> ## Documentation Index
> Fetch the complete documentation index at: https://docs.connie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Working across workspaces

> One OAuth grant covers every workspace you belong to. Refer to them by name; the AI resolves the rest.

When you authorize an MCP client via [OAuth](/mcp/quickstart), the grant covers **every workspace you're a member of** — not just the one you picked on the consent screen. The picker sets the *default* workspace; everything else is fluid per request.

This is the headline difference between OAuth and the [workspace API key](/mcp/api-key) path. An API key locks you to one workspace; OAuth lets a single connection drive all of them in the same session — without pasting UUIDs, without restarting your IDE, without separate MCP server entries.

<Info>
  This page is about the OAuth path. Workspace API keys are scoped to a single workspace by design — see [Workspace API key](/mcp/api-key) for that path.
</Info>

***

## Just use workspace names

You don't need to know any UUIDs. Ask the AI to list your workspaces once at the start of a session, then refer to them by name from then on:

```
List my Connie workspaces.
```

The AI calls `list-my-workspaces` and gets back something like:

```
Personal              (a4f1…)   owner
Acme Sales            (b8c2…)   member
Acme Support          (c3d7…)   admin
```

It keeps that map in conversation context. From here on, just name the workspace in your prompt:

```
Search the Acme Sales workspace for warm leads.
```

The AI resolves "Acme Sales" → `b8c2…`, passes it as the `workspaceId` argument on the `crm-search` call, and you get the right result. No copy-paste, no config edit.

<Note>
  If you don't ask first, the AI will call `list-my-workspaces` itself the moment it needs to disambiguate. The explicit list-at-session-start trick is just a way to front-load the lookup so the first real request doesn't pause to discover.
</Note>

***

## Default workspace

If you don't name a workspace in your prompt, the request uses the **default** — the one you picked on the consent screen when you first authorized.

This is what makes casual use frictionless: most prompts don't need to name a workspace at all. *"Draft a reply to the latest email"* uses your default. *"…in Acme Sales"* uses Acme.

To change the default, revoke the grant from **Settings → Connected apps** and re-authorize — the consent screen lets you pick a different default.

***

## Discovering workspaces

Already covered above, but worth restating as a one-liner reference:

```
What Connie workspaces do I have access to?
```

`list-my-workspaces` returns name, UUID, and your role on each — useful for sanity-checking access after a permissions change.

***

## Permissions

The OAuth grant **does not expand** what you can access. It inherits whatever workspace memberships your account already has — nothing more.

If you ask a tool to act on a workspace you aren't a member of, the worker returns:

```json theme={null}
{
  "error": "forbidden",
  "error_description": "You are not a member of the requested workspace."
}
```

This surfaces in the AI's response as a tool error. Adding access requires being invited via **Workspace settings → Members**, not anything on the MCP side.

<Warning>
  Removing someone from a workspace **does not** automatically revoke their OAuth grant for *other* workspaces they're in. Their next MCP request targeting the removed workspace returns 403 immediately — Connie re-checks membership on every request — but the same grant still works against any other workspace they belong to. To kill an ex-member's MCP access across the org entirely, the user themselves can revoke the client in **Settings → Connected apps**.
</Warning>

***

## Advanced: hard-pin a workspace

Most users should ignore this section. The natural-language pattern above is the right default.

If you have a specific reason to lock one MCP server entry to one workspace — e.g. a high-stakes prod workspace where you want a hard guardrail that *cannot* be inferred away by the AI — pin the workspace ID into the URL:

```json theme={null}
{
  "mcpServers": {
    "connie-prod-locked": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://mcp.connie.ai/api/mcp?client=cursor&workspaceId=<prod-wid>",
        "0",
        "--static-oauth-client-metadata",
        "{\"client_name\":\"Cursor\"}"
      ]
    }
  }
}
```

Every request from this MCP entry routes to that workspace; per-tool `workspaceId` arguments are still respected (so the AI can broaden the scope), but if the AI omits the argument it goes to the pinned workspace, not your OAuth default.

Trade-off: you lose the fluid-multi-workspace property OAuth gives you. If you find yourself wanting a hard pin in *every* server entry, you probably want the [workspace API key](/mcp/api-key) path instead — that's exactly what it's designed for.

***

## What's next

<CardGroup cols={2}>
  <Card title="Add more clients" icon="grid-2" href="/mcp/clients">
    Connect Cursor, Claude Code, and Windsurf alongside Claude Desktop.
  </Card>

  <Card title="Troubleshooting" icon="life-ring" href="/mcp/troubleshooting">
    403s, missing workspaces, default-not-applied.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.