By the end of this page an application you connected can no longer use your site’s tools.
Which steps apply depends on how the application signed in.
An application that signed in through OAuth
This covers Claude Code, claude.ai and ChatGPT when they connected through the consent screen.
- Go to Settings → Block Theme MCP and open the Connect tab.
- Scroll to Connected apps. Each row is one application acting as one account. The columns are Application, Account, Connected and Last token issued.
- Find the row and click Revoke.
The notice “The application was disconnected. It will need your approval again to reconnect.” appears and the row is gone. The application’s next call is refused.
Two things to know:
- An administrator sees the connections of every user here. The Account column names the account each one acts as.
- Application names are unverified. Each one is what the application chose for itself when it registered. Go by the Account and the dates as well as the name.
A client that uses an Application Password
- Go to Users → Profile and scroll to Application Passwords.
- Find the password by the name you gave it. The table shows when it was last used.
- Click Revoke on that row.
The client’s next request fails, because the header it sends no longer matches a password.
Stop every remote client at once
On the Settings tab, under Ways to connect, untick MCP clients over OAuth (claude.ai, ChatGPT, Claude Code) and MCP clients over HTTP (Application Passwords), then click Save Changes. No remote client can call a tool while both are off.
Switching OAuth off does not revoke anything. The rows stay in Connected apps, and the connections work again when you switch OAuth back on. Use Revoke to end a connection for good.
To stop everything, browser agents included, untick Enable Block Theme MCP.
Tidy up on the client side
Revoking on the site is what cuts the access. Removing the entry from the client stops it from asking to sign in again.
- Claude Code:
claude mcp remove example-com, with the name you used when you added the site. - claude.ai or ChatGPT: remove the connector in its settings.
Check that it worked
- The row is gone from Connected apps, or the password is gone from your profile.
- Ask the client to call
btm.site-info. The call fails, or the client asks you to sign in again. Approving that request makes a new connection.