> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign in with OAuth

> Connect an MCP client by signing in through its browser flow, and disconnect it later.

OAuth lets an MCP client sign you in to Pomerado without handling a key. This page covers signing in, connected apps and disconnecting an app.

## Sign in

<Steps>
  <Step title="Add the MCP without a key">
    Follow [client setup](/guides/connect/client-setup) and choose to sign in with OAuth.
  </Step>

  <Step title="Sign in and approve">
    The client opens a browser. Sign in to Pomerado with Google, GitHub or email, then approve the client. Your first sign-in creates an account.
  </Step>

  <Step title="Refresh the tools">
    The client lists the MCP's tools once sign-in succeeds.
  </Step>
</Steps>

A connected app can do what your role allows in the account you signed in to, and Pomerado checks your account and role on every request. It can use your saved logins in jobs but never reveal their passwords. See [permissions](/guides/authentication/permissions) for what a token reaches.

## See connected apps

The Dashboard's **Settings** > **Connected apps** page lists your connected apps. Each shows the app's name, the Pomerado MCPs it reaches, the permissions it has used, and when it first and last used Pomerado. Programs can list them with `GET /v1/connected-apps`. Apps that use an API key aren't listed; see [API keys](/guides/authentication/api-keys) for those.

## Disconnect an app

Disconnect an app on that page, or with `DELETE /v1/connected-apps/{id}`. Its access ends at once on every Pomerado MCP it reaches, and the jobs it started stop. To use the app again, sign in from it again.

<Accordion title="Details">
  * From an MCP client, the same operations are `connected_apps.list` and `connected_apps.revoke` through `call_pomerado_api`.
  * An API key can list and disconnect apps only if it carries `api_keys:manage`, and only an app whose used permissions the key holds.
  * If a client's authorization expires or is revoked, reconnect from the client.
</Accordion>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.