Do I need to install the server or Vault?
No. End users install mcpbridge. Your administrator configures company services and tools.
Are client-id and ci_… the same?
No. --client-id in login/setup identifies a registered login application. --client in connect/doctor identifies a generated client entry.
Why authorize after logging in?
Login establishes your identity. Authorization determines which services, tools, and data an entry may use. Each entry is confirmed and revoked independently.
Why does authorization expire when login can renew?
Their lifetimes are independent. When an entry expires, run client authorize or use the wizard again, confirm in the browser, and reconnect.
Do new tools appear automatically?
An existing authorization does not expand automatically. Confirm the tools you now need. If they are still unavailable, ask your administrator to check publication and permissions.
Why does replacing an account stop access?
Replacing or disconnecting an upstream account invalidates old authorizations. Reconnect the account and authorize the entry again. Connecting an account for the first time can satisfy an existing authorization.
Does approved mean completed?
Approval allows the operation to continue. The original client still needs to call mcphub_resume_approval with the original ID and verify the business result.
Can revocation roll back an operation?
No. Revocation blocks future admission and cancels active streams. It does not undo side effects already accepted by the upstream service.
Does doctor execute tools?
It does not execute tools or create authorizations. It may refresh your login token and performs a handshake and catalog read. It does not refresh upstream credentials.
Can a colleague reuse my configuration?
Your configuration includes local paths and your own entry. Each person should run the wizard and authorize independently.
How do portal logout, logout, and broker stop differ?
They end your browser session, local login, and local transport respectively. See Logout and credential protection for entry revocation and account disconnection.
Can I use another desktop client?
If it supports local stdio MCP and accepts command, args, and env, follow Client configuration. Use the format required by that client.