@voyant-travel/max-embed, paste an API key, create an operator, or add a token endpoint. Those steps are handled by the managed control plane.
What users see
Authorized staff open Max from the managed Admin interface. The Admin uses the current staff session and deployment identity to request a short-lived Max session. Platform-owned credentials never enter the browser or the customer-facing dashboard.What the platform manages
Voyant owns the complete lifecycle:- Installation during managed deployment provisioning
- Operator registration and configuration
- Credential creation and rotation
- Session authorization for signed-in staff
- Revocation when a deployment is disabled or leaves managed hosting
@voyant-travel/max-embed package remains published for compatibility with existing managed integrations. Installing the package alone does not provide access to Max, and Voyant does not issue session tokens for customer-built or self-hosted integrations.
Next steps
Max overview
Learn how Max fits into managed Voyant deployments.
Extend with platform Tools
Add canonical Tools to the deployment’s MCP catalog.
Cloud
Learn about managed deployments.