Ask an agent
It connects to this stand over MCP and can only see what the account you pick can see. Ask it for something that account is not permitted to read and watch what it says — not a shorter list of results, a refusal it cannot see past.
Sign in as
Can read:
This is the real OAuth walk, and this page has no standing access to anything: it registers itself with this stand’s authorization server, you sign in with the email and password the front door printed when you created an organization, and you choose on the consent screen which layers it may reach and whether it may write. The token that comes back acts as you, bounded by that ceiling and re-checked on every request — withdraw it and the next call is refused.
Model
Your key, your browser. It is stored encrypted on this device and sent only to the provider you chose. It never reaches this stand — nothing here ever receives a request carrying it.
Document
Optional, and text only — Markdown. Attach one and ask the agent to add it to a layer: the bytes go with the call, so the model chooses the layer and never retypes the document. The two accounts above hold read and nothing else, so they are refused — and refused as a layer that is not there, because “you may not write here” and “there is no such layer” are deliberately the same answer. In your own organization it works if you allowed write on the consent screen.
Question
The agent is @dudko.dev/agent-web 0.0.13 — headless, in your browser, MIT. Nacre is the thing it is asking.
What you are looking at
Every call in the trace went to https://playground.nacre.work/mcp and
was answered by the same authorization service the console and the API use. The
badge on a call is the permission that tool needs: read and
write are separate, and holding one does not imply the other.
A tool marked not offered is one this connection did not get. For the
two published accounts that is nothing — they hold read and
the tools they lack, they lack by permission rather than by absence. For an
organization of your own it is whatever ceiling you approved:
a search client that cannot delete a document is what approving read-only means,
and the client never sees the tool at all.
The interesting answer is the one you get for the contract number. Nothing comes back, and the agent cannot tell you whether that is because the document is not there or because it is not permitted to see it. Neither can anybody else — the permission filter runs inside the index traversal, so the search never reached the document, and “no permission” and “no such object” are the same answer on purpose.
Nothing here runs on our machines
The agent is a bundle this page serves and your browser runs. There is no key of ours behind a proxy, so there is nothing to rate-limit and no bill a stranger can write. What leaves your browser is: your question and the tool results, to the provider you chose; and the tool calls, to this stand.
With a local model, not even that: the weights are downloaded once from Hugging Face, cached by your browser, and the answering happens on your GPU. These are offered here — Llama-3.2-3B-Instruct (about 2.2 GB of GPU), Qwen3-1.7B (about 2.0 GB of GPU), Phi-4-mini-instruct (about 3.4 GB of GPU) — and this page will not offer one over 4.0 GB: enough to try the product and no more, checked when the stand starts rather than after you have downloaded a gigabyte.