Sign in and disconnect an assistant
This page explains how an AI assistant signs in to your Orphi account, what it may do once it is connected, and how you disconnect it.
Orphi uses OAuth. You sign in with your Orphi account, and you can disconnect at any time in Settings, under Connected assistants. You never give an assistant your password or an API key, and you must be 18 or older to connect one.
How sign-in works
- You add Orphi's address,
https://mcp.useorphi.com/mcp, to your assistant. - The assistant opens Orphi's sign-in page, and you sign in the way you sign in to Orphi.
- You allow the assistant to use your account.
- The assistant receives a token that works only for your account and only for Orphi's tools.
The assistant sends that token with every tool call. Orphi checks the token each time and finds your account from it. No tool takes a learner id, so an assistant can never reach another learner's data.
What a new connection may do
A new connection can only read. The assistant can see your level, lessons, due cards, saved words, notes count and call summaries, as the tool reference describes.
To let an assistant save words, review results, notes and lessons, turn on Allow changes for it:
- Open Orphi at
https://app.useorphi.com. - Open Settings, then find Connected assistants.
- Turn on Allow changes for that assistant.
Each assistant has its own switch. No assistant can delete anything, even with Allow changes on.
Disconnect an assistant
- Open Settings in Orphi, then find Connected assistants.
- Select Disconnect under the assistant.
- Confirm in the dialog.
The assistant loses access right away, and every tool call it makes is refused. The words and results it already saved stay in Orphi. The assistant moves to the Disconnected group, with its Allow changes switch turned off.
Signing in to the assistant again does not reconnect it. To give it access again, select Allow again next to its name in the Disconnected group. It comes back with read access only.
For developers
Orphi follows the MCP authorization specification. A client without a valid token receives 401 Unauthorized with a WWW-Authenticate header that names the protected resource metadata:
https://mcp.useorphi.com/.well-known/oauth-protected-resource/mcpThe metadata names Orphi's authorization server. Clients that follow an older version of the specification can read https://mcp.useorphi.com/.well-known/oauth-authorization-server. The server supports PKCE, Client ID Metadata Documents and Dynamic Client Registration. The only scope is profile, and Orphi reads no profile data with it.
Send the access token in the Authorization header as Bearer <token>. Orphi accepts only OAuth access tokens issued to an assistant, and it refuses a session token of the Orphi app.
To see what an assistant can read and what it never receives, read What an assistant can see in Orphi.