Choose access by domain
New selections start with No access. Choose Read or Read & write for each domain you need. Read all selects available read actions; Read & write all selects every available action, including writes; Clear all removes the selection. At least one permission is required to create a key or connect an app.
Read & write includes consequential actions within the domain, including sending, deletion, automation or execution where listed. It grants permission; selecting it does not itself perform those actions. Provider readiness, business rules and other server checks still apply.
Narrow an integration’s access
Expand Customize permissions to select individual actions. Partial selections display Custom. Existing API keys and connections keep their exact permissions and show grouped summaries; expand a domain to inspect the granted actions. Seeing Custom does not mean access has changed. MCP consent can grant only the scopes requested by the registered OAuth client. A Limited request shows the exact available actions for that domain. Read & write includes only those requested actions, even if the client requested writes without reads. MCP excludes webhooks and operational handoff creation; those remain M2M-only. Examples:- Reporting integration: Reporting → Read; all other domains → No access.
- Catalog editor: Commerce → Read & write, or use Customize permissions for catalog-only access without sales reads.
- Conversation assistant: Conversations → Read for review, or Read & write when sending and conversation management are intended.
Compatibility and connection approval
Domain choices expand to existing scope strings. The public API still accepts and returns the samescopes arrays; no wildcard permissions or new authorization format were introduced. Existing keys and OAuth grants do not gain new scopes when the catalog grows.
Codex and Claude control their own tool-approval interfaces. Their approval prompts do not replace Visito’s tenant and scope checks. Switching businesses in the Visito dashboard does not switch a saved connection.
Custom installation is the v1 distribution method. Store/directory publication is deferred to v2. See Claude setup for the verified custom connection flow.