Guides
Choose a guide by the principal and operation you are implementing.
Runtime access
Section titled “Runtime access”- Connect an MCP client for standard Streamable HTTP capability invocation.
- Act on behalf of a User with Authorization Code, PKCE, consent, and delegated Grants.
- Run an autonomous Application with the Application’s own eligible attachments.
Tenant and upstream setup
Section titled “Tenant and upstream setup”- Automate tenant management with a Service Account.
- Connect an upstream provider without coupling the flow to a provider catalog.
- Request offline access when delegated authority must outlive a browser session.
Operations
Section titled “Operations”- Revoke a Grant or Connection and verify live authority disappears immediately.
- Inspect tool-call evidence without exposing secrets or unrestricted payloads.