Security

How WhoisExtractor MCP protects your account and data.

Authentication

OAuth 2.1

Sign in through secure OAuth. Your WhoisExtractor sign-in credentials are never shared with AI clients.

Authorization

Scoped permissions

Connections receive only the permissions you grant during consent.

Account isolation

OAuth identity → authenticated user

The server derives the customer from your OAuth token. AI requests cannot access another customer's data by supplying a different ID.

Write protection

Preview → confirmation → execution

Support ticket actions require preview and explicit confirmation with an idempotency key.

Data protection

No sign-in credentials · No tokens in logs

OAuth tokens are not stored in audit logs. MCP audit entries record tool usage metadata only.

Auditability

MCP requests logged

Tool calls are logged with request IDs for security and troubleshooting.

Revocation

Disconnect anytime

Revoke any AI connection from Dashboard → Settings → Connections on whoisextractor.com.

← Documentation