← Pando

Taking an agent’s access back

Any MCP client and Pando, for taking access back.

The question people ask before connecting an assistant is not how to connect it. It is what happens when they want it gone, and in most tools the honest answer is that you delete an integration and hope.

Open Agents and API keys in the app and revoke the key. It stops working on the agent’s next request, and nothing it already wrote is lost.

Set it up

  1. Point the client at https://pando.ink/mcp, which speaks streamable HTTP.
  2. Authenticate with OAuth 2.1 and dynamic client registration, or paste a key from Agents and API keys as a Bearer token.

What the list shows you

Every key is listed with its name, and which agent holds it when it is not your own. A key nobody has used yet also says never used, and that is a key you can take back without wondering what breaks.

What revoking does, exactly

Revoking is not the only lever

A smaller move often fits better than cutting the connection. Giving the agent a different bullet to remember in, on the agent’s row under Your agents in Agents and API keys, takes nothing back: its writing lands in the new bullet from then on, it may write there, and it keeps what it had in the old one. If the agent was made without the whole outline, you can take back one bullet it holds and leave the others: open that bullet’s Share sheet from its menu and remove the agent there. One that reaches your whole outline, as every connector does at first, can be cut back to one bullet: open that bullet, then the agent’s row under Your agents in Agents and API keys, and press Let it reach only “…”, the bullet you are in.

Deeper

Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this