Approvals, revocation & blacklist
Human decisions remain authoritative.
Optional legal approval
A platform may provide Terms of Service, Privacy Policy, both, or neither under Console's Advanced settings. Neither means there is no Versine legal-acceptance gate. This does not waive the platform's own obligations.
After the agent's handshake, a missing current-version acceptance produces
USER_ACTION_REQUIRED. Open My approvals
or Mobile, review the linked documents, and accept or reject yourself. The agent
cannot submit legal acceptance for you.
The server records the accepted document URLs, version and time. A duplicate click is handled idempotently. Current acceptance is reused; changing a legal URL increments the version and prompts at the next authorization. A stale screen/version cannot accept a different document. Expired requests need a fresh platform sign-in.
Notifications
Push is an optional prompt to open a durable request, not an approval. Opening a deep link fetches the current state for the authenticated user. Disabled, delayed or failed push does not prevent you from using My.
Only legal authentication approvals currently queue push notifications. Requests for missing onboarding details appear in My/Mobile Approvals; automatic push for those detail requests is not implemented.
Revoke versus blacklist
- Revoke ends the current Versine authorization. A new platform sign-in may start a new authorization.
- Blacklist persistently blocks new authorization and access to stored onboarding details for that platform. Only you can remove the entry.
- Disconnect an agent invalidates its MCP connection bearer.
- None of these deletes an account or an already-issued session at the external platform.
The server checks ownership, current state, expiry and blacklist again at sensitive transitions. These controls are shared across My and Mobile.