Documentation
Connect an agent to your workspace.
Enable the local MCP server, issue a credential, and configure a client using the app’s own connector.
1. Prepare the desktop app
Set up your vault in Settings → Security and unlock its keys. Open Settings → MCP, enable the MCP server, and keep the desktop app running. It can remain in the tray.
2. Create an agent grant
Enter an agent name, choose permissions, and optionally set an expiry. Select Generate agent PEM, then Save PEM file.
- Save the credential before dismissing it. It is shown only in the current settings session.
- Store it privately, outside shared or synced app-data folders.
- If you lose it, generate a fresh grant and revoke the old one. It cannot be recovered from the UI.
3. Configure the client
Enter the saved PEM’s absolute path in Settings and copy the displayed mcpServers configuration into your MCP client. The example below shows the shape; replace both paths with the real paths from your installation.
{
"mcpServers": {
"cqs": {
"command": "C:\\Apps\\CalciteQuickSolve.exe",
"args": [
"--mcp-connect",
"C:\\Users\\you\\agent.private.pem"
]
}
}
} Choose permissions for the task
Permissions apply to a workspace and its keys, including future keys. They do not restrict a grant to an individual note.
- Read library: retrieve notes, attachments, versions, trash, calculation data, search results, exports, and encrypted backups.
- Edit library: create or edit notes and attachments, and commit calculations, variables, functions, and graphs.
- Delete & restore: trash, restore, or purge notes and remove calculation history.
- Sign, encrypt & decrypt: use CQS keys for cryptographic operations and secure note exchange. Changing note protection also requires Edit library.
- Manage CQS keys: generate, import, rename, archive, trust, or choose storage keys. Deleting keys also requires Delete & restore.
- Export private keys: export private keys protected by an agent-chosen passphrase. The agent can recover those keys.
- Manage other agents: create credentials, change any grant’s permissions, revoke grants, and configure the server. This can grant full access to itself or others.
- Settings, import & backup: change app settings and perform related import, backup, and index operations. Replacement imports also require Edit and Delete.
- Administer vault: change auto-lock or the master password. Treat this as authority comparable to private-key export.
Locking, expiry, and revocation
Locking the app UI does not stop authorized agents. Their grants can continue working after an app restart without your master password. Disable MCP or use Revoke access to stop subsequent requests; a request already in progress may finish.
- You can disable the server or revoke a grant while the UI is locked.
- Adding, restoring, or changing permissions requires the UI vault to be unlocked.
- Expiry also stops subsequent requests.
- Changing the vault password does not revoke grants.
- Revocation cannot recall exported content or keys, or automatically revoke other grants an agent created.
Understand the credential boundary
A PEM is both an authentication credential and decryption authority. Normal API responses do not return private keys without explicit export permission, but a PEM together with access to the app’s grant and key-store files can permit offline decryption outside API permission checks.
Check a connection
Confirm that the main app is running, MCP is enabled, the executable and PEM paths are absolute, and the grant is neither expired nor revoked.
- After moving the executable, update the client’s command path.
- After changing the local server port, issue a fresh credential with the new connection metadata and revoke the old one.
- Review Recent agent activity for tool names, outcomes, grant names, and times. The log retains the latest 1,000 operations without request payloads.
- Agent credentials and grants are device-local and excluded from ordinary library backups. Create fresh grants after restoring to a new installation.