API
04Application services

No direct database access. The adapter must use the same business validations and permissions as the workspace UI.

A key for each identity

Workspace credentials are independent. A key assigned to one workspace must never access another, even when resource IDs are guessed.

Only the scopes you grant

Read tools and write tools are separate. The adapter discovers capabilities from the authenticated API rather than accepting scopes from a client.

Draft before execution

The adapter defaults proposed writes to draft mode. High-risk actions such as billing, role changes and external messaging are not exposed.

Trace the source of an action

The server foundation carries integration, workspace and initiating-user attribution. Durable audit storage remains part of the production work.

PLANNED WORKSPACE COMMANDS

Natural language.
Structured actions.

The assistant translates a request into a focused tool call. The server must authorize and validate it before returning real records or committing a change.

Show open issues in the launch project.

list_issues · issues:read

Find the task about onboarding.

search_issues · issues:read

Draft a task for the login timeout bug.

create_issue · issues:create · DRAFT

Add the QA result to this issue.

add_issue_comment · issues:comment
A LITTLE MORE DETAIL

Common questions.

Is live MCP access available now?

No. The adapter and workspace-isolation policy have been tested against a mock API. Real authentication, YugabyteDB services and persistent token management are not configured, so the integration API remains disabled.

Will every workspace have a different API key?

Yes. Each integration identity is bound to one workspace, and each agent should have an independent key. Tokens must be hashed in storage, revocable and rotatable.

Can an administrator’s AI read private chats or personal files?

Administrator status alone does not bypass resource access. The policy foundation still requires conversation participation or an explicit file grant.

What is needed before connecting an AI client?

Verified server configuration, real authenticated business APIs, durable audit, distributed rate limits, transactional idempotency and a successful create/update/revoke acceptance test are required before activation.

THE NEXT STEP STARTS WITH A CONVERSATION

Plan the AI access your team needs.

Tell us how your company works. We’ll explore how Suparko can fit your workflow.

Contact us