> ## Documentation Index
> Fetch the complete documentation index at: https://docs.northernlogic.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connection settings

> Inspect devices, edit vault scope, rotate credentials, and revoke an endpoint.

Open **Connections** to see active machines and remote MCP clients. Connection
owners and authorized workspace administrators manage them, subject to vault
permissions.

## Read a card

Replica cards show the owner, client version, platform, recent activity, and
vault sync information. **This computer** identifies the adopted local replica
in the desktop app. An old client can show **Update available** and **Copy
update prompt**.

Remote MCP cards show read/write grants and last MCP activity. They do not have
local replica health. **Never used** is not evidence of a stalled sync.

## Change settings

Open **Settings** to rename the connection, change attached vaults, reissue an
unredeemed pairing code, or manage credentials. Review the resulting grants
against the owner's current vault access. A manager cannot grant access the
owner does not have.

Revoking a vault grant stops future permitted requests for that scope. Files
already downloaded to an unmanaged machine remain there.

## Rotate a durable key

1. Choose **Rotate key** to issue a replacement.
2. Save the new one-time key in the correct client's secure configuration.
3. Make a successful request with the replacement.
4. Revoke the old credential after the replacement is verified in use.

There can be two active credentials during cutover. A third is refused. An
unused extra credential can be discarded, but a previously used key cannot be
revoked until another active key has been used. Inventory does not recover the
secret value of a lost key.

Pairing-code reissue is different from key rotation. Use it for an unfinished or
lost enrollment, not for adding another harness to a healthy paired machine.

## Remove a connection

Choose **Delete** on the card and confirm the intended endpoint. This revokes
its remaining credentials and removes it from the active list. The revocation
cannot be undone; create a new connection if the endpoint needs access again.

Deleting one connection does not revoke another machine's key and does not
remotely erase downloaded files. Review
[offboarding](/administration/offboarding) when removing a person's broader
access.
