How it works
Sign in with Raff (OAuth)
When you add the server to an app such as Claude or ChatGPT, the app opens a Raff page in your browser:- Sign in to Raff, with your authenticator code if you use one.
- Read the request: Allow app name to use your Raff account?
- If you belong to more than one account, pick the account the app works in.
- Click Allow access.
API key
Tools that send a fixed header (Claude Code, Cursor, scripts) can use a Raff API key instead of signing in:What the app can do
Access is granted once for the whole account, the same way you would give a teammate access:- Create and manage databases, and apps, functions and servers as Raff adds them to the MCP server.
- Read and change data in your databases with SQL.
- Only what your role allows in this account. A member without permission to delete databases cannot delete them through an AI app either.
As tools for more products ship, the same sign-in reaches them, and this table is updated.
Every call is made through the public Raff API, so it follows the same permissions, billing rules and rate limits as the API, and appears in the account’s audit log.
Remove access
- Signed in with Raff: remove the Raff connector in the app (in Claude: Customize → Connectors; in Claude Code:
claude mcp remove raff). The app can no longer call Raff. - API key: delete the key in the dashboard. Every tool using it stops at once.
Trade-offs
- Access is account-wide, not per database. To keep an app away from production data, sign it in to a separate account, or give it an API key in an account that holds only what it should touch.
- Read-only mode removes every tool that changes anything, if you only want the app to look.
Related
Paid changes
How prices are confirmed before anything is charged.
Connect Claude
Sign in with Raff from Claude.