MCP 0.4.2 / Operations
MCP audit, retention, and privacy
Review connection and tool activity without retaining credentials or command payloads.
Activity records retain client identity, tool or command classification, outcome, and time. They do not retain raw tool arguments, authorization codes, access tokens, refresh tokens, Application Passwords, or credentials.
Authorization codes and tokens are stored only as hashes. User activity retention defaults to 90 days; Pro may configure up to 365 days. Disconnecting an app invalidates future access without deleting the WordPress account or owning add-on data.
Review activity after every new client, scope change, write-tool activation, approval, and revocation. Export only sanitized support information and rotate any credential accidentally exposed outside the intended client.
