Security and permissions

Ternary MCP uses your existing Ternary identity and permissions. Connecting an AI assistant does not create a separate Ternary user, bypass existing access controls, or give the assistant broader access than you already have.

Authentication

Ternary MCP uses OAuth 2.1.

When you connect a supported AI client:

  1. The client opens a Ternary sign-in page.
  2. You sign in with your existing Ternary credentials.
  3. You approve the access request.
  4. The client receives access scoped to the MCP connection.

No Ternary API key is required.

⚠️

Your Ternary user must already exist. Connecting an AI assistant does not create an account.

Regional separation

Use the MCP server that matches the region where your Ternary tenant is hosted.

https://core-api.ternary.app/mcp

A user that exists only in the US environment cannot sign in through the EU MCP server, and vice versa.

Ternary permissions still apply

Every MCP tool call runs as the authenticated Ternary user. Ternary checks requests through the same authorization layer used by the Ternary web application.

That means:

  • You only see tenants you can access
  • You only see reports you have permission to read
  • Data returned by cost queries follows your Ternary access
  • Dashboard content follows the permissions available to you

Connecting MCP does not grant additional Ternary access. If you need access to another tenant or object, your Ternary administrator must grant it through Ternary.

Read and write access

The current Ternary MCP surface is predominantly read-only.

It can currently read or analyze:

  • Tenants
  • Dimensions and measures
  • Cost and usage data
  • Saved reports
  • Budgets
  • Dashboards
  • Cost alerts
  • Savings recommendations
  • AI spend and revenue

The only current write capability is Create report.

When you explicitly ask your assistant to save a cost analysis, Ternary can create a private report owned by you.

MCP cannot currently:

  • Create or edit budgets
  • Create or edit labels
  • Create or edit alert rules
  • Update billing rules
  • Delete reports
  • Change other Ternary configuration

Data transport

Ternary MCP uses HTTPS. Authentication uses short-lived OAuth tokens scoped to the MCP endpoint.

How data moves

Ternary does not independently push your Ternary data to an AI provider. Data is returned when your connected AI client makes an MCP request during your conversation or agent session.

A simplified flow is:

flowchart LR 
    A[You] --> B[Your AI client]
    B --> C[Ternary MCP]
    C --> D[Ternary data and authorization]

Ternary returns the result to the requesting client. What the AI provider subsequently does with conversation content is governed by your agreement and settings with that provider.

ℹ️

Review your organization's policies for the AI client you connect, particularly if you work with financial or commercially sensitive data.

Audit

Ternary MCP calls are logged for audit. Authorization is applied on each call rather than only at connection time.

Client approval

Ternary only accepts authentication from supported AI clients. An MCP client can be rejected even if:

  • The server URL is correct
  • The user has a valid Ternary account
  • The user can access Ternary normally

This is an intentional security control. See Supported AI assistants for the current list.

If a client asks for a client ID

Some supported clients require an OAuth client ID.

Use:

https://core-api.ternary.app/oauth/client-metadata.json

Do not provide a client secret. This client ID is used for both US and EU Ternary accounts. Only the MCP server URL changes by region.



Did this page help you?