Review connected apps
When you connect an MCP client — Claude Desktop, Cursor, or anything else speaking MCP — it asks for your approval on a consent screen. This is the list of approvals you granted, and where you take them back.
Where to find it: Settings → Connected apps
No special organization permission is required. The list is yours: it shows the apps you authorized, not the organization's. Other members see their own.
What a grant covers
Each grant is pinned to two things at once, which is why the same app can appear more than once:
- One user — you. Revoking yours does not touch a colleague's access.
- One organization — the list only shows grants for the organization you are currently in. Switch organizations to review the rest.
The Access column lists the permissions the app is locked to, exactly as approved on the consent screen. An app cannot widen its own access afterwards; it has to ask again.
Reading the list
| Column | Means |
|---|---|
| App | The client's registered name, or its client ID if it never supplied one |
| Access | The permissions approved for this grant |
| Toolboxes | Which of your toolboxes the app can run tools from — All tools, a count like 3 toolboxes, or — if it was never approved to run tools at all |
| Connected | When you approved it |
| Last used | When the app last called Elaichi, or Never |
Filter by app name, by a specific access level, or by usage. Never used is the useful one during a cleanup: it surfaces grants approved during a trial and forgotten.
Hover the Toolboxes column for the names, or click the row to open the app's own page.
What "All my tools" means
If the app was approved to run tools at all, you chose one of two things on the consent screen:
- All my tools — every connection you can use, including ones you connect after approving the app. This is the default, and what MCP clients saw before toolbox scoping existed.
- Specific toolboxes — only the toolboxes you picked. A toolbox the app can no longer reach (deleted, or a share you lost) simply drops out silently; the app never falls back to seeing everything.
Manage what an app can reach
Click an app in the list to open its page. Alongside the scopes and Disconnect button, the Toolboxes section lists what it's authorized for, with the status of each toolbox (usable, no longer usable, or deleted).
Choose Edit toolboxes to change the set — switch between All my tools and specific toolboxes, or add and remove individual ones.
Widening an app's toolbox access is allowed here even though its other permissions can't widen without a fresh consent. You're the one making the change, for yourself, so there's nothing to re-approve.
Changes to an app's toolboxes take effect immediately — on that client's very next call, not after a reconnect.
If an app was never approved to run tools, its page says so and there's nothing to edit; reconnect it from the client to ask for that permission.
Disconnect an app
Choose Disconnect on the row, or from the app's own page, and confirm.
Disconnecting takes effect immediately. The app's next call fails rather than degrading quietly, so expect a running MCP session to start erroring rather than politely stopping. Reconnecting means going through the consent screen again.
Good to know
- An empty list is the normal state until you connect a client — nothing is authorized on your behalf automatically.
- This is not the same as Connections, which is Elaichi reaching out to third-party accounts. Connected apps is the opposite direction: other software reaching in to Elaichi.
- Disconnecting is per-grant, not a global sign-out. To secure the account itself, see Secure your account.
- A toolbox's own page shows the flip side of this: how many connected apps reach it, and who they belong to. See Use your toolboxes.