# Safe connection checklist

AI Workshop · episode 2: Connecting and authorizing
https://mihalkevich.com/en/workshop/auth

- [ ] Keys live in .env.local or a secrets manager, .env* is in .gitignore
- [ ] One key per service, least privilege, a clear name
- [ ] Only the MCP servers the project needs are connected; for each you know what it can reach
- [ ] The agent settings have a command allowlist; dangerous ones (rm -rf, git push --force, deploy) need confirmation
- [ ] The agent has no production access; production goes through CI with environment secrets
- [ ] There's a leak plan: where to revoke, who reissues, what to check in the logs

## Harness in this episode

Permissions and secrets are the harness perimeter: the agent can make mistakes, but can't step outside what it was given.

## Official documentation

- [Claude Code — identity and access](https://code.claude.com/docs/en/iam)
- [Claude Code — MCP](https://code.claude.com/docs/en/mcp)
- [MCP specification — authorization](https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization)
- [OAuth 2.0 (oauth.net)](https://oauth.net/2/)
- [Claude Code — security](https://code.claude.com/docs/en/security)
- [GitHub Actions — using secrets](https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets)

— mihalkevich school
