Skip to main content
What you need back decides the surface. Putting something on screen needs no setup at all; reading rows back needs AppleScript or a token.

Pick a surface

A launcher needs two of these: AppleScript or MCP to list connections, and a tablepro://connect/<uuid> link to open one. On iPhone and iPad, an integration has two connection links and the Shortcuts actions.

Find the app

Look TablePro up by its bundle ID, com.TablePro, through Launch Services. A path check fails twice over: the app runs from /Applications, ~/Applications or any other folder, and an unrelated app also installs itself as /Applications/TablePro.app.
Check the version before relying on a newer surface: CFBundleShortVersionString in the bundle, or the serverInfo version once the MCP server answers. Read nothing the app writes to disk: not ~/Library/Application Support/TablePro, not the com.TablePro preferences, not its Keychain items. None of them is under the contract, and Versioning names what to call instead.

What stays stable

Versioning has the rule for each surface and how a break is announced.

Security model

The MCP server binds 127.0.0.1, and on stock settings every request carries a token. A call is allowed only where the token’s scope, the token’s connection allowlist, and the connection’s own External Clients level all permit it; the effective permission is the lowest of them. Tokens has the full model. On top of that, an AI policy of Never refuses the connection outright, and Safe Mode still holds destructive statements behind a confirmation. AppleScript has no token. macOS asks the sending app for Automation permission instead, and the connection’s External Clients level and Safe Mode apply exactly as they do over MCP. The AI policy does not: it governs the assistant, not other apps. A database URL that matches no saved connection opens at Silent unless it sets safeModeLevel: 1 asks before each write and 2 refuses writes. A URL that matches a saved connection runs at that connection’s own level and ignores the parameter. Each request lands in the activity log with the token behind it, and a statement is stored as a SHA-256 digest rather than as text. Open Settings > MCP and click View Activity to read it.