# Connect Claude

> Give Claude access to selected Orbit workspaces.

## Connect with secure sign-in

You need a verified Orbit account and access to custom connectors in Claude. Organisation policies can restrict who may add them.

Copy this **MCP server URL** into your new connection:

```text
https://orbit.duskworks.co.uk/mcp/orbit
```

1. Open **Customize → Connectors** in Claude and add a custom connector named **Orbit**.
2. Paste the MCP server URL above.
3. Choose OAuth sign-in. If Claude offers an OAuth client choice, choose **Register automatically**. Orbit currently supports dynamic registration, not Claude’s published client identity option.
4. Connect, then sign into Orbit.
5. Select the permitted workspaces and choose **View only** or **View and edit**. Approve the connection.
6. Return to Claude and enable Orbit in your conversation.

See Claude’s current [custom connector instructions](https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp) for account-specific setup and menu names.

## Check the shared context

Ask Claude to call `workspaces_list`, let you choose a workspace, then retrieve its context. With edit access, ask it to create a fictional contact and retrieve that contact in another conversation.

Claude and Hermes can use the same records when both connections have permission to that workspace. Each keeps its own agent identity, access settings and attribution.

## Alternative: an existing Orbit token

Claude’s connector settings also support **Request headers**. If you prefer manual credentials, create an agent in Orbit and add the header `Authorization` with value `Bearer YOUR_ORBIT_TOKEN`. Use **No sign in** for the client’s OAuth setting when configuring this header; Orbit still requires the token on every request.

Keep the token out of prompts and shared configuration. Replace or revoke it from Orbit if needed. Follow the [agent access guide](/docs/authentication).

## Manage or reconnect

OAuth connections appear under **Agents** in Orbit. Change workspace permissions or revoke access there. Tokens refresh automatically, with one-hour access tokens and 30-day refresh credentials. After revocation or refresh expiry, reconnect in Claude and approve a new connection. Revoke unused connections to stay within your account’s agent limit.

If sign-in fails, start again and complete approval within ten minutes. If the automatic registration option is unavailable, follow the token-header alternative where your Claude client supports it.

Local OAuth integration tests cover the protocol and permissions. Live acceptance in Claude still needs to be completed after deployment.
