Your account & agents On this page

Getting started

Your account & agents

Manage your account, workspaces and agent connections.

A small home for your connections

The owner interface at /account manages your account and agent access. Choose Records to browse your workspace without editing. CRM changes are still managed through MCP. Your login password controls the browser account; each agent has a separate bearer token with view-only or view-and-edit access. Agent tokens cannot sign in to the owner interface.

Create your account

Choose Create your free account at /login. No invitation or setup code is needed. Register with email and a password, or an available GitHub, Google or Microsoft sign-in provider. Give your first workspace a name and timezone, then follow the verification email in the same signed-in browser. Private records and agent management are unavailable until your email is verified.

Each account gets three workspaces and 20 active agents, free during beta. There are no paid plans. Each business has its own contacts, organisations, projects, tasks, tags, custom fields and activity. All-workspace tokens only cover workspaces belonging to their account.

Use Manage workspaces to create another business, and the workspace selector to switch. Record links retain their workspace so an open tab stays in its original business. Additional workspace members are not implemented.

Connect ChatGPT or Claude

Use the ChatGPT or Claude guide to connect from your preferred application. Orbit’s approval screen lets you select workspaces and permissions. Each approval creates a separate connection in Agents, where you can manage or revoke it. OAuth credentials refresh automatically; you never need to copy them.

Sign in and connect an agent with a token

Choose Sign in or visit /login. From the workspace overview:

  1. Choose Connect an agent and give it a recognisable name.
  2. Choose View only (reader, selected by default) or View and edit (contributor).
  3. Confirm your password, or confirm a linked provider in Settings if you use social sign-in without a password, then create the token.
  4. Copy the token immediately. Save it in your password manager and the client's secret settings.
  5. Follow the connection steps for Hermes or another remote HTTP MCP client.

The token is shown on the first connection-page response only. Refreshing or leaving the page hides it. For that redirect, the secret is temporarily encrypted in the session and can be displayed for at most five minutes; authentication stores only its SHA-256 hash. Responses are not cacheable. Tokens never appear in the generated configuration: it references ORBIT_MCP_TOKEN instead.

Use the MCP endpoint shown on your agent’s connection page. Hermes configuration enables every tool allowed by the selected role; use the explicit allowlist in the Hermes guide if you want a narrower client tool list.

Check the connection

For Hermes, run hermes mcp test orbit on its host, then start a new session or use /reload-mcp. Ask it to call workspaces_list, choose a workspace, then call workspace_context with its workspace_id and confirm the workspace and role. Copy a freshly created token before selecting Check connection, because that refreshes the page.

The overview and connection page show the last accepted authenticated MCP request for the current token. This is historical evidence of access, not a continuous online indicator or proof that a CRM operation completed. Older tokens begin with no timestamp until their next accepted request. Replacing a token clears its connection timestamp.

Complete the create, disconnect, reconnect and retrieve exercise in the Hermes guide to verify the full live journey.

Replace or revoke access

Open an agent from your overview, then expand Replace token or Revoke access. Both require password confirmation or recent provider confirmation for social-only accounts.

Replacing a token keeps the same agent identity and records. The old token stops authenticating immediately; copy the replacement and update the client's secret settings. Revoking an agent permanently disables that identity, while preserving records and attribution. To reconnect after revocation, create a new agent. Requests already in flight may finish, and existing task claims retain their normal expiry.

Creation, replacement and revocation record the owner ID in the audit summary. Accounts can only manage their own agents. See Agent access & tokens for permissions and credential safety.

Account settings and recovery

Settings lets you change your name, connect or disconnect GitHub/Google/Microsoft, add or change a password, sign out other browsers, export the selected workspace and request account deletion. Available providers appear on the sign-in page.

Social identities are matched by provider and permanent provider ID. Orbit never silently links accounts by email address. To add a provider to an existing account, sign in first and link it in Settings. At least one sign-in method must remain connected. Orbit does not retain provider access or refresh tokens.

Password accounts confirm sensitive actions with their current password. Social-only accounts choose Confirm identity beside a linked provider, complete that provider's sign-in, then retry the action within five minutes. Adding a password enables password confirmation thereafter.

Forgot your password? sends a reset link. Password resets and changes invalidate other browser sessions; agent tokens are unaffected. Resetting an unverified account also removes any linked providers so a person who registered someone else’s email cannot retain access after the email owner recovers it.

Use passwords of at least 12 characters and no more than 72 bytes. MFA is not implemented by Orbit; a provider may enforce its own MFA.

Export and deletion

From Settings, export the selected workspace as private NDJSON. Credentials and idempotency responses are excluded. Account deletion requires identity confirmation and typing DELETE. This disables the account immediately and revokes its agents; removal is then completed by the service operator. Export first if you need a copy. Backups expire under the hosting operator's retention policy; deleting live data does not rewrite historical backups.

Grant workspace access

When creating or editing agent access, choose selected workspaces (with a role for each), all current workspaces (a snapshot), or all current and future workspaces. All-workspace access is restricted to your own memberships. Future access uses the chosen common role. Permission changes require identity confirmation and apply to subsequent requests; in-flight work may finish. Removing access retains historical attribution and task attempts. Revoking the token blocks every workspace.

Agent management belongs to the account that issued the token. Editing a multi-workspace token changes it across its grants. Agent tokens never manage owner accounts or workspaces.

Orbit by
Your relationships, kept in view.

Search guides, concepts, and tool reference.

Explore the docs