Superforms developers
Superforms authentication documentation
Connect an agent to a Superforms account with OAuth while keeping public respondent links free of creator authentication.
OAuth endpoints
Superforms publishes OAuth authorization-server metadata and RFC 9728 protected-resource metadata at predictable well-known URLs. Dynamic client registration is supported for compatible MCP clients.
- Authorization metadata: /.well-known/oauth-authorization-server
- Protected resource: /.well-known/oauth-protected-resource
- Authorization endpoint: /oauth/authorize
- Token endpoint: /api/oauth/token
- Dynamic registration: /api/oauth/register
Scopes
- forms:read — list and inspect forms owned by the connected account.
- responses:read — retrieve human responses submitted to owned forms.
- forms:write — create and publish forms; the Actions API also supports private drafts and explicit publishing.
- offline_access — keep a revocable account connection available to later agent sessions.
Credential boundaries
Never place OAuth tokens or per-form agent tokens in public respondent URLs or browser embed code. Public respondents do not sign in. Account operations remain protected, and the anonymous bridge uses a private askId plus agentToken pair for creator-side reads.
Self-serve onboarding
Install the authenticated MCP endpoint, complete the browser OAuth approval, and return to the agent. Codex, Claude Code, Cursor, and compatible clients can then use the account-scoped tools without a manual API key.
codex mcp add superforms --url https://superforms.co/mcp/account --oauth-resource https://superforms.co/mcp/account
codex mcp login superforms --scopes forms:read,responses:read,forms:write