OAuth lets you connect an application or AI agent to Eqdeal without giving it your Eqdeal password. You sign in directly to Eqdeal, review the requested access, and decide whether to allow it.
What happens when you connect
The application opens Eqdeal in your browser. Eqdeal confirms who you are, shows the application name and explains what it wants to do. Nothing is connected until you choose Allow access.
-
Start from the application
Choose Connect, Sign in, or Add Eqdeal inside the application or AI client you trust.
-
Sign in to Eqdeal
Use email and password or Continue with Google. If you are new to Eqdeal, you can create a free account without losing the connection request.
-
Confirm the correct identity
Check the Eqdeal email shown on screen. Use a different account if the application should operate under another user.
-
Review the request
Read the application name and every capability listed on the Eqdeal authorization screen.
-
Allow or deny
Choose Allow access only when you recognize the application and the requested capabilities make sense. Choose Deny to return without connecting.
Continue with Google only proves your identity to Eqdeal. The following Eqdeal authorization screen is where you decide whether the external application or agent may use your Eqdeal access.
Understand the authorization screen
How permissions really work
An approved connection still has to pass two independent checks for every request. Having only one is never enough.
| Permission gate | What it controls | Example |
|---|---|---|
| OAuth capability | Whether the application may request a type of action, such as reading companies or managing reports. | A reports permission does not grant cap-table management. |
| Your live Eqdeal access | Which companies, investor positions, and operations your signed-in Eqdeal user can access now. | Company A access does not reveal Company B. |
Eqdeal checks your live permissions when the application makes a request. If your company role is reduced or removed later, the connection cannot use the old access to bypass that change.
Read and manage are not the same
- Read access — lets the application retrieve authorized information without changing it.
- Manage access — lets the application create or update specific authorized records and normally includes the related reading needed for that workflow.
- Sensitive equity actions — remain subject to stricter company roles, fresh authentication, locks, previews, confirmations, and other Eqdeal safeguards where applicable.
Connecting an agent never makes you a company administrator, stakeholder, or investor. It can act only within the authority your Eqdeal user already has.
Connect safely
- Start the connection from the official application or a client you trust.
- Check the application name and your Eqdeal email before approval.
- Prefer the smallest useful permission set and reconnect later if a legitimate workflow needs more.
- After connecting an AI agent, first ask it to list the companies and tools available to you.
- Name the intended company explicitly and review previews or confirmation summaries before changes.
- Never paste your Eqdeal password, Google password, authorization code, or access token into a chat.
Disconnect or revoke access
- Open the connected application or AI client and find its integrations, connectors, or MCP settings.
- Choose Disconnect, Remove, or Revoke for Eqdeal.
- Close active agent sessions that may still contain previously returned information.
- Reconnect only if you still recognize the application and need its requested capabilities.
If a disconnected client still appears able to obtain new Eqdeal data, contact and include the application name, your Eqdeal email, and when you disconnected it. Never send passwords or tokens.
Troubleshooting
I see the wrong Eqdeal email
Choose Use a different account or cancel the request, sign out, and restart the connection with the intended Eqdeal user.
I do not have an Eqdeal account yet
Choose Create account. Eqdeal preserves a valid connection request through signup and returns you to authorization afterward.
Eqdeal asks me to confirm my password again
This is expected for sensitive access. Reauthentication ensures that a recent browser session alone cannot approve a high-impact connection.
The agent cannot see a company or action
Confirm the active Eqdeal user, company role, requested capability, company status, subscription, and any temporary workflow lock. Reconnecting cannot override missing company authority.
The application name is unfamiliar
Choose Deny. Return to the application you intended to connect and restart from its official connection flow.
The browser did not return to my application
Do not approve repeatedly. Return to the client, check whether it already connected, then retry once. If it still fails, record the client name and error before contacting support.
OAuth in plain language
- OAuth
- The secure authorization process used to grant limited access without sharing your password.
- Capability or scope
- A named category of access the application is allowed to request.
- Consent
- Your approval of a specific application, resource, and set of capabilities.
- Token
- A short-lived credential the approved application uses instead of your password. Treat it as secret.
Continue with the MCP connection guide for agent-specific setup and first-use checks.