Forge MCP Privacy
Privacy Disclosure
This disclosure explains the data boundaries for using Forge through an external MCP client.
Scope
This disclosure applies to the Forge MCP endpoint at https://forge.thevikingstack.com/mcp. It describes the Forge side of an MCP connection. The external client you choose has its own privacy practices and controls.
External MCP Clients
Claude.ai, Codex, Claude Code, or another compatible client sends tool requests to Forge and receives the authorized result. Information placed in prompts, tool inputs, or returned results may therefore be processed by that external client. Review the client's privacy settings and policies before connecting or approving a tool call.
Forge uses browser-based OAuth authorization. Do not give an MCP client your Forge password, access token, refresh token, provider credential, or context handle as prompt content.
Identity and Account Context
Forge identifies the caller through an authenticated, signed-in Forge identity and OAuth grant. An ordinary grant is immutably bound to the account selected at consent. Forge checks current membership, role, entitlement, and MCP controls on every request.
A verified platform owner may authorize a distinct platform grant. It begins without a customer account and uses an explicit, expiring context handle for customer-scoped work. The handle is bound to the actor, OAuth client, grant, and account, and is reauthorized whenever it is used. It expires after 12 idle hours or 24 total hours.
Data Forge Makes Available
Authorized reads return Forge identity, account, connection, project, project-asset, and eligible AEO metadata. Project and asset reads are metadata-only. Forge MCP does not expose secrets, raw provider tokens, stored asset bodies, generic database access, or provider payloads.
Authorized account admins, owners, and platform contexts can explicitly create projects and bounded draft assets. Draft content is supplied in the tool request and is limited to supported inline text formats up to 100 KB. Verified platform owners can also explicitly provision an account for an existing verified target identity. Forge MCP does not send, publish, scan, enrich, validate connections, or perform destructive actions.
Security Records and Retention
Every mutation writes a redacted, write-ahead audit record containing the actor, client, grant, account, tool, outcome, request ID, and timing. Payloads, credentials, secrets, provider data, and asset bodies are not written to that audit record. Mutation audit records are retained for 30 days and removed by daily cleanup.
Forge also keeps the OAuth grants, tokens, expiring context handles, bounded idempotency records, and rate-limit state required to authorize and protect the service. Expired records are removed by daily cleanup. Forge does not create MCP protocol sessions or provide a Usage & History or per-session activity timeline product.
Platform-Owner Support Access
Verified platform owners may use the distinct platform grant for support operations. Customer-scoped access requires an explicit expiring context handle and remains subject to authorization, rate limits, and mutation audit. An account owner's MCP opt-out revokes ordinary customer grants and tokens, but does not block this audited platform-owner support path. A global service control can stop all MCP access.
Your Choices
- Deny consent before a grant is created.
- Disable unneeded tools in the external client.
- Disconnect Forge in the client.
- Revoke a connected OAuth grant from Forge Connections.
- If you are an account owner, opt the account out of ordinary Forge MCP access; re-enabling does not recreate revoked grants.