---
title: "Documentation — PageWeave"
---

> For the full documentation index, see [PageWeave Documentation](https://pageweave.dev/docs) or fetch [llms.txt](https://pageweave.dev/llms.txt).

# MCP Write Lock

Lock a website for your own MCP access: reads keep working, every write is refused until you unlock. Use it when an agent must stop changing a site — while you review, or when a task must not touch one particular project.

## How it works

- The lock is **per website and per user**. Locking a site never affects other members' agents — each user controls their own lock.
- While locked, every MCP write tool that resolves the website fails with `isError: true` and a message containing a deep link to the unlock page. Reads (pages, tables, feedback, releases, …) are unaffected.
- Account-level tools that resolve no website (domain and DNS record tools such as `add_dns_record`, `update_dns_record`, `delete_dns_record`) are not affected. Tools that take a website and act on it — including `manage_domain_dns` and `purchase_domain` with a `website` argument — are.
- The lock also stops pending approvals: a confirmation created before the lock fails when replayed, and a pending domain purchase releases its authorized (manual-capture) payment instead of attaching a serving hostname to a locked site.

## Lock and unlock

Dashboard: open the website's **MCP access** card → **Manage MCP access** (`/websites/<id>/mcp_lock`).

- **Lock** — writes stop immediately.
- **Unlock indefinitely** — removes the lock; writes work until you lock again.
- **Timed unlock** — presets (15 minutes, 1 hour, 4 hours, 24 hours) or a custom window from 1 minute to 7 days. When the window ends the lock re-engages automatically — no scheduled job, just the timestamp.
- **Lock now** — closes an open unlock window and locks again.

`get_website` reports `mcp_locked` for the calling user, so agents can check before attempting writes.

The unlock link carries no token: opening it only lets a signed-in user manage their own lock.
