Permissions & access
What you grant when you authorize, what it requires, and how to disconnect.
What you grant
The consent screen lists what you're granting:
| Scope | What it allows |
|---|---|
profile:read | See your username, name, and avatar |
saves:read | Read your saves and your home feed |
boards:read | Read your boards and the saves on them |
search:read | Search Savee's public library on your behalf |
saves:write | Save items to your account and change their privacy |
boards:write | Create and edit your boards, and add or remove saves on them |
Private saves and private boards are included — the server shows the assistant the same things you see when you're signed in. If you'd rather keep private board saves out, the Hide private board saves from profile feed setting in Savee applies here too.
search:read is the odd one out: it doesn't expose anything of yours. It reads
Savee's public library — the same thing you'd see searching the site while
signed out — so granting it tells the assistant it may look outward, not that it
may see more of your account.
What write access does and doesn't allow
The two write scopes are what let an assistant act on a request like "make me a board of ceiling lamp inspiration" — search the library, then collect what it finds. They're marked separately on the consent screen, and they're never granted implicitly: a client that doesn't ask for them doesn't get them, and a connection made before they existed carries read access only until you reconnect.
With write access an assistant can:
- Create boards, including sub boards under a board you already have
- Rename a board, change its description, or change whether it's private
- Save items into your account, on a board or on their own
- Take a single save off a board
It cannot:
- Delete a save, or delete a board — neither is exposed at all
- Upload new images
- Change anything about your profile, email, or billing
- Act on team boards, which have to be edited on savee.com
Taking a save off a board leaves the save in your account, so the worst an assistant can do is untidy — nothing it does here destroys a save.
New boards are private by default. An assistant has to be told explicitly to make one public, because a public board appears on your profile under whatever name it chose.
One thing worth knowing: filing a save under a sub board takes it off the parent board. That's how Savee works everywhere — a save lives on a board or on one of its sub boards, never both — and the assistant is told when it happens so it can pass that on.
Write limits
Writes are metered per account, like search, and separately from it:
| Limit | Window |
|---|---|
| 10 boards created | 1 hour |
| 50 boards created | 7 days |
| 300 items saved | 1 hour |
| 3,000 items saved | 7 days |
| 60 other changes | 1 hour |
Saving is counted per item rather than per request, so one call that saves forty things costs forty. These are set well above anything a conversation produces — they exist to stop a client stuck in a loop from filling your account, not to ration ordinary use. Your plan's own limits on how many boards and saves you can have still apply on top.
Search limits
Search is much more expensive to serve than reading your own saves, and it's the only tool that reads the public library rather than your account. It's metered separately and far more tightly:
| Limit | Window |
|---|---|
| 20 searches | 5 minutes |
| 200 searches | 7 days |
The weekly ceiling is the one to know about. It's deliberate — it's what keeps the library from being enumerated a query at a time — and it's per Savee account, so it can't be reset by reconnecting.
It's also a single budget across everything you've connected: searching here and searching through the REST API draw on the same 200.
Each search returns at most 30 results, and paging stops after the first 90 for a query. To see more, search for something more specific.
An assistant that hits it gets a clear error and can carry on using every other tool; only search pauses until the window rolls over.
Requirements
The MCP server needs an active Savee subscription with API access enabled — the same requirement as the REST API. This is checked on every request, not just when you connect, so if your subscription lapses the connection stops returning data until billing is current again.
MCP or the REST API?
Use the MCP server when you want an assistant to read your Savee data conversationally. Use the REST API when you're writing code — it's the same data, and MCP tools are built on the same endpoints.
Disconnecting
Connected apps are listed under Connected apps at Settings → Developers, with what each one can read or change and when it was last used. Disconnecting takes effect immediately — the app loses access on its very next request, with no grace period. Anything it already created stays; disconnecting stops further changes rather than undoing past ones.
Most clients also revoke their own access when you remove them on their side. If a client disappears without doing that, disconnecting it here has the same effect.