OAuth Authorization Flow
- The AI client connects to the ORBSIS MCP Server for the first time.
- The client opens the browser authorization page, and the user signs in to ORBSIS.
- The user reviews the application name and requested scopes, then decides whether to approve.
- After approval, ORBSIS issues an authorization code and the client completes the Token exchange.
- Subsequent calls execute under the combined constraints of the authorized user, application scope, and platform permissions.
- The user can disconnect individual or all Connected Agents in the Business Portal; an administrator can perform a forced revocation in the Admin & Ops Portal.
User-level authorization: An AI agent cannot obtain permissions higher than those of the authorizing user. A Read-write application scope does not mean that every write operation is available. Availability still depends on user permissions, the exposed tool set, and platform risk-control rules.