Version 1.0.7
- Improved OAuth tokens are now re-checked against their owner on every MCP request, not just when the connection was first authorized. If the administrator who authorized an app is later removed or loses their admin role, that app's access stops immediately instead of lasting until someone remembers to revoke it, and the OAuth apps card on the MCP Server page shows exactly which connection is affected and why.
- Improved New installs now accept only OAuth-authorized MCP clients by default. The static bearer token fallback stays enabled on existing sites so command-line clients keep working after the update, with a dismissible recommendation on the MCP Server page to turn it off once your clients use OAuth — and a new setting under Connected Apps, Advanced lets you switch it off (or back on) at any time.