Administrator setup
A one-time step for each organisation. It takes about 15 minutes and needs an administrator of the identity domain your Fusion pod signs in with (OCI IAM identity domain or IDCS).
1. Start onboarding
- Open https://console.testingthetestingapp.online/onboard and enter your company name, your work e-mail and your Fusion pod URL. Add any extra e-mail domains your people sign in with (optional).
- MyAi follows the pod's public sign-in redirect to discover your identity domain and reads its published OpenID configuration. You'll see “Discovered: identity domain …, endpoints OK”. No credentials are sent.
- Open the confirmation link MyAi e-mails you (valid 30 minutes) and choose Confirm. Nothing is saved before that.
2. Create the confidential application
The onboarding page shows this checklist pre-filled with your pod's values and a block you can copy. In the OCI Console, as an identity-domain administrator:
- Open your identity domain → Integrated applications → Add application → Confidential Application → Launch workflow. Name: MyAi for Oracle Fusion.
- Configure OAuth → Configure this application as a client now.
- Allowed grant types: tick only Authorization code and Refresh token. Do not tick Client credentials, Resource owner, Implicit or Device code.
- Redirect URL (exactly — scheme, host and path must match):
https://mcp.testingthetestingapp.online/oracle/callback - Client type: Confidential.
- Token issuance policy → Authorized resources: Specific → Add scope: pick your pod's Fusion Applications resource and its
urn:opc:resource:consumer::allscope. The resulting scope looks likehttps://<your-pod>:443urn:opc:resource:consumer::all. MyAi also asks foropenidandoffline_access. - Token lifetimes: keep the access-token expiry at 3600 seconds (the default). The refresh-token expiry sets how long a person stays linked before signing in again (for example 8–24 hours); people simply re-link when it ends.
- Finish, then activate the application. Copy the client ID and client secret (the secret is shown once) into the MyAi onboarding form. Never send them by e-mail.
- If your domain requires app assignment, assign the users or groups who may use MyAi. Each person keeps their own Fusion roles and data access.
At a glance
| Application type | Confidential Application |
|---|---|
| Grant types | Authorization code, Refresh token |
| Redirect URL | https://mcp.testingthetestingapp.online/oracle/callback |
| Authorized scope | https://<your-pod>:443urn:opc:resource:consumer::all (plus openid, offline_access) |
| Access token | 3600 s |
3. Allowlist MyAi's egress IPs
If your identity domain or Fusion pod uses network perimeters or IP allowlists, allow all of MyAi's static egress IP addresses. The onboarding checklist lists them; you can also ask support@testingthetestingapp.online. Every call MyAi makes — REST, report jobs, token exchange and release checks — comes from these addresses. Nothing inbound needs to be opened.
If your organisation uses an additional hosting region, allowlist that region's addresses instead. See Regions & data residency.
4. Choose a plan
Choose a plan and the number of users (at least the plan's minimum) to open checkout. Your 14-day trial starts when the organisation is created. Later, manage the card, seats, e-mail domains and custom reports in the admin console at https://console.testingthetestingapp.online/admin, with a one-time sign-in link sent to your e-mail.
Optional: to let people without a Claude plan use MyAi in the browser, enable MyAi Web in the admin console with your organisation's own Anthropic API key. Also add https://app.testingthetestingapp.online/auth/callback as a second redirect URL of the MyAi application in your identity domain.
5. Link Oracle once as an administrator
Add MyAi to Claude and link Oracle yourself (guide). The first administrator sign-in completes the setup from the verified token and runs a smoke check.
On the Link page, administrators also see the box “Let MyAi check our Oracle pod for Oracle updates using my access”. Ticking it lets MyAi's daily release check read your pod's API metadata as you, so Oracle's quarterly updates are picked up. Without it, the release check can't run for your organisation.
Reports: privileges
To run Oracle reports through MyAi, people also need Oracle's privilege to submit the report's scheduled job and access to the ERP integration REST service. Without both, Oracle refuses the report. See Custom reports.
Extra e-mail domains
Your own domain is verified by the confirmation e-mail. Other domains stay pending until you publish a DNS TXT record _myai-verify.<domain> with the value shown on the billing page and choose Check DNS now. Personal-mail domains can never be used.