Managing Permissions with the Cycle MCP.

With read-only access, the LLM connected to the Cycle MCP (which I will refer to as Claude for this guide) can find out what's wrong in your hub but can't change anything. This page shows how to recognize when that's what's stopping a fix, and how to reconnect the connector with more permissions.

API vs Login Type Permissions

When using a Cycle API key for interactions with the MCP, permissions are set by the key itself. This guide has to do with using the login feature generally used when setting up a Claude connector or ChatGPT connection. The API keys are generally used when using Claude Code or Codex (respectively


The concept

The Cycle MCP connector gets its permissions, called scopes, when you connect it and approve access on Cycle's authorization screen. Each scope unlocks a set of tools:

Scope

What Claude can do

read

Inspect state, logs, telemetry, DNS, and run diagnose. Nothing changes.

write

Change resources, for example create a DNS record, or start and stop a container.

exec

Run commands inside a running instance or virtual machine.

Tools a session isn't allowed to use don't appear to Claude at all. So a read-only session doesn't fail when it reaches a fix. Claude finds the cause, names the fix, and tells you it can't apply it.

How read-only shows up

There are three signals, usually together.

Claude says it can't make the change. Its answer ends with something like "The connector is read-only, so you'll need to make this change in the portal." This is the clearest sign.

A diagnostic finding suggests a tool Claude doesn't have. Every diagnose finding names a next step. When that step changes something, like manage_dns_record or cycle_control_container, and Claude doesn't take it, the tool isn't available in the session.

The session reports read-only scopes. Ask Claude "What permissions does the Cycle connector have?" It answers from the message the connector sends when the conversation starts, which names the hub and its scopes, for example:

This session is authenticated to hub "Acme" with connector scopes: read.

That third check is the definitive one.

One error is easy to mistake for a permissions problem. Some Cycle API endpoints only work from the portal, and they return 403.restricted-portal no matter which scopes you grant. Reconnecting won't change that, so don't treat it as a reason to reconnect.

Do it

In a guide listed here, Claude has found that no LINKED record points at the web container in the acme-web environment, and it can't create one.

  1. Confirm the connector is read-only. Ask:

    What permissions does the Cycle connector have?

    If the answer lists only read, reconnecting will unlock the fix. If it already lists write, the problem is something else, so ask Claude why it can't apply the fix.
  2. Disconnect the connector in Claude. In the Claude app, open Settings → Connectors, find the Cycle connector, and choose Disconnect. If your organization added the connector for everyone, an organization owner may need to do this.
  3. Connect it again. Choosing Connect opens Cycle's authorization screen in your browser.
  4. Grant the scopes on Cycle's screen. Select write as well as read. Add exec only if you want Claude to be able to run commands inside instances. It isn't needed for this fix.
  5. Start a new conversation. A conversation that was already open may keep its original tool list, so the new tools might not appear until you start fresh. Then check the permissions again:

    What permissions does the Cycle connector have?

    The answer should now list the scopes you granted.
  6. Ask Claude to apply the fix.

    Create a LINKED record for acme.example.com pointing at the web container in acme-web, with TLS on.

    Claude describes the exact change and waits for you to confirm before it creates anything. Once the record exists, ask Claude to check the container again. The unreachable check can now test DNS and send a live request, and a successful request confirms web is reachable.

What just happened

Nothing about the diagnosis changed. Claude found the same cause with read-only access that it would have found with full access. Permissions only decide who applies the fix: you in the portal, or Claude after you confirm.

The permissions belong to the connection, not to Claude. Cycle records what you approved on its authorization screen, and every tool call runs under those scopes. That's why the fix is to reconnect instead of asking Claude to try harder. Claude has no way to raise its own permissions.

Granting write doesn't let Claude act on its own. It still proposes each change and waits for your confirmation. What changes is that, once you confirm, the change happens in the conversation instead of in a separate trip to the portal.

To go back to read-only after the fix, disconnect and reconnect again, this time approving only read.

Cookies

Cookies Preferences

We run basic, anonymous analytics by default to measure site traffic. By clicking "Accept," you allow additional cookies for advanced app improvements and tailored advertising. Choose what you share by clicking "Customize."