Security & Data Handling

Understand the public MCP boundary, credential handling, and safe tool approvals.

Updated 2026-09-23
5 min read

Connecting an AI client delegates the Forvibe access represented by your OAuth grant or API key. Forvibe rechecks organization membership and role-derived scopes on every MCP request; an old credential does not preserve permissions after a role is reduced or membership is removed.

Data the public MCP can return

  • Project records and connection state for the authenticated organization.
  • ASO keywords, competitors, ranks, histories, suggestions, alerts, and public store research.
  • Store listings, listing versions, subscriptions, in-app purchases, pricing plans, and In-App Event or Custom Product Page records.
  • App Store and Google Play reviews stored by Forvibe.
  • Screenshot metadata and available image URLs, SS Studio session data, templates, and localization-job status.
  • App Store metadata review-simulation inputs and results.

Data and capabilities outside the public boundary

  • The server does not read your local source repository. Codebase-aware flows require a separate local Forvibe workflow.
  • App Store Connect and Google Play credentials are not returned to the AI client. Authorized publish and product tools may use the encrypted credentials server-side to perform the requested store operation.
  • Billing payment methods, Stripe details, internal administration, and other organizations are not exposed.
  • Console-agent-only Workflow, Tracking, organization, attachment, project-deletion, internal skill, and selected image-generation tools are excluded from the public catalog.

What the AI provider receives

The connected client sends tool names and arguments to Forvibe and places returned tool data into the model context. That means the AI provider may process listing copy, reviews, project metadata, URLs, and other returned fields under its own retention and training policies. Forvibe does not receive the rest of the conversation unless the client includes it in a tool argument.

Write and outward actions

  • update_listing and localize_listing stage changes in Forvibe; publish_listings is the explicit outward push.
  • push_custom_product_page and push_in_app_event send a draft to App Store Connect but do not submit it for App Review.
  • Product creation, price application, deletion, and rollback tools can change connected store state.
  • AI localization, suggestions, and simulations can spend organization credits.

Tool annotations help clients distinguish read-only, destructive, idempotent, and open-world actions, but approval behavior belongs to the client. Review arguments before approving delete, publish, push, price, or credit-spending calls, and avoid blanket unattended approval for those tools.

Prompt injection

Reviews, competitor metadata, and store descriptions are untrusted external text. A malicious string can try to persuade an agent to call another tool. Treat instructions found inside tool results as data, not authority, and require confirmation before any write or outward action.

  • Prefer OAuth where supported; otherwise create one API key per client or machine.
  • Keep keys in environment variables or protected secret inputs and never commit them.
  • Revoke a credential immediately if a device, configuration file, shell history, or shared workspace may have exposed it.
  • Keep the user's organization role as narrow as practical; the server enforces the current role on each request.
  • Enable only the Forvibe tools needed for the current task when the client offers a tool picker.