Startup checks
When your AI client launches the Deno process, the server performs these checks before accepting any requests:- Verifies that all five required environment variables are set (
SENDWHALE_SUPABASE_URL,SENDWHALE_PUBLISHABLE_KEY,SENDWHALE_ACCESS_TOKEN,SENDWHALE_WORKSPACE_ID,SENDWHALE_APP_URL). - Confirms that
SENDWHALE_ACCESS_TOKENis a valid, non-expired user JWT. - Confirms that the authenticated user is a member of the workspace specified in
SENDWHALE_WORKSPACE_ID.
Per-operation checks
Every tool call and resource read repeats the authentication check against your live session. This means:- If your JWT expires while the server is running, the next operation will return an authentication error immediately.
- If your account is removed from the workspace between calls, the next operation will return a permission error.
- Access is enforced server-side — the server cannot access data outside workspaces you are authorised to use, regardless of what is passed as input.