Identity information
OpenPMM requests these OAuth identity scopes:openididentifies your signed-in user.emaillinks the authorization to your OpenPMM identity.offline_accesslets the client refresh its connection without repeated sign-in.
profile or phone for MCP access. Identity scopes
control information that Supabase shares during sign-in. They do not limit
OpenPMM capabilities.
Human checkpoints
MCP authorization does not remove OpenPMM safety checks:- Provider OAuth stays in your browser.
- Publication requires an explicit confirmed input.
- Destructive operations require their documented confirmation input.
- The agent cannot widen its own OpenPMM access through an MCP tool.
Dynamic clients
Many MCP clients register themselves automatically. The authorization page labels these as unverified dynamic clients because OpenPMM did not pre-register or verify them. A local client often redirects to127.0.0.1 with a temporary port. Continue
only when you started that local connection.
