# Sign in and disconnect an assistant

This page explains how an AI assistant signs in to your Orphi account, what it may do once it is connected, and how you disconnect it.

Orphi uses OAuth. You sign in with your Orphi account, and you can disconnect at any time in Settings, under Connected assistants. You never give an assistant your password or an API key, and you must be 18 or older to connect one.

## How sign-in works

1. You add Orphi's address, `https://mcp.useorphi.com/mcp`, to your assistant.
2. The assistant opens Orphi's sign-in page, and you sign in the way you sign in to Orphi.
3. You allow the assistant to use your account.
4. The assistant receives a token that works only for your account and only for Orphi's tools.

The assistant sends that token with every tool call. Orphi checks the token each time and finds your account from it. No tool takes a learner id, so an assistant can never reach another learner's data.

## What a new connection may do

A new connection can only read. The assistant can see your level, lessons, due cards, saved words, notes count and call summaries, as the [tool reference](/docs/tools) describes.

To let an assistant save words, review results, notes and lessons, turn on Allow changes for it:

1. Open Orphi at `https://app.useorphi.com`.
2. Open Settings, then find Connected assistants.
3. Turn on Allow changes for that assistant.

Each assistant has its own switch. No assistant can delete anything, even with Allow changes on.

## Disconnect an assistant

1. Open Settings in Orphi, then find Connected assistants.
2. Select Disconnect under the assistant.
3. Confirm in the dialog.

The assistant loses access right away, and every tool call it makes is refused. The words and results it already saved stay in Orphi. The assistant moves to the Disconnected group, with its Allow changes switch turned off.

Signing in to the assistant again does not reconnect it. To give it access again, select Allow again next to its name in the Disconnected group. It comes back with read access only.

## For developers

Orphi follows the MCP authorization specification. A client without a valid token receives `401 Unauthorized` with a `WWW-Authenticate` header that names the protected resource metadata:

```text
https://mcp.useorphi.com/.well-known/oauth-protected-resource/mcp
```

The metadata names Orphi's authorization server. Clients that follow an older version of the specification can read `https://mcp.useorphi.com/.well-known/oauth-authorization-server`. The server supports PKCE, Client ID Metadata Documents and Dynamic Client Registration. The only scope is `profile`, and Orphi reads no profile data with it.

Send the access token in the `Authorization` header as `Bearer <token>`. Orphi accepts only OAuth access tokens issued to an assistant, and it refuses a session token of the Orphi app.

To see what an assistant can read and what it never receives, read [What an assistant can see in Orphi](/docs/privacy).
