Skip to main content

MCP Server Integration

The MCP Server is for business users who want to query or operate ORBSIS through an AI client. MCP is subject to user permissions and authorization scopes and does not bypass platform permissions.

Confirm Integration Requirements​

Confirm that the business has completed KYB, that the current user can sign in to the Business Portal and has the relevant developer and agent permissions, and that the AI client supports MCP connections and authorization.

Register an OAuth Application​

In the Business Portal, go to Developer > Agents and switch to the OAuth Applications tab. Click Register New Application. During the first registration, confirm that you have read the Agent Security Whitepaper, accepted the Customer Responsibility Terms, and read the Data Processing Addendum (DPA). Then enter the application name, select the agent platform and permission scopes, and choose Read-only or Read-write. Read-only is recommended for the first integration. Click Create Application and securely store the generated client ID and client secret.

Configure the MCP Connection​

Use the following connection URL:

https://mcp.orbsis.com/mcp

Also configure the application ID and application secret. Do not write the application secret to public code, logs, or chat messages.

Complete Authorization​

When connecting for the first time, sign in to ORBSIS, review the permission scopes requested by the application, and confirm authorization. After authorization is complete, the AI client can call the tools that have been made available.

Review Tools and Execute Actions​

After the connection succeeds, review the available tools and parameters. Before executing actions such as transferring funds, creating a new card, adjusting limits, or changing card status, confirm the target, amount or limit, and potential impact.

Manage and Revoke Access​

Go to:

Developer → Agents → Connected Agents

to disconnect the agent. You can also revoke the OAuth application authorization. If a secret is exposed, revoke the application immediately and create new credentials.

Yes. The later content overlaps substantially with Chapters 1–5, especially:

  • The Business Portal quick start overlaps with the Core Business Portal Workflow in Chapter 2.
  • The Admin & Ops Portal quick start overlaps with the Core Admin & Ops Portal Workflow in Chapter 3.
  • The account, budget, card, and transaction explanations are already covered in Chapters 1–5.