ReDock Web · AI access and policy

One door to every site you run.

The same MCP server the desktop app runs on your machine, running on your live sites. Connect Claude once and it can work on all of them, at the level you approved, under rules you set.

Claude · Claude Code · Cursor · any MCP client
🔒 app.redock.xyz/apps
Connected apps2 AI apps connected · each at the level you approved
Claude
redock:edit · connected 10 Jan
Revoke
Cursor
redock:draft · connected 13 Jan
Revoke
app.redock.xyz/mcp· one workspace, every site in it
app.redock.xyz/mcp/s/a1b2c3d4· one site, and no other
0 policy switches per workspace, tightenable per site
0 addresses: the whole workspace, or exactly one site
Consent a screen naming what is being approved, before anything connects
Next call when you revoke an app, not the next hour
Connecting

An address, a consent screen, a name on the list.

Point an MCP client at your workspace address and the first connection lands on a consent page here, which names the workspace it is being approved for and the level it is asking for. Approve it and the app appears under Connected apps with the date, the level and a Revoke.

A per-site address reaches that one site and nothing else in the workspaceAPI tokens for a script, scoped to a workspace or a single siteEvery call is recorded with the app's name, which site, and how it ended
🔒 app.redock.xyz/consent
the first connection lands here · every app you approve is listed under Connected apps
The policy

Seven switches. Off means refused and told to ask.

Publishing or trashing content. Changing what the front page is. Switching the theme. Installing, removing, updating or toggling plugins. Changing site settings. Database writes. Creating users or changing roles. Switch one off and an AI app is refused it at the door, told to ask a person, and the refusal is on your Activity page.

Switching one off does not stop you: your team and your jobs are unaffectedA single site can be made stricter than the workspace, on its own pageThe app is told which switches are off when it connects, not when it fails
🔒 app.redock.xyz/policy
Usage policywhat an AI app may do on its own
Publish or trash content
Change what the front page is
Switch the theme
Install, remove, update or toggle plugins
Change site settings
Run database writes
Create users or change roles
switching one off does not stop the work: you and your team still do it from these pages
Tokens

For the script that has no browser.

A scoped token for a workspace or a single site, at the level you choose, revocable on the next call. It is the same door, the same policy switches and the same records as an app that signed in, so a script cannot quietly do more than a person watching it could.

Scope a token to one site and the rest of the workspace does not exist for itA read-only token stays read-only however the question is askedRefusals are recorded with the code and what was asked
🔒 app.redock.xyz/apps
API tokensfor a script, rather than an app that signs in
Nightly content sync
every site · redock:edit
Revoke
Harbourside only
clinic.harbourside.org · redock:view
Revoke
Authorization: Bearer rdw_••••••••••••••••
revoked on the next call, not on the next hour
"What you switch off, the app is refused and told to ask a person. You, your team and your jobs are unaffected." from the security page →

Connect one site and look.

One connected site is free, with no card. Install the plugin, type the code, and the site is on the list a minute later.

Free for one site · the desktop app is free on every plan