Home / Categories / MCP
Is it safe to give an AI access to my account?
systeme.io documents no way to limit a key to part of the server, and what the server exposes includes deletions and sending newsletters to your list. It caps a key at 90 days and two per account, and the permission switches it documents sit in the AI tool rather than in systeme.io.
What the key is
A key is created under Settings, then MCP & API keys. Creating one asks for two things: a name, and an expiration date.
Those two fields are all systeme.io documents about setting a key up. Its documentation does not describe any way to limit a key to particular data, to particular features, or to reading without writing.
So nothing in that documentation describes a key covering less than the whole server, for as long as the key lives.
The limits systeme.io does set
- 90 days. systeme.io states that for security reasons MCP keys are valid for a maximum of 90 days.
- Two keys. An account can hold a maximum of two MCP keys at a time.
How the key travels
Two methods are documented: the key attached to an X-MCP-Key header, or the key included as an mcpKey parameter in the request URL. systeme.io says the dual approach exists because some clients cannot set custom headers.
Both of the published setup guides use the URL. The Claude instructions paste the key into the connector address, and the ChatGPT instructions set the authentication field to No Auth for the stated reason that the key is already in the URL.
systeme.io's own instruction on the matter, in its developer documentation, is to keep MCP keys secure, and it says that failing to do so may lead to significant risks.
The authentication method is not the one they recommend
systeme.io states that the current implementation does not yet support OAuth, which it names as the recommended authentication method.
It says OAuth support is planned, that it will improve security, and that it will remove the need for key expiration. Until then, keys are what exists.
What the connection can destroy or send
The tools are not read-only. From systeme.io's own capability list, an AI holding a working key can delete contacts, delete tags, delete price plans, delete coupons, delete digital products, delete physical products, and delete email campaigns and individual campaign steps.
It can also send a newsletter directly to your audience, not only draft one.
It cannot delete a funnel or a funnel step. systeme.io states that modifying or deleting funnels and funnel steps through MCP is not supported.
Where the permission switches actually sit
In the AI tool, not in systeme.io.
Claude's connector panel lists the tools in two groups, read-only tools and write or delete tools. Permissions offered are Always allow, Needs approval and Blocked across the tools, plus a Custom setting so each tool can be configured on its own.
ChatGPT is described differently. systeme.io says that depending on your ChatGPT plan and workspace settings, actions such as create, update and delete may be restricted or may require additional confirmation.
Every one of the six MCP feature articles repeats the same line: the AI will require confirmation prompts depending on the platform being used. systeme.io separately states that for sensitive newsletter actions, scheduling, sending and deleting, the AI asks for confirmation first.
The pattern is that the documented guard rails belong to the client. None are documented on the key itself.
What can be taken back
Deleted contacts are recoverable. They sit in a Recently deleted bin under Contacts for 30 days, with the deletion date and removal method shown, and can be restored from there.
Nothing equivalent is documented for tags, price plans, coupons or products removed through the server.
For deleted funnels and blogs, recovery is a paid support request, and only within 7 days of the deletion. That one is context rather than a live risk here, since the MCP server cannot delete a funnel.
What systeme.io does not document
Three gaps are worth knowing about before deciding anything.
- Revoking a key. The MCP article covers creating a key and naming it. It does not describe deleting or revoking one.
- Being told a key was made. systeme.io documents an email notification whenever a new public API key is created on an account. The MCP article says nothing about whether MCP key creation triggers the same alert.
- A scope model. No read-only key, no per-feature key and no per-key restriction appears anywhere in the MCP documentation.
Those are the facts systeme.io publishes. The decision rests on what is in the account and who else can reach the chat window it is connected to.
Did this answer your question?
Keep reading
- Is systeme.io free? Yes, and the free plan never expires. Here is exactly what fits inside it.
- Which systeme.io plan do I need? Count your contacts. That is nearly the whole decision.
- Should I build my website with a funnel or a blog? There is a third option, and it is the one their own help centre buries.