Skip to main content

MCP Server

What should I do if the MCP client cannot connect?​

Answer: Confirm the MCP URL and network connection, and check that the client supports Streamable HTTP and OAuth 2.1 Authorization Code. The default URL is https://mcp.orbsis.com/mcp. If the browser authorization page does not open, check the OAuth application settings and the client configuration format.

What should I do if MCP authorization succeeds but I still have no permission or cannot see the tools?​

Answer: Successful authorization does not mean that the current user can use every tool. Check the user role, OAuth application scope, environment, and tool permissions. Refresh the connection and retrieve tools/list again. The tool list may vary by version, environment, or permission. Do not infer MCP tool names from the REST API list.

How do I revoke an AI client’s access?​

Answer: Open the Agents page in the client portal and revoke access in one of the following ways:

  • Connected Agents: disconnect one AI client or click Disconnect All to disconnect all connections.
  • OAuth Applications: find the relevant OAuth application and revoke consent or delete the application from the action menu.
  • After revoking access, also clear locally stored access tokens from the AI client. Platform administrators can force-revoke an application or agent in the Operations Portal when they have the required permissions.

What should I do if the Client Secret is lost or exposed?​

Answer: Stop using the exposed Secret immediately, disconnect the related agent, and delete or revoke the OAuth application. Then register a new application and generate new credentials. A Client Secret is normally shown only once during creation and must not be stored in source repositories, public logs, screenshots, or AI chat messages.