Skip to main content

OAuth Authorization Flow

  • The AI client connects to the ORBSIS MCP Server for the first time.
  • The client opens the browser authorization page, and the user signs in to ORBSIS.
  • The user reviews the application name and requested scopes, then decides whether to approve.
  • After approval, ORBSIS issues an authorization code and the client completes the Token exchange.
  • Subsequent calls execute under the combined constraints of the authorized user, application scope, and platform permissions.
  • The user can disconnect individual or all Connected Agents in the Business Portal; an administrator can perform a forced revocation in the Admin & Ops Portal.

User-level authorization: An AI agent cannot obtain permissions higher than those of the authorizing user. A Read-write application scope does not mean that every write operation is available. Availability still depends on user permissions, the exposed tool set, and platform risk-control rules.