Authentication
Authenticate the public Forvibe MCP server with OAuth or a personal API key.
Every request to https://forvibe.app/mcp must carry a valid Forvibe access token. Use OAuth when the client supports remote-server discovery; use a personal API key when it expects a fixed Bearer header.
OAuth 2.1 + PKCE
Forvibe publishes protected-resource and authorization-server metadata and supports Dynamic Client Registration. Compatible clients open a Forvibe consent page, then store and refresh the resulting token themselves.
- PKCE with
S256is required. - Authorization-code and refresh-token grants are advertised.
- Access tokens last 1 hour; refresh tokens last up to 90 days and rotate when used.
- Discovery:
https://forvibe.app/.well-known/oauth-protected-resourceandhttps://forvibe.app/.well-known/oauth-authorization-server. - Dynamic registration:
https://forvibe.app/api/oauth/register.
OAuth support varies by client. The platform guides only recommend it where the current client flow is documented and compatible; otherwise they use an API key.
Personal API keys
- Create a key at Settings → API Keys while the intended organization is active.
- The secret starts with
fvk_live_and is displayed only once. - Send it as
Authorization: Bearer fvk_live_…. - Keys are rate-limited to 120 MCP requests in a rolling 60-second window.
- Revoking a key immediately prevents new authenticated calls.
Do not commit a key, paste it into chat, or store it in a shared project file. Prefer an environment variable, OS secret store, or the client's protected input mechanism.
Scopes and organization roles
The public MCP uses the following scope families. New personal keys currently receive wildcard access, then every request is capped by the user's current organization role; a viewer does not gain write or credit-spending access because an older key contains *.
projects:read,projects:writeaso:read,aso:writescreenshots:read,screenshots:writestore:read,store:writecpp:read,cpp:writeiae:read,iae:writereview:simulate
Revoke or rotate access
Revoke personal keys from Settings → API Keys. For an OAuth client, disconnect Forvibe in that client's connector or app settings; if it continues to authenticate, revoke the corresponding Forvibe authorization and reconnect. A 401 after rotation means the client still holds the old credential.