corsair_permissions table work the same on Hub. Hub hosts the approve/deny UI, so you do not build a review page.
How it works on Hub
The authoritative approval record lives in yourcorsair_permissions table. Hub renders the UI and delivers the signed decision to your handler, which writes the outcome to your database. Hub never touches your database. To render the review screen and route the decision, Hub does keep a short-lived session of its own holding the plugin, endpoint, the call arguments shown for review, and the tenant id, until the request is decided or expires. Delivery uses the same environment-specific transport as connect flows: a signed POST over the Corsair tunnel in development, a signed POST to your public URL in production.
Configuration
Withhub configured, blocked calls include a hosted approval URL with no extra setup:
corsair.ts
Approvals require the
corsair_permissions table. That table is your system of record; Hub only holds the pending session while the review is open. See Permissions for the migration.What’s next
Permissions
Policies, modes, overrides, and the full approval lifecycle.
Hub overview
The relay model and the surfaces Hub hosts.
MCP adapters
How approvals gate agent tool calls.