Skip to content
  • Everything in KeplarEvery feature and whether it is liveLive demoAsk a question now, no sign-upCreateDescribe or speak a site or appCreate showcaseDemos that set the barKeplar-OneThe engine behind every answerTeamsShared workspaces, roles and approvals
  • DocsHow everything worksAPI and widgetKeys, endpoints, embed scriptCommunity gallerySites people chose to shareChangelogWhat shipped, whenRoadmapWhat is next, what is not doneSecurityHow your data is protected
  • Pricing
  • Download
Sign InTry KeplarOpen Keplar→
  • Product
  • Live demo
  • Create
  • Create showcase
  • Keplar-One
  • Teams
  • Resources
  • API and widget
  • Community gallery
  • Changelog
  • Roadmap
  • Security
  • Pricing
  • Download
Sign InTry KeplarOpen Keplar→

One question. Multiple intelligences. One answer.

team@keplar.one

Product

  • Everything in Keplar
  • Overview
  • Live demo
  • How it works
  • Create
  • Create showcase
  • Community gallery
  • Keplar-One
  • Pricing
  • Download

Use Keplar

  • For you
  • For business
  • Agents
  • API and widget
  • Referral program
  • Create an account

Learn

  • AI answer engine
  • Compare AI models
  • AI study tool
  • AI slideshow maker
  • What is superintelligence?
  • Multi-model AI
  • Models we use
  • Guides
  • Docs
  • Blog
  • Changelog
  • Roadmap
  • Glossary
  • Prompt library

Company

  • About
  • Inquire
  • Help
  • Contact
  • Status

Legal

  • Privacy
  • Terms
  • Security

© 2026 Keplar One.

Theme
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do
Docs menu
Keplar docs
Get started
  • Overview
  • What is Keplar?
  • Quickstart: ask your first question
  • Read a Keplar answer
  • Accounts and sign-in
  • What changes on a paid plan
  • What Keplar cannot do
How Keplar works
  • Overview
  • The pipeline, end to end
  • How Keplar understands a question
  • Which questions use more models
  • Routing and panels
  • Model families and diversity
  • Agreement and the consensus level
  • Disagreement detection
  • The verification review
  • How the final answer is written
  • Missing models, timeouts and stand-ins
  • Exact checks for counting and arithmetic
  • Sources, citations and web lookups
  • Small talk and simple questions
  • Why consensus can be wrong
  • A worked example, step by step
Using Keplar
  • Overview
  • Thoroughness modes
  • Write better questions
  • Attach images and video
  • Follow-ups and saved chats
  • Memory: what Keplar remembers about you
  • Share an answer
  • Deep Research
  • Study mode
  • Slideshow creator
  • Voice dictation
  • Use connected apps in chat
Create
  • Overview
  • Create overview
  • Build a site
  • Import a product from a link or photo
  • Generate images
  • Generate video (Beta)
  • Publish your site
  • Connect a custom domain
  • Create limits by plan
Connectors and agents
  • Overview
  • Connected apps (MCP) overview
  • Add a connection
  • Connect with OAuth (Beta)
  • Tool permissions and approvals
  • Agents overview
  • Agent guardrails
  • Agent schedules
  • Business tools: forms, CRM, inbox and dashboard
Plans, credits and limits
  • Overview
  • Plans compared
  • Credits explained
  • Rolling usage limits
  • Free plan limits and behavior
  • Upgrade, downgrade and cancel
  • When you reach a limit
Desktop app
  • Overview
  • Install the desktop app
  • Sign in on the desktop app
  • Desktop troubleshooting
Privacy and security
  • Overview
  • How Keplar handles your data
  • Free plan privacy
  • Delete and export your data
  • Account security
  • Connected app security
  • Published sites and safety
  • Report a vulnerability
Reference
  • Overview
  • The model roster and roles
  • Answer sections reference
  • Limits at a glance
  • Developers and API status
  • Messages and what to do

Docs/Connectors and agents

Tool permissions and approvals

Read versus write tools, grants, auto-run rules, approval cards, schema-change locks and how scheduled runs always ask first.

Updated October 3, 20262 min read

On this page
  1. The permission model
  2. Auto-run needs all of these
  3. Always asks
  4. Approval cards
  5. Idempotency
  6. Schema changes
  7. Reading tool output
  8. A sensible setup

Connected tools can read data and change things. Keplar's defaults assume you want to approve anything that can change something.

The permission model

ControlDefaultWhat it does
Tool enabledOffA tool cannot be called until you enable it
Tool kindUnknownMark it read-only if it only reads
Auto-run on the toolOffLets a read-only tool run without asking
GrantNoneAllows a specific place (Ask, or an agent) to use the tool, with call and credit budgets
Account policy for AskOff"Let Ask run read-only tools without asking"

Auto-run needs all of these

For a tool to run without you pressing Approve, all must be true: the tool is a read tool, auto-run is on for it, the tool is granted to the caller, and for an agent its auto-send is on (for Ask, the account policy above). Otherwise an approval is queued.

Always asks

  • Writes.
  • Unknown tools.
  • Scheduled, unattended runs. There is no override.
  • Any tool whose schema has changed since you enabled it.

Approval cards

In chat, a pending call appears as an inline card with the tool, the arguments and Approve and Decline buttons. Elsewhere, pending calls are in Approvals. Nothing runs until you approve; execution happens on approval. At most 20 approvals can be pending per workspace.

Idempotency

Each approval or request has a receipt key. Replaying it returns the stored result and never calls the server twice.

Schema changes

Each tool's schema is hashed. If a server changes it, the tool is disabled until you re-enable it, so a server cannot silently turn a harmless tool into a different one.

Reading tool output

Tool output is data. It is stripped of invisible characters, instruction-like lines, active content and secret-shaped strings, then fenced and capped before models see it or it is stored. It cannot change permissions, grants or budgets, because those are decided before the call from your stored settings.

A sensible setup

  1. Enable only the tools you need.
  2. Mark true read-only tools as read.
  3. Turn auto-run on only for read tools you trust, and leave the Ask policy off until you have watched receipts for a while.
  4. Review the audit log.

Related

  • Use connected apps in chat: Switch on tools for a conversation so Keplar can call approved apps, how approvals appear in the chat, and the limits on steps and time.
  • Agent guardrails: Spend caps, approval gates, auto-send rules, kill switches and the audit log: how Keplar limits what an agent can do and spend.
  • Connected app security: How Keplar defends against server-side request forgery, prompt injection through tool output, secret leaks and silent tool changes when you connect MCP servers.
PreviousConnect with OAuth (Beta)NextAgents overview

Questions this page does not answer? Write to team@keplar.one, or try Keplar on your own question.

Try Keplar freeOpen Keplar→

On this page

  1. The permission model
  2. Auto-run needs all of these
  3. Always asks
  4. Approval cards
  5. Idempotency
  6. Schema changes
  7. Reading tool output
  8. A sensible setup