Teams

Security

Use account and team controls to protect access to Lettermint. Account controls apply to one user. Team controls apply to managed access across a team.

Account security

Users can secure their own account with passkeys and connected OAuth providers.

Passkey and OAuth providers screen.

Team MFA enforcement

Members with Manage team security can require team members to use multi-factor authentication before accessing team resources.

Team MFA enforcement settings.

Enterprise identity

Use SSO to route managed users through your identity provider, and SCIM to provision and deprovision users.

SSO

Configure SAML or OIDC sign-in.

SCIM

Provision users and groups.

Managing SSO providers, SCIM tokens, role mappings, and team MFA enforcement requires Manage team security.

Token security

  • Use Project API tokens only for sending.
  • Use Team API tokens only for management automation.
  • Create one token per integration.
  • Add IP allowlists for tokens used from stable outbound IP addresses.
  • Rotate or revoke tokens when ownership changes.
  • Never expose tokens in client-side code.

See Handle API tokens securely for storage, rotation, and exposed-token response steps.

MCP security

Members with Manage team security can control whether connected MCP applications may access a team. Disabling MCP blocks both new and existing connections from using that team immediately without disconnecting a member from other teams.

Personal-information filtering is enabled by default. It hides stored message identities and metadata, suppression values, message bodies, and raw source. It also blocks identity searches, member records and assignment changes, email sending, batch sending, and suppression additions. A permitted user can still remove a suppression by its ID. Operational delivery data and permitted team, project, route, domain, and webhook configuration remain available.

If a team turns off this filter, the connected client can receive personal information and perform permitted identity-related actions. Every call still checks current membership, project access, role permissions, MFA requirements, and team settings. See MCP server for the exact boundary.

Next steps