Normal
Contact

Access control

Normal permissions explained

Give each MCP Client only the access it actually needs.

Normal separates capabilities so access stays understandable. Each MCP Authorization also names the exact WhatsApp Connections it covers.

The four permission areas

  • Connection metadata lets an MCP Client see approved connection details.
  • WhatsApp Directory access exposes the connection scoped projection of active contacts and joined groups.
  • Stored Message read access allows observed conversation content to be retrieved.
  • Send access allows outbound attempts to eligible WhatsApp Recipients.

Read and send stay independent

Send permission never implies Stored Message read permission. Different MCP Clients can receive different access, and connections created later remain outside existing grants.

About Client Confirmation

Every outbound tool invocation requires Client Confirmation. It is an interaction presented by the MCP Client, not a separate server verified security boundary.

Private beta

Make WhatsApp useful to your AI.

Tell us about your workflow and the MCP Client you want to use.

Book a Normal call