Skip to main content
OAuth lets an MCP client sign you in to Pomerado without handling a key. This page covers signing in, connected apps and disconnecting an app.

Sign in

1

Add the MCP without a key

Follow client setup and choose to sign in with OAuth.
2

Sign in and approve

The client opens a browser. Sign in to Pomerado with Google, GitHub or email, then approve the client. Your first sign-in creates an account.
3

Refresh the tools

The client lists the MCP’s tools once sign-in succeeds.
A connected app can do what your role allows in the account you signed in to, and Pomerado checks your account and role on every request. It can use your saved logins in jobs but never reveal their passwords. See permissions for what a token reaches.

See connected apps

The Dashboard’s Settings > Connected apps page lists your connected apps. Each shows the app’s name, the Pomerado MCPs it reaches, the permissions it has used, and when it first and last used Pomerado. Programs can list them with GET /v1/connected-apps. Apps that use an API key aren’t listed; see API keys for those.

Disconnect an app

Disconnect an app on that page, or with DELETE /v1/connected-apps/{id}. Its access ends at once on every Pomerado MCP it reaches, and the jobs it started stop. To use the app again, sign in from it again.
  • From an MCP client, the same operations are connected_apps.list and connected_apps.revoke through call_pomerado_api.
  • An API key can list and disconnect apps only if it carries api_keys:manage, and only an app whose used permissions the key holds.
  • If a client’s authorization expires or is revoked, reconnect from the client.