Security

Paid token access with minimal logging.

MCP Server Tools rejects unauthenticated MCP calls, keeps checkout and access activation separate, and logs usage summaries without storing full Bearer tokens.

Bearer token

Tokens are issued after paid checkout and shown once through the activation flow.

Usage log

Logs include method, tool, status, duration, and plan metadata; sensitive request bodies are avoided.

Agent confirmation

Payment and account-impacting workflows should keep explicit human confirmation gates.