Skip to main content

Kanera MCP FAQ

Common questions about what a connected AI agent can see and change, how its work is recorded, and how to remove it. Start with Connect Kanera to your AI agent if you have not connected one yet.

What can an AI agent see?

A personal OAuth connection or personal API key can read content that you can access in Kanera. This may include boards in multiple workspaces, standalone boards, guest boards, and your private personal notes. Board access still follows explicit board membership.

A workspace or board connection is limited to the destination where its credential was created. An unattended agent is also limited by its configured maximum scope.

Can the agent change my work?

For personal OAuth and device-code connections, the AI client must allow the write tool and the acting user must be an Editor on the target board. Kanera rejects writes for Observers even when the client allows the action. Read-scoped API keys and unattended agents can inspect, search, summarize, and report without changing Kanera.

Ask the agent to show a draft or proposed plan before applying a sensitive or broad change.

What can and cannot be deleted?

Kanera MCP cannot delete boards, lists, custom fields, notes, or note attachments. Delete those manually in the Kanera interface.

Workspace, board, list, label, field, option, retention, and list-order administration is also UI-only in the default MCP server. Agents can still read that configuration so they can target work correctly, and can create, style, position, move, or delete board-specific separators inside list lanes.

It can delete comments authored by the acting user, checklists, and checklist items when you explicitly request the operation, the client allows it, and your Kanera role permits it. Write-capable API keys or service connections are required when OAuth is not used. Cards can be archived individually or in batches. See the technical reference for the complete boundary.

Will I be able to tell what the agent did, and what I did?

Yes. Work done through an interactive agent connection is recorded as the agent acting for you, not as you. Comments and activity rows carry a via <agent> badge, notification groups read <person> via <agent>, and Work Done attributes the row the same way. Agent activity is never presented as your own.

You are also notified about it. Kanera suppresses notifications about your own actions, but not about your agent's, so you find out what it changed without having to go looking. The notification drawer's Agent tab collects all of it in one place; it only appears once an agent has acted for you.

A personal API key used by a script you run yourself acts as you, with no agent label.

Can I see what an agent is working on right now?

Yes, when the agent opens a run. runs.start puts a live chip on the card tile naming the agent and the job; runs.update keeps it current and can mark the run blocked when the agent is waiting on a person, which turns the chip amber. A terminal status ends the run and it stays in the card's history.

Every update doubles as a heartbeat. If an agent crashes, Kanera marks its run stalled after fifteen minutes rather than leaving the card showing "working" indefinitely.

Can a connection access multiple workspaces?

Yes. A personal OAuth connection or personal API key follows the connected user's accessible boards across workspaces and standalone boards. A workspace key or unattended agent remains pinned to one workspace or standalone board.

How do I disconnect an agent?

Open Profile settings -> API keys, find AI agent connection, and choose Disconnect agent. Existing access and refresh tokens stop working immediately.

Delete an unattended agent from Workspace settings -> API to revoke its credentials and active tokens.

Does Kanera MCP consume AI tokens?

Yes. Kanera does not charge AI tokens, but MCP results become context in your AI client and count toward that client's message or token limits.

My team runs Kanera at its own address. Which MCP address do I use?

The one your own Kanera shows you. Open Profile settings -> API keys and use the MCP address listed there rather than the hosted default. For a coding agent, copy the setup prompt from the same page so it is filled in for you.

When should I use an API key?

Use an API key for local stdio, a client that only accepts a static bearer token, or a custom deployment where OAuth is unavailable. Prefer OAuth for an interactive personal assistant and an unattended agent for CI or server-side automation.

If the only obstacle is that the client cannot open a browser redirect, such as a CLI or an SSH session, check whether it supports device authorization before falling back to a key. That keeps the connection tied to you and revocable in one place.

When you do use a key, create it Read-only unless the agent genuinely needs to change work. Kanera then refuses every mutation at the API, so the client's tool permissions are not the only thing standing between an unattended agent and your boards.

My agent can only run shell commands. Can it still use Kanera?

Yes. Install the Kanera CLI, log in once, and run kanera setup claude or kanera setup codex to write the instructions the agent needs. Every MCP tool is available as a command, so no MCP client configuration is involved.

The same CLI can act as a local stdio MCP server with kanera mcp, reusing the credential you already stored.

Still stuck?​