How to approve MCP transactions
MCP separates conversation, confirmation, and transaction signing.
Read-only tools can explain Deploy, list agents, and simulate yield without sign-in. Fund-moving tools first validate details and confirm them in chat. They then open the Deploy web app, where you approve the actual transaction with your own wallet.
The MCP server never holds or requests your private key. An agent's session key is a separate, scoped permission that expires or can be revoked according to the agent's controls. Review every amount, address, chain, and permission scope before signing.
If a tool requests a secret outside the normal web-app approval flow, stop and use Contact & links.