security
An agent in your production data, on a short lead.
A coding agent connected to Vinktar reads what you let it, writes only inside your workspace, and leaves a record of every call. Here is how each of those holds, where your data lives, and what we do not have yet.
the_grant
One workspace, one choice of access, approved by a person.
- An agent connects with OAuth 2.1 and PKCE, so there is no API key to paste into it: a person signs in, in their own browser, and approves one workspace, optionally one project, read only or read and write. The token it gets is good for that grant only.
- Two checks run on every call. The connection’s grant is checked against every id the agent passes, and the person’s own membership is checked by the same resolvers the web app uses, so an agent never sees more than the person who approved it.
- Read and write is offered only where that person can change data themselves. Any connection can be disconnected at any time; an admin can disconnect anyone’s, or switch agents off for the whole workspace, which refuses the next call.
vinktar · you approve the grant
Claude Code wants to connect
It will act as you, inside what you choose here.
Workspace
Project
Access
can_and_cannot
Writes stay inside your workspace.
An agent can configure what it needs to answer questions and follow up. It cannot remove anything, create credentials, or name a new place for your data to go: there is no tool for any of those, and the one tool that could reach outward refuses to.
It can
- Read events, errors, boards and trends in the scope you chose
- Define events and write the project’s notes
- Build, edit and delete boards and panels; a deleted one can be restored for 30 days
- Create watches that reach your owners and admins
- Resolve, ignore, reopen or assign an issue
writes need a read-and-write grant · mcp:write
It cannot
- Delete events, errors, issues or projects
- Create projects or API keys
- Add a webhook, Slack channel or email list
- Hide or un-hide an event or property
- Touch members or billing
- Run code or deploy anything
no tool for these · create_watch refuses a destination
The line is create_watch. An agent can create a watch, and it reaches the workspace’s existing owners and admins. A request that names a webhook, a Slack URL or an email list is refused with a sentence the agent can relay to you. Anything an agent changes on an issue is recorded as done by that agent.
hostile_text
What your users write is data, never instructions.
Error messages, event names, payloads and URLs arrive from anyone who can load your app, since the key that sends them is public by design. Some of that text will one day be written to steer an AI agent.
Marked as untrusted
<vinktar-data> block, cleaned of anything that could close it early, with the server’s instructions saying what that block is.Links from ids only
Nowhere to send it
the honest caveat
That lowers the risk; it does not remove it. An agent can still be misled about what it reads, and it has other tools than ours. Check what an agent proposes before you act on it, and be most careful with connections that can make changes.
vinktar · you correct it
acme / web
What agents made
- Claude Code Delete
Pricing page launch
board · expires in 14d
- Claude Code Delete
Checkout errors spiking
watch · to owners and admins
user.email
hidden from agents
staying_in_charge
You see what it did, and you can undo it.
Every call on the record
Everything it made, labelled
Hidden properties stay hidden
Budgets and deadlines
your_data
Where it lives, and how it is kept apart.
In Helsinki
No model provider
Tenancy in three layers
SQL that can only read
run_sql goes through our own compiler: SELECT only, your events only, allowlisted functions, every literal bound. It runs on a read-only connection with time, row and memory caps.Two kinds of key
IPs are not kept
what_we_do_not_have
What we do not have yet.
If your review needs any of these, we are not the right vendor today, and it is better you know now.
No SOC 2 report
and no other certification.
No region choice
Your events and errors are stored in the EU, in Helsinki.
No SSO or SAML
Sign in by email, password or Google.
A small company
Deliberately so. Weigh it as the risk it is.
Found a vulnerability? Email john@vinktar.com.