A portfolio platform can publish read-only interfaces that let other software read your data with your permission, instead of you retyping it. Artha publishes four: an MCP server an AI assistant reads your account through, a browser side panel, a set of open agent skills, and a public documentation search server. Two need an account and your approval; two need nothing at all, and none of them can place an order.
Key takeaways
- An interface is read-only when it publishes no tool that writes, so there is no order path to misuse.
- Permissions are approved one at a time and can be withdrawn, and withdrawal takes effect on the next request.
- Two of the four interfaces need no account, because they carry public market data and public documentation.
- Broker credentials are never handed to a connected tool, in any of the four.
- Every figure a connected tool reads is as of the last sync with your broker, not a live broker session.
What does connecting actually mean here?
Connecting means giving another piece of software permission to read specific data, through an interface that decides in advance what is readable. It is not giving that software your password, and it is not giving it your broker account.
The distinction matters because the two are easy to confuse. A tool that holds your login can do whatever you can do. A tool that holds a scoped, revocable permission can do exactly the things that permission names, and nothing else, no matter how it is asked. The second kind is what a published interface gives you, and it is why revoking one takes effect immediately rather than requiring a password change.
Which interface answers which need?
Start from the task rather than the technology.
If you want to ask an assistant about your own holdings, you want an MCP server: it connects Claude, ChatGPT or Cursor to your account and is explained in What is an MCP server. If you want the market on screen while you work on something else, you want a browser side panel, covered in Market data in a side panel. If your assistant keeps applying US market conventions to Indian data, you want agent skills, covered in Agent skills for Indian markets. And if you want it to cite a source rather than recall one, you want a documentation server, covered in Getting cited answers.
What each one does, whether it needs an account, what it can read, and how long setup takes.
What can each one see?
Only what it publishes a way to ask for. An interface built to read a portfolio exposes tools for holdings, totals and allocation; there is no general query behind them and no way to reach a table nobody decided to publish.
Two of Artha's four reach a signed-in account at all. The MCP server reads your portfolio, risk metrics, watchlists and alerts, split into three permissions you tick separately. The browser panel asks for one permission, to read your holdings, and shows public market data before you grant anything. The skills reach nothing — they are instructions an assistant loads, not access. The documentation server reaches published documents only, and has no path to a user record.
How do I withdraw access?
In Artha, connected tools are listed in Settings under API Keys, in a panel called Connected assistants, and each one can be revoked there. Revocation is checked on every request rather than cached, so the next thing the tool asks for is refused.
Two things revoking does not do. It does not reach back into an AI provider's records: anything an assistant already read has left, and what happens to it afterwards is governed by that provider's terms. And it does not affect public data — a side panel showing index levels keeps working, because that part never needed your account in the first place.