Choose the right sign-out action
| Goal | Action | Effect |
|---|---|---|
| Sign out of the portal | End the web session. | Ends the portal session and keeps local and upstream connections. |
| Clear local sign-in | logout --profile work | Clears secrets for that profile, disconnects it, and attempts remote-session revocation. |
| Stop local connections | broker stop | Stops local transport and keeps remote grants. |
| Block one entry | Revoke in the portal or use client revoke. | Invalidates that client's grant. |
| Remove a personal service account | Disconnect in the portal. | Removes the upstream connection and invalidates related client grants. |
Confirm remote revocation
mcpbridge logout --profile work
Local secrets are cleared first, then remote revocation is attempted. Offline failure may report that revocation was not confirmed; revoke the old session in the portal. Restart connections after signing in again.
These actions do not invalidate identity-provider tokens or roll back writes already accepted upstream. Revoke upstream authorization through the business system's own process.
What is stored on your computer?
The default directory is ~/.mcphub/ on macOS/Linux and %USERPROFILE%\.mcphub\ on Windows. MCPHUB_HOME can select another private directory.
Sign-in tokens are stored as local JSON and are not encrypted. macOS/Linux use directory mode 0700 and file mode 0600. Windows uses a DACL granting access only to the current user; use a local filesystem with access controls, such as NTFS.
Everyday protection
- Keep credential directories off shared drives and backups readable by other people.
- Do not paste tokens or credential files into AI chats or support tickets.
- Authorize only necessary tools and resources, with separate entries for different clients.
- After changing computers, losing a device, or suspecting misuse, revoke old entries and sessions and contact your administrator.
Diagnostic information
Doctor reports contain no tokens or process-communication credentials. Still review business identifiers and errors according to company requirements before sharing. Do not send the entire .mcphub directory.