Agent access policy

Public catalog reads do not require an account. Managed installs, publishing, workspace writes and other protected actions require explicit user approval through the local browser authorization broker.

This local broker is not OAuth and is not an authorization server for the public MCP endpoint.