Choose the right sign-out action

GoalActionEffect
Sign out of the portalEnd the web session.Ends the portal session and keeps local and upstream connections.
Clear local sign-inlogout --profile workClears secrets for that profile, disconnects it, and attempts remote-session revocation.
Stop local connectionsbroker stopStops local transport and keeps remote grants.
Block one entryRevoke in the portal or use client revoke.Invalidates that client's grant.
Remove a personal service accountDisconnect in the portal.Removes the upstream connection and invalidates related client grants.

Confirm remote revocation

mcpbridge logout --profile work

Local secrets are cleared first, then remote revocation is attempted. Offline failure may report that revocation was not confirmed; revoke the old session in the portal. Restart connections after signing in again.

These actions do not invalidate identity-provider tokens or roll back writes already accepted upstream. Revoke upstream authorization through the business system's own process.

What is stored on your computer?

The default directory is ~/.mcphub/ on macOS/Linux and %USERPROFILE%\.mcphub\ on Windows. MCPHUB_HOME can select another private directory.

Sign-in tokens are stored as local JSON and are not encrypted. macOS/Linux use directory mode 0700 and file mode 0600. Windows uses a DACL granting access only to the current user; use a local filesystem with access controls, such as NTFS.

Everyday protection

  • Keep credential directories off shared drives and backups readable by other people.
  • Do not paste tokens or credential files into AI chats or support tickets.
  • Authorize only necessary tools and resources, with separate entries for different clients.
  • After changing computers, losing a device, or suspecting misuse, revoke old entries and sessions and contact your administrator.

Diagnostic information

Doctor reports contain no tokens or process-communication credentials. Still review business identifiers and errors according to company requirements before sharing. Do not send the entire .mcphub directory.