> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bouncy.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and revoking access

> What a connected AI app can see and change, and how to disconnect it

## What a connected AI app can see and change

A connected AI app acts on your Bouncy account through the [Bouncy API](/introduction), limited by the access level you picked when you approved it.

|                                                                               | Viewer | Creator | Full Access |
| ----------------------------------------------------------------------------- | ------ | ------- | ----------- |
| Read deeplinks, stats, groups, geo presets, domains, websites and plan limits | Yes    | Yes     | Yes         |
| Create, edit, pause and delete deeplinks                                      | No     | Yes     | Yes         |
| Create, edit and delete groups                                                | No     | Yes     | Yes         |
| Draft and edit websites                                                       | No     | Yes     | Yes         |
| Connect and verify custom domains                                             | No     | No      | Yes         |
| See payment details, change your plan or buy anything                         | No     | No      | No          |
| See your password or sign-in sessions                                         | No     | No      | No          |
| Manage your team                                                              | No     | No      | No          |

The AI app only ever receives the tools its access level allows, and every tool call is checked again by the Bouncy API. A Viewer connection cannot create or change anything, whatever it is asked to do.

## Before you approve

The approval page shows:

* **The app's name**, as the app reported it.
* **Where you will be sent back**, for example `claude.ai` or `chatgpt.com`. Well-known apps (Claude, ChatGPT, VS Code, Cursor, and apps running on your own computer) show a **Verified** badge.
* **The access level**, with Full Access selected by default.

Only approve a connection you started yourself, from an app you use. If you did not just click Connect in an AI app, or the address shown is not one you recognize, click **Cancel**.

After every new connection, Bouncy emails you ("A new AI app was connected to your Bouncy account") and lists it on the [Connections page](https://app.bouncy.ai/connections). If you did not make the connection, revoke it and change your password.

## Confirmations for destructive actions

Every Bouncy tool is labelled for your AI app as read-only, write, or destructive (changing or removing something that may already be live). Claude, ChatGPT and most other AI apps use these labels to ask you before running a tool that changes your account.

* Keep confirmations on for `bouncy_update_deeplink`, `bouncy_set_deeplink_status`, `bouncy_delete_deeplink`, `bouncy_delete_group` and `bouncy_update_website`. These affect deeplinks and websites your visitors are already using.
* Read the confirmation before you approve it: which deeplink, which destination, which domain.
* Deleting a deeplink is permanent. The deeplink stops working straight away and its slug becomes free for reuse.
* There is no "delete everything" tool. Deletes happen one deeplink at a time.

## Choose Viewer for reporting

If an AI app only needs to answer questions like "how did my deeplinks do this week", connect it with the **Viewer** access level. It can read every stat it needs, and it cannot create, change or delete anything even if it is given bad instructions.

For developer tools and the Claude API, do the same with a **Viewer** API key.

## Revoke access

You can disconnect an AI app at any time, from either place:

* **Connections page:** open [app.bouncy.ai/connections](https://app.bouncy.ai/connections), find the app under **AI assistants** and click **Revoke**.
* **API dashboard:** open [app.bouncy.ai/api/dashboard](https://app.bouncy.ai/api/dashboard), find the key with the **AI connection** badge and click **Revoke**. This is also where you revoke API keys you pasted into developer tools.

The connection stops working within a minute. The AI app then reports that it needs to sign in again. To use it again later, connect and approve it again.

Removing Bouncy inside the AI app (for example deleting the connector in Claude) stops that app from using it, but the safest way to cut off access is to revoke it in Bouncy.

## Connections are separate from sign-in sessions

AI connections are not the same as the devices signed in to your Bouncy account:

* Signing out of Bouncy, or signing out of other devices, does **not** disconnect AI apps.
* Revoking an AI connection does **not** sign you out anywhere.

If you think someone else had access to your account, change your password **and** revoke any AI connections you do not recognize on the [Connections page](https://app.bouncy.ai/connections).

## When connections end automatically

* **Plan change:** if your account moves below the Growth plan, AI connections stop working within an hour. Upgrade, then connect again.
* **Connection limit:** you can have 10 AI connections. Approving an 11th disconnects the one used least recently.
* **Long inactivity:** if an app does not use its connection for 90 days, it has to sign in again.

## Prompt injection

AI apps follow instructions in the text they read, and not all of that text comes from you. A web page, a document, another connected tool, or data your visitors send (such as referrers and campaign tags) could contain text written to trick an AI into doing something you did not ask for.

What Bouncy does:

* Values that come from visitors, such as referrers, UTM values and platform names, are treated as untrusted. Bouncy shortens them, strips hidden characters and returns them only as data fields, never as instructions.
* Tools are labelled so AI apps ask before changing or deleting anything.
* The access level limits what any instruction can achieve.

What you can do:

* Use **Viewer** for reporting-only connections.
* Keep confirmations on for tools that change live deeplinks, and read each confirmation.
* Be careful when one chat mixes Bouncy with content from sources you do not trust, such as unknown web pages or files.

## API keys in developer tools

When you paste a Bouncy API key into a developer tool instead of signing in, the key's role sets what the AI can do, just like an access level.

* Treat the key like a password. Keep it in an environment variable or your tool's secure prompt, never in a file you commit.
* Create a separate key per tool, so you can revoke one without breaking the others.
* Revoke a key in the [API dashboard](https://app.bouncy.ai/api/dashboard) the moment you think it has leaked.

See [Authentication](/authentication) for more about keys and roles.

## How connections are protected

For security reviewers:

* Sign-in uses OAuth 2.1 with PKCE (S256 only). Authorization codes are single use and expire after 10 minutes.
* Access tokens expire after 1 hour and only work on `https://mcp.bouncy.ai/mcp`. Refresh tokens are rotated on every use, and each refresh checks that the connection is still active and your plan still includes it.
* Each connection is backed by its own API key with the role you picked. Bouncy never stores that key itself, only a hash.
* Every tool call goes through the Bouncy API, so the same role checks, rate limits and Request Log apply as for any API key.
