Connect Claude, ChatGPT, Cursor or any MCP-capable agent and let it deploy an app, read logs, explain a failed build or restart a database. It can only do what you allow.
A built-in MCP server with one tool per action, driven through the same authorization gates a person goes through. Pick the agent, create a token with the capabilities and expiry you want, paste the printed configuration, and the page lights up on the agent's first call.
A token is a principal with its own capabilities, scoped to the teams, projects or apps you choose. Take a capability from its owner and every token they hold is blunted at once. A web assistant connects through an OAuth consent screen, and a team-level switch is the kill switch.
Install takes one command on a server you already pay for. What you do with the money you get back is your business.