---
url: /relyagent-whmcs/features/connections-oauth.md
description: >-
  Every AI client connects through an admin-provisioned connection with its own
  secret, an OAuth 2.0 + PKCE flow, your native WHMCS admin login and a consent
  screen — no self-registration.
---

# Connections & OAuth

A **connection** links an AI client to WHMCS via **Addons → Relyagent → MCP Clients**. There is **no self-registration**: clients require an administrator-issued **Client ID** and **Client Secret**. OAuth manages the secure sign-in and authorization flow.

![MCP Clients list with connections](/relyagent-whmcs/img/relyagent-connections-oauth-clients.png)
*Addons → Relyagent → MCP Clients*

## Creating a connection

Configure a new connection in three steps:

1. **Name and tools:** click **New connection**, specify a name (e.g. *"Claude — Production"*), and tick **Allowed tools**.
2. **Issue credentials:** saving generates an OAuth **Client ID** and **Client Secret** (the secret is shown only once; copy immediately).
3. **Configure client:** paste the **Endpoint URL**, Client ID, and Client Secret into the AI client's connector settings.

The **Endpoint URL** is persistent and the same for every connection, with a Copy button:

```
https://<your-whmcs>/modules/addons/relyagent/public/mcp/endpoint.php
```

## The OAuth flow

With the Endpoint URL, Client ID and Client Secret, connecting runs an **OAuth 2.0 authorization-code flow with PKCE**:

1. **Endpoint discovery:** the client resolves authorization and token endpoints from the Endpoint URL.
2. **Secret verification:** token requests require the connection's **Client Secret**.
3. **Admin authentication:** operators sign in via the **native WHMCS admin login** (2FA and IP rules enforced).
4. **Tool consent:** the admin approves the consent screen displaying allowed tools.

From then on the client sees only that connection's tools, and any other tool call is rejected.

![Consent screen listing a connection's tools](/relyagent-whmcs/img/relyagent-connections-oauth-consent.png)
*Consent screen shown after the WHMCS admin login*

## Changing a connection safely

Editing which tools a connection may use follows a **secure edit model** so a change can never
silently widen access:

* **Removing tools:** takes effect **immediately**; the client loses invocation rights instantly.
* **Adding tools:** requires **reconnection and re-consent**; existing tokens revoke automatically until approved.

::: info Why reconnect on add?
Consent is tied to the exact tools a client was granted. Requiring a fresh consent when access
grows means an AI client can never gain new abilities without you signing in and approving them.
:::

## Regenerate secret and revoke

Each connection has its own actions:

* **Regenerate secret:** issues a new Client Secret; invalidates the old secret immediately and requires client reconnection.
* **Revoke:** permanently deletes the connection and blocks all further access.

::: tip
For step-by-step setup of a specific AI client, use the connection guides — start with
[Claude Desktop](/relyagent-whmcs/guides/claude-desktop). To review what each connection actually
did, see the [Audit Log](/relyagent-whmcs/features/audit-and-rate-limits).
:::
