Control the drawing
Edit, invite, remove members, move to Trash, restore, and permanently delete.
Account access, drawing roles, live collaboration, read-only snapshots, and external-agent permissions each have a distinct job.
Access model
Permission checks protect saved changes and live collaboration traffic.
Edit, invite, remove members, move to Trash, restore, and permanently delete.
Edit, save, rename, and organize a drawing without receiving ownership controls.
Open the drawing and participate in presence without sending canvas changes.
Account protection
New accounts prove control of their email before they can sign in or claim an invitation.
Email verification and password-reset tokens expire and cannot be replayed after use.
Changing or resetting a password invalidates older application sessions.
Access waits until the invited address is verified instead of trusting an unproven account.
Read-only sharing
A shareable snapshot is encrypted client-side. Its decryption key lives in the link fragment rather than the snapshot storage request.
External AI agents
Compatible MCP clients connect through OAuth. The consent screen identifies the client and the access it requests.
Nothing is shared until you sign in and allow the request.
Scopes separate drawing reads, drawing creation, and visual preference access.
Review clients, last use, and expiry in Settings, then revoke access at any time.
Deleting is reversible first. Owner-deleted drawings stay recoverable for 90 days.