--- title: "Questions" description: "Common questions about access, administration, cost and setup." canonical: https://past.dev/docs/mcp/faq last-updated: 2026-10-09 --- # Questions > Common questions about access, administration, cost and setup. Product: past.dev MCP Server. Source: https://past.dev/docs/mcp/faq #### Does connecting the account server give my assistant access to everything in past.dev? It gives the assistant exactly what you can reach in the console, and nothing else. Your platform role decides which tools appear, and your reach on a project decides which projects they work on. Permission checks run on every request and exclude other organizations. Its memory tools recall and ingest only in the projects you reach, at the level each needs. Its debugging tools read what Trace shows about the data points you sent, filtered by the same reach, so an assistant sees there exactly what you would see on the screen. #### Can it delete my data? It can do what you can do. `delete_project`, `revoke_api_key`, `delete_tag`, `delete_access_rule`, `delete_access_group`, `remove_member`, `set_member_role`, `merge_tags` and `revoke_project_grant` are destructive, and each one refuses to act until you have agreed to a sentence describing what it would do. Deleting memory is not one of them. That happens through the Memory API or in the console. #### Do I need an admin to set this up? For the account server, no. Any member can connect a client, and their connection reaches only what their role reaches. For the end-user server, yes. It is off until someone with project Admin enables it and connects an identity provider. #### Can my whole team share one connection? No. Each person connects with their own account. Every call is attributed to that person and bounded by their permissions, and every call is recorded with their name. #### Do my end users need past.dev accounts? No. They sign in at the identity provider you already run. past.dev is the authorization server and never a place for them to sign in, so they never see a past.dev account and past.dev never holds a password for them. #### What about an agent that cannot sign in? Mint an access link in the console. It is one address that is one identity, installed as the client's MCP server URL with nothing else to configure. The secret in the path is the credential, so mint one link per install and revoke the one you need to. #### How do I disconnect? Remove the connector in your AI client to stop normal use. For a lost device or a departing member, also remove the person's organization membership: that ends every account MCP session they hold, and the next call fails whatever the client still has. For one of your users, revoke their access link or change the trait their access depends on. #### Does it cost anything? Account tool calls are neither ingestions nor recalls, so they are not metered: reading your usage over MCP costs nothing. `recall` and `answer` on the end-user server are charged the plan's recall rate, exactly as the same calls on the Memory API are: a tenth of a credit on Free, nothing on Flex and Enterprise. No plan caps the number of calls. #### Will it appear in the Claude directory? past.dev plans to join the directory. Until then, use the custom-connector setup in section 2. A directory listing would change discovery only, and would use the same OAuth flow and the same security controls.