Security
How WhoisExtractor MCP protects your account and data.
Authentication
OAuth 2.1
Sign in through secure OAuth. Your WhoisExtractor sign-in credentials are never shared with AI clients.
Authorization
Scoped permissions
Connections receive only the permissions you grant during consent.
Account isolation
OAuth identity → authenticated user
The server derives the customer from your OAuth token. AI requests cannot access another customer's data by supplying a different ID.
Write protection
Preview → confirmation → execution
Support ticket actions require preview and explicit confirmation with an idempotency key.
Data protection
No sign-in credentials · No tokens in logs
OAuth tokens are not stored in audit logs. MCP audit entries record tool usage metadata only.
Auditability
MCP requests logged
Tool calls are logged with request IDs for security and troubleshooting.
Revocation
Disconnect anytime
Revoke any AI connection from Dashboard → Settings → Connections on whoisextractor.com.