Security

Useful AI, without giving up control.

MCPtoAI is designed so that connecting AI to your computer never means giving it unrestricted access. Here is how your keys, devices and actions are protected.

Security built into every layer.

Your API keys stay on your device

Keys are kept in a single protected entry in your operating system's credential store — the Keychain on macOS. They are never uploaded to MCPtoAI, and requests to AI providers are made from your device.

Every device has its own identity

When you pair a device, it creates a unique Ed25519 signing key that never leaves the device. Each connection is signed and verified, and a captured request cannot be replayed.

Off, Ask or Allow

Every capability and MCP tool has a permission level. With Ask, nothing happens until you approve it in the conversation.

High-impact actions always ask

Writing files, opening applications or links, capturing the screen, camera or microphone, and running commands always require approval. Running commands is turned off by default.

Limited file access

The Device Agent works only inside the folders you allow. Paths are resolved before access, so tricks such as ../ or symbolic links cannot reach other locations.

Protected connections

All traffic between the web app, the relay and your device is encrypted. The web app connects to a device with short-lived tickets that only its owner can obtain.

Safe MCP connections.

MCP servers extend what AI can do, so they follow the same principles as the rest of MCPtoAI.

Learn about MCP

  • Remote MCP servers must use HTTPS
  • Private and local network addresses are blocked for remote servers
  • Local MCP programs can only be added on the device, never from the web
  • Sign-in tokens and server secrets are stored on your device

What is stored where.

A clear account of where your information lives.

Stored by MCPtoAI

  • Your account details
  • Your paired devices and their public keys
  • Conversation history, so you can continue on any device

Stays on your device

  • AI provider API keys
  • The device's private signing key
  • MCP sign-in tokens and server secrets
  • Your permission settings and files

Shared with services you choose

  • Your messages go to the AI provider you select
  • Tool calls go to the MCP services you connect

Security questions

Does MCPtoAI store my API keys?

No. Your keys stay in your operating system's credential store on your device. MCPtoAI's servers never receive them.

Can the AI do something without my knowledge?

Only what you have set to Allow. Capabilities set to Ask wait for your approval, and high-impact actions always ask — whatever the setting.

How do I remove a device's access?

Disconnect the device in MCPtoAI Desktop. This removes it from your account and deletes its session. You can also clear all local MCPtoAI data, which deletes the stored keys and the device identity.

Stay in control of your AI.

Install MCPtoAI Desktop and decide exactly what AI may do on your computer.