Sign-in flow
The FreightPOP MCP Server uses OAuth 2.0, the industry-standard secure sign-in protocol used by banks, enterprise apps, and every major SaaS platform. When your AI client first calls a FreightPOP tool:- A browser popup opens on the FreightPOP login page.
- You sign in with your normal FreightPOP username and password. Your password is entered directly on FreightPOP, and the AI client never sees it.
- You approve the requested permissions once.
- FreightPOP issues a short-lived access token to the AI client.
Session and token expiry
Access tokens are short-lived for your protection.- When your session expires, the next tool call may fail with an authentication error.
- Most AI clients handle this automatically by re-opening the login popup or refreshing the token.
- If automatic re-authentication does not happen, sign in again via the same connector settings you used originally. Your prior approvals are remembered.
Data handling
What data leaves FreightPOP
Only the data needed to answer the request you made. When your AI client calls a FreightPOP tool, the tool’s response travels back through your AI provider so the model can read it and answer you. Depending on which tool ran, that response can include:- Shipment and order records, including reference numbers and line-item details
- Shipper, consignee, and third-party addresses, contact names, phone numbers, and email addresses
- Carrier names, services, rates, and charges
- Documents attached to an order, when you ask for them
Who processes it
Three parties are involved in a tool call:
Your AI provider’s handling of your conversations, including whether they are retained or used for model training, is controlled by your account settings with that provider. Review their privacy policy and data controls directly. FreightPOP cannot change those settings on your behalf.
What FreightPOP does with it
Tool calls run against your existing FreightPOP account under your own user permissions. The MCP Server does not give an AI client access to anything you could not already see and do in the FreightPOP web app, and it does not create a separate copy of your data. For FreightPOP’s full data practices, including collection, retention, and third-party subprocessors, see the FreightPOP Privacy Policy.Reducing what is exposed
- Ask narrow questions. “What’s the status of shipment X” returns far less than “list everything from the last month.”
- Review the confirmation prompt before approving a write tool. It shows exactly what will be sent.
- Some AI clients let you turn off individual tools in the connector settings if you only want a subset available. This depends on the client, so check its connector or MCP settings to see if it’s supported.
Revoking access
You can disconnect the FreightPOP MCP Server at any time:- In your AI client: remove the FreightPOP connector from your client’s settings. This stops your AI client from calling FreightPOP tools going forward, but any token it already holds stays valid on FreightPOP’s side until it naturally expires.
- In FreightPOP: contact support to revoke your active tokens immediately. This is the only way to guarantee a token stops working right away.
.webp?fit=max&auto=format&n=0fYGJvv1vhU_H_hD&q=85&s=cc6901d82ea9d5e5b86636dd0911349b)
