What you approve
When an assistant connects, Popcorn opens the Authorize Popcorn MCP screen. You must be signed in to Popcorn; if you are not, you are sent to sign in and then brought back. The screen shows:
Click Allow access to connect or Deny to cancel. The footer reminds you that access can be removed later.
Access levels
Each line under Requested access is an area (campaigns, inbox, customers, products, and so on) plus a level, with the short code the assistant asked for (for exampleinbox:send) shown next to it. The description on the screen tells you what that level does:
Two campaign lines have their own wording: Read campaign workspace data (view connected assets, templates, campaign status, recipients, and performance stats) and Create and manage campaigns (draft templates and campaigns, submit templates, launch campaigns, and pause or stop sends).
Assistants that ask for nothing specific
If the assistant does not request particular areas, Popcorn grants read-only access to every area your role can view. The assistant can answer questions and produce reports but cannot change anything. Reconnect if you later want it to make changes and it supports asking for that access.Your role is the ceiling
An assistant can never do more than you can. Each area of access maps to a permission on your Popcorn role, the same ones shown under Settings → Roles & Permissions (Full Access includes every other action for that area):
Two consequences:
- Approval fails if the request exceeds your role. You see Your Popcorn role cannot grant MCP scopes followed by the areas you cannot grant. Ask an Owner or Admin to change your role, or connect as a user who has the access.
- Changes to your role apply on the next request. Popcorn re-checks your user and role every time the assistant calls it. If your role is reduced, the assistant loses that access immediately. If you are removed from the workspace or the workspace is suspended, the connection stops working.
Bound to you, your workspace, and that assistant
Every approval creates a connection tied to three things: your user, the workspace your Popcorn account belongs to, and the specific assistant that asked. It cannot be transferred to another person, another workspace, or another assistant. If the approval link is opened while signed in as a different Popcorn user, approval fails with Authorization request belongs to another Popcorn user.Confirmation before anything irreversible
Actions that reach a customer, publish something, delete data, move money, or change what is live are split into two steps. The assistant first asks Popcorn for a plan, which returns an exact preview: recipients, template, timing, amount, what will be created or deleted. The assistant must show you that preview and wait for your go-ahead. Only then can it ask Popcorn to carry the plan out. What Popcorn enforces on its side:- A go-ahead is valid for 10 minutes and for one execution only.
- It is bound to the exact plan. If the assistant changes anything, or if the underlying data changed in between (a template was edited, a conversation received new messages, a price changed), Popcorn refuses and the assistant must prepare a new plan for you to review.
- Retrying a completed action with the same details does not run it twice.
Things you must do in the browser
Some steps never go through the assistant, because they involve your credentials or consent with another company:- Signing in to Shopify, Salla, or Zid and approving the store connection.
- Meta login and consent for WhatsApp or a product catalog. The assistant gives you a link that opens Channels → WhatsApp in Popcorn ready to connect (or Integrations for a catalog); you click Login with Facebook and complete Meta’s steps yourself.
- Slack authorization for an agent.
- Entering or changing a payment card, changing your plan, and any payment that your bank asks you to authenticate. The assistant can start a billing session (after your confirmation) and give you the link.
How long access lasts
- The approval request itself expires after 10 minutes.
- Once approved, the assistant’s session is renewed automatically while you keep using it. A connection that goes unused for 30 days expires, and the assistant asks you to approve again.
- Reconnecting after a permission change is expected. Connections approved before an area existed do not include it; to add it, connect again so the assistant requests the new access. Importing customers or products, for example, needs read access to those areas as well as write access.
Revoking a connection
Settings → AI Assistants shows setup instructions only; it does not list or revoke connections. To end an assistant’s access:- Ask the assistant. Say “List my connected assistants” and then “Revoke the connection for X”. Revoking is itself a confirmed action, so the assistant shows you which connection it is about to remove and waits for your go-ahead. This works from any connected assistant, including the one you are revoking.
- Change the role or remove the user. An Owner or Admin can reduce your role or remove you from the workspace under Settings → Team Members; every connection you approved stops with the next request.
- Removing Popcorn inside the assistant’s own settings stops that assistant from using the connection. Unless the assistant tells Popcorn it is disconnecting, the approval on Popcorn’s side remains until it is revoked or expires after 30 days unused.
Rate limits
Popcorn limits how quickly each assistant can call it, per action type, per minute:
Generating agent instructions has its own, tighter limits because it calls an AI model: 3 per minute per assistant, 5 per minute per user, 20 per minute per workspace, and a daily allowance of 25 per user and 250 per workspace (the day resets at midnight UTC).
When a limit is hit, the assistant receives Too many MCP requests with the number of seconds to wait. Nothing is lost; it can continue after the window. Edits, sends, deletions, and instruction generation also pause if Popcorn’s safety limiter is temporarily unavailable (the assistant is told to retry in 60 seconds), so that nothing runs unchecked. Reads keep working.