Your account, your permissions
MCP authenticates to Bench with your account or a scoped Bench API key. A client cannot use MCP to bypass repository access, tenant isolation, key limits, or evaluation quotas. Prefer hosted sign-in when your client supports it. For key-based setup, Bench automatically prepares an account setup key. It is encrypted at rest and can be copied again from your signed-in setup page. Additional keys created with New key are shown once. Keep credentials in personal client configuration or a secret manager. Share setup prompts only with a trusted coding agent; never commit keys or include them in logs, screenshots or public chats. A revoked setup key remains disabled until you explicitly replace it.Local environments
Use theBENCH_API_BASE_URL supplied by the environment that created your key. A local key will not authenticate against the production API. Do not copy production credentials into a test account.
Actions with consequences
Ask your coding agent to get confirmation before spending evaluations or creating pull requests. A reviewable candidate is not an applied, deployed, or independently validated fix.

