Project-scoped MCP tokens

Linking the whole hub is fine on a solo Mac. On a shared catalog, prefer a token scoped to one project so the agent cannot restart a sibling client's API.

Rotate when someone leaves. Revoke when a laptop is gone.

MCP docs cover hub vs project linking. Pair with scoped MCP, not a pasted terminal.

https://userig.app/blog/project-scoped-mcp-tokens