Developer Sandbox Security Principles
- Firebase Auth Independence: DealOra account authentication remains strictly separate.
- Zero Password Storage: No Swiggy passwords are ever requested or stored. All authentication occurs on official Swiggy servers (
mcp.swiggy.com). - Server-Side Encryption: Tokens are encrypted at rest with AES-256-GCM.
- Read-Only Guardrails: Strictly restricted to discovery tools (
get_addresses,search_restaurants,search_products). No ordering or payment APIs are invoked. - Adapter Protection: All DealOra production adapters remain marked
NOT_INTEGRATED.
S
Swiggy Account Connection
OAuth 2.1 Authorization Code + PKCE S256
Connect your Swiggy account to test live, user-consented address resolution and catalog search via the official Swiggy Builders Club MCP server.
Flow Details:
• Target Server: https://mcp.swiggy.com/auth/authorize
• Client ID: swiggy-mcp (RFC 7591 Dynamic Registration)
• Scope: mcp:tools (Read-only discovery)
