Granting AI Agent Permissions: How Much Access an Assistant Really Needs
Distinguish Between Read and Write
When assigning AI agent permissions, the same principle applies as with humans: as little as possible, as much as necessary. An agent that only reads can answer questions and create reports, but cannot change anything.
With Same-QR, you create keys in three levels: "read only", "read + write" (create, change names and texts) or "full" (additionally change targets, take offline, delete). If you connect a coding agent like Claude Code, Cursor, or Codex with a read key, it is not offered the write tools at all. Thus, it cannot accidentally use them.
Delete Only with Confirmation
A new daily special is harmless, a deleted code is permanent. Therefore, Same-QR secures everything that is changed, where a printed code leads: target changes, taking offline, and deletion require the "full" level, a confirmation with the previously read state, and via API and MCP at most 10 times per hour and 30 times per day. With connected apps, you receive an email each time. Still, provide your own rules:
- "Show me a list before every change to existing codes."
- "Never delete anything without my explicit confirmation."
- "If a code is no longer needed, change its target instead of deleting it."
- "Publish pages only after I have seen them."
Separate Accounts per Task
- A read-only key for the monthly scan report.
- Give it a "read + write" key only for the script that creates new product codes.
- For ChatGPT and Claude.ai, log in via OAuth, completely without a copied key. When consenting, you only check the boxes you need.
Name each key after its purpose and select a duration: 30, 90, 180, or 365 days, default 90. Up to 10 keys are possible per account.
Control
- After major changes, view the dashboard and scan some codes.
- Use the conversation history as proof of what was ordered.
- Read or have scripts written by an agent read before they run regularly.
Additionally, limits slow down an agent in a loop: at most 120 enquiries per minute per key and an hourly limit per plan. And at night, Same-QR checks each target and reports via email if one is unreachable.
Revoke
Revoke keys and disconnect when a project ends, a service provider leaves, or a key has become visible. Revocation takes effect immediately, your codes remain unchanged. Changing a password revokes all keys at once.
Conclusion: why Same-QR
Same-QR is built for working with agents: read keys that hide writing tools, marked deletion tools, durations, throttling against loops, and immediate revocation. This way, you give an assistant exactly as much access as it needs, and no more.
Get started right away: sign up for free at sameqr.com, two dynamic QR codes are free forever. API, CLI and MCP server are included in every plan, and the documentation is at sameqr.com/entwickler.
Frequently asked questions
Only if it is supposed to make changes. For questions and evaluations, a "read only" key is sufficient.
Give it a "read only" or "read + write" key, then deletion is not possible at all. With "full", every deletion requires confirmation.
Nothing. They remain unchanged. Only the program or assistant loses access.
Reserve your spot before we go live.
One email as soon as the tool goes live — including pricing and the free plan. No spam, unsubscribe any time.
- Your free account is reserved — there is nothing to pay yet anyway
- 90 days of unlimited destination changes instead of 30, only for early sign-ups
- Launch price locked in, even if we raise prices later
By subscribing you consent to receiving the newsletter. You can withdraw consent at any time via the unsubscribe link in every email.