Target authorization
Non localhost external targets require an organization assertion before exploration or state changing automation.
Molar runs close to sensitive application behavior, so control is part of the product. The platform uses organization scoped access, exact origin rules, scoped tokens, approval gates, and explicit side effect handling across browser, clone, trace, and MCP workflows.
Non localhost external targets require an organization assertion before exploration or state changing automation.
MCP tools carry scopes, and high risk actions identify themselves as state changing, destructive, or approval requiring.
Trace artifacts use authenticated organization checks and signed or expiring references for reads.
Login tools use saved, exact origin credentials or opaque identity references. Connector controlled OTP and message reads are limited to identities provisioned for the organization.
payment_intent.succeededOpen checkoutScreenshot captured200
Confirm paymentPOST /webhooks/payment200
Receive receiptTest inbox matchedready
Molar uses organization scoped access, target authorization, approval gates, and controlled artifact reads. Contact us for the current security and deployment details.
Talk through your use case4242 4242 4242 424208 / 28 · Test cardPOST /webhooks/payment signature verifiedHave a specific workflow in mind?
Let’s talk it through
Contact us for current security documentation and deployment details. Compliance status depends on the specific service and customer arrangement.
The identity tools are restricted to connector provisioned identities for the organization.
High risk actions identify their scope and may pause for Attention or confirmation, depending on the action and runtime policy.
Choose a concrete workflow. We’ll help you get the right setup for your application.