Prerequisites
- An MCP connection request started from a compatible client.
- An active eligible PayCanvas membership.
- The six-digit code from your authenticator app.
Review the consent screen
- Confirm the client name, remembering that the client supplies this display label.
- Confirm the callback belongs to the client you started from.
- Review the baseline read-only operator access.
- Select optional permissions only when you need them:
- start confirmed source collection;
- record confirmed, non-payroll resolution reviews;
- let an authorized payroll operator apply an offered payroll resolution;
- start a confirmed payroll calculation.
- Choose Allow connection or Deny.
Before an assistant can change anything, PayCanvas shows a preview and waits for confirmation. It also rechecks your live account access, verification status, permission, and the current payroll version. Giving an optional permission does not let an assistant act silently.
What permissions do not allow
The operator connector cannot change payroll policy or rates, invent identities, access provider credentials or raw reports, approve payroll, lock a run, export or email a worksheet, submit payroll, or pay anyone.
Calculation finality is also separate from approval: a final result means pay-affecting review is clear and money reconciliation passed.
Change permissions
Existing clients do not receive new permissions silently. To change a connection's permissions:
- Revoke or disconnect the existing connection.
- Start a new Sign in with PayCanvas connection.
- Review and select the optional permissions you need on the PayCanvas consent page.
Disconnect safely
- Remove or disconnect PayCanvas in your MCP client to clear that client's local credentials.
- For immediate server-side blocking, ask PayCanvas to revoke the connection.
Current limitation: The payroll workspace does not yet offer self-service connection revocation. If you need immediate server-side disconnection, contact PayCanvas Support with the client name, payroll account, and approximate connection time. Do not send tokens or authorization codes.
Expected result
After local disconnection, the client no longer uses its saved credentials. After server-side revocation, requests fail live authorization even if an old access token has not reached its expiry.
Troubleshooting
authorization_required: the connection lacks the optional permission or your role is not authorized for the action.invalid_token: reconnect; do not copy a token between clients or endpoints.insufficient_scope: revoke and reconnect with the reviewed permission you need.- Client is connected to the wrong PayCanvas surface: disconnect it and create a separate OAuth client for the operator endpoint.