Desktop clients: multiple services in one connection
Use standard OAuth sign-in and explicitly select each service, tool, prompt, resource and subscription. Write requests are off by default and still require individual approval when enabled. Current group permissions and each service grant constrain calls; new tools never expand existing grants. Revoke one service or the whole connection in the portal.
mcpbridge login --native --server https://hub.example.com/mcp --profile work
mcpbridge connect --profile work
Use this flow with a local browser. Administrators preregister native MCP client callbacks under Operations → OAuth clients. Clients use PKCE and standard Bearer credentials without a custom grant header. Headless Agents retain device link authorization, with one service per pairing; existing single-service entries remain available.
For remote or headless Agents, use link authorization: sign in and choose access on one page, or use --interactive-auth for authentication tools. The existing setup flow below remains available.
Enterprise sign-in supports OIDC or LDAP. LDAP users select LDAP in the authorization page’s account-source field. After your first sign-in, ask an administrator to enable your account and grant group access.
Sign in with your company identity
Default deployments use a MCPHub username and password supplied by your administrator. If MFA is enabled, also enter the authenticator code. Enterprise sign-in is optional. Local and enterprise identities are separate; using the same name does not share group permissions. In the portal, My account lets local users change passwords and enroll MFA in separate sections. MFA setup generates a secret to add to your authenticator; confirm its code within five minutes. Failed confirmation keeps the setup information; Restart setup returns to the secret-generation step if it expires. Password changes and successful MFA enrollment sign out existing sessions. Ask your administrator to reset a forgotten password.
For your first connection, use the setup wizard; it opens sign-in when needed. To sign in first or restore a saved profile:
mcpbridge login --server https://hub.example.com/mcp --client-id mcpbridge --profile work
mcpbridge status --profile work
When the URL and sign-in application ID are saved, use mcpbridge login --profile work. Use the full HTTPS URL supplied by your administrator. Sign-in still needs to be followed by authorization for each client entry.
If the browser does not open
Open the terminal's authorization link on the same computer that runs the command. Sign-in waits up to five minutes for the local callback; run it again after a timeout. If a fixed callback port is required, add --callback-port 8765 using the actual assigned port.
An SSH terminal may expect a callback on a different machine. Sign in where your AI client actually runs the connector. See Multiple services and environments.
If access is pending or your account is disabled
A message saying that your identity was recorded but access is not granted or the account is disabled means the company identity was recognized, but MCPHub access has not been enabled or has been removed. Ask your administrator to enable the user and add them to groups with the required services, scopes, and tool permissions, then sign in again.
Failed or cancelled sign-in keeps your previous credentials. After a successful sign-in, restart existing MCP connections for that profile.
Open your personal authorization portal
Open https://hub.example.com/client-auth/ on your company's MCPHub domain and sign in with your company identity. The portal manages accounts and client authorizations.
| Area | Purpose |
|---|---|
| Confirm authorization | Check the pairing code, service, tools, business resource limits, and expiry; confirm or reject the request. |
| Connected accounts | Connect personal service accounts, view details, reconnect, or disconnect. |
| Your connections | View your grants, revoke one entry, or revoke all grants for a broker session. |
The portal manages only your own accounts and authorizations. Administrators configure team members' permissions.
If a link expired or belongs to a different account
Make sure the portal and terminal use the same identity. If a link expired, run setup or client authorize again and compare the new pairing code. An invalid request does not prevent you from managing existing grants.
Understand the three separate sign-in states
Your browser session, local sign-in, and personal upstream account are independent. Signing out of the portal does not revoke local clients; local logout does not disconnect upstream accounts; disconnecting an upstream account affects grants for that service. Choose the appropriate sign-out or revocation action.