PageWeave / Docs

Platform

Markdown

MCP Write Lock

Lock a website for your own MCP access: reads keep working, every write is refused until you unlock. Use it when an agent must stop changing a site — while you review, or when a task must not touch one particular project.

How it works

  • The lock is per website and per user. Locking a site never affects other members' agents — each user controls their own lock.
  • While locked, every MCP write tool that resolves the website fails with isError: true and a message containing a deep link to the unlock page. Reads (pages, tables, feedback, releases, …) are unaffected.
  • Account-level tools that resolve no website (domain and DNS record tools such as add_dns_record, update_dns_record, delete_dns_record) are not affected. Tools that take a website and act on it — including manage_domain_dns and purchase_domain with a website argument — are.
  • The lock also stops pending approvals: a confirmation created before the lock fails when replayed, and a pending domain purchase releases its authorized (manual-capture) payment instead of attaching a serving hostname to a locked site.

Lock and unlock

Dashboard: open the website's MCP access card → Manage MCP access (/websites/<id>/mcp_lock).

  • Lock — writes stop immediately.
  • Unlock indefinitely — removes the lock; writes work until you lock again.
  • Timed unlock — presets (15 minutes, 1 hour, 4 hours, 24 hours) or a custom window from 1 minute to 7 days. When the window ends the lock re-engages automatically — no scheduled job, just the timestamp.
  • Lock now — closes an open unlock window and locks again.

get_website reports mcp_locked for the calling user, so agents can check before attempting writes.

The unlock link carries no token: opening it only lets a signed-in user manage their own lock.