Desktop clients: multiple services in one connection

Use standard OAuth sign-in and explicitly select each service, tool, prompt, resource and subscription. Write requests are off by default and still require individual approval when enabled. Current group permissions and each service grant constrain calls; new tools never expand existing grants. Revoke one service or the whole connection in the portal.

mcpbridge login --native --server https://hub.example.com/mcp --profile work
mcpbridge connect --profile work

Use this flow with a local browser. Administrators preregister native MCP client callbacks under Operations → OAuth clients. Clients use PKCE and standard Bearer credentials without a custom grant header. Headless Agents retain device link authorization, with one service per pairing; existing single-service entries remain available.

View your grants

The portal's client area shows names, services, scopes, tools, resource conditions, capabilities, expiry, and status. Locally, run:

mcpbridge client list --profile work

Online results check the server and effective scopes. Offline results explicitly show cached data, which does not prove that authorization is still valid.

Grant states

StateMeaning and action
Awaiting confirmationCompare the pairing code, then confirm or reject.
Confirmed, awaiting terminal redemptionReturn to the original terminal and let its flow continue.
ActiveWithin its validity period; current policies and account status still apply.
Expired / confirmation requiredReview the scope, confirm a new grant, and reconnect.
Rejected / revokedThis grant cannot be used; submit a new request if needed.

Reauthorize or renew

mcpbridge client authorize --profile work --client ci_example

Compare the new pairing code and scope in the browser, confirm, and restart the MCP connection. Renewable sign-in does not automatically extend a client grant. --ttl must stay within the server's maximum duration.

Change the scope

Unspecified settings are preserved; list parameters replace previous lists. This example replaces the resource condition with project B rather than adding it:

mcpbridge client authorize --profile work --client ci_example --resource /project=project-b

Repeat a parameter in the same command for multiple values. Browser confirmation and reconnection are still required. To narrow tools, explicitly provide the --tool list.

Revoke an entry or a whole session

Revoke authorization in the portal, or run:

mcpbridge client revoke --profile work --client ci_example

Revoking all grants for a session affects every entry in that broker session, so confirm the target first. Revocation immediately blocks subsequent admission and cancels related active streams. It does not roll back effects already accepted upstream.

Authorize clients separately

Use recognizable names such as codex-project-a-read or claude-tasks. A name helps management but does not prove application identity. Other processes under the same system account may use the entry; keep your computer's access controls in place.

The personal portal shows active connections first, groups their services, and collapses history. Revoking one service keeps other services available; revoking a connection confirms the full scope. Expand technical details to inspect IDs and scopes.