Review authority deliberately.
Sign in to inspect Delegations, review audit activity, and approve OAuth access for trusted Clients.
Configure OAuth
- Deploy Runtime at a direct public HTTPS origin and set
PDE_RUNTIME__BASE_URLto that exact origin. - Keep
PDE_RUNTIME__COOKIE_SECURE=trueand set a unique, high-entropyPDE_RUNTIME__PERSON_SECRET.PDE_RUNTIME__OWNER_SECRETis a deprecated fallback. Never publish either value, browser cookies, authorization codes, or access tokens. - Start the Client's OAuth connection, then review its Client name, Client ID, redirect URI, protected resource, and scope on the consent page.
- Approving a trusted Client connects it to the Embassy but grants no Desk authority. Configure its access deliberately in Dashboard after OAuth completes; use the Desk's unrestricted action where available or its Permission editor to choose bounded access.
Connect an MCP Client
- Configure the Client with this exact MCP endpoint:
Loading endpoint… - The Client discovers the OAuth endpoints automatically, then completes the standard authorization-code flow with S256 PKCE. Runtime selects or authenticates the authorizing Person or Delegate in its browser.
- Approval connects the Client but creates no Delegations.
- Configure an exposed Capability in Dashboard. A Delegate can use the same unrestricted or Desk-defined configuration flow for their own connected Client; changing upstream authority requires a fresh configuration, and revoking a Delegation denies subsequent calls immediately.
Runtime configuration reference
Set these environment variables before starting Runtime. Values not listed as required use the shown defaults.
| Variable | Default | Purpose and constraints |
|---|---|---|
PDE_RUNTIME__BASE_URL |
Required | Public Runtime origin, for example https://pde.example. It must be an absolute HTTP(S) origin without a path, query, fragment, or credentials. Use HTTPS outside explicit development. |
PDE_RUNTIME__PERSON_SECRET |
Required | Person login secret. Generate an independent value of at least 32 characters and keep it private. |
PDE_RUNTIME__OWNER_SECRET |
Deprecated | Fallback only when PDE_RUNTIME__PERSON_SECRET is empty. Runtime normalizes either source into its single Person-secret configuration value. |
PDE_RUNTIME__COOKIE_SECURE |
true for an HTTPS base URL; false for HTTP |
Marks Person session cookies as HTTPS-only. HTTPS deployments must use true. Accepted explicit values are true, false, 1, and 0. |
PDE_RUNTIME__OWNER_SESSION_TTL_SECONDS |
3600 |
Person session lifetime in seconds (one hour). Must be a positive integer. |
PDE_RUNTIME__AUTHORIZATION_REQUEST_TTL_SECONDS |
300 |
OAuth approval-request lifetime in seconds (five minutes). Must be a positive integer. |
PDE_RUNTIME__AUTHORIZATION_CODE_TTL_SECONDS |
120 |
OAuth authorization-code lifetime in seconds (two minutes). Must be a positive integer. |
PDE_RUNTIME__ACCESS_TOKEN_TTL_SECONDS |
900 |
OAuth access-token lifetime in seconds (15 minutes). Must be a positive integer. |