Superforms developers

Superforms authentication documentation

Connect an agent to a Superforms account with OAuth while keeping public respondent links free of creator authentication.

OAuth endpoints

Superforms publishes OAuth authorization-server metadata and RFC 9728 protected-resource metadata at predictable well-known URLs. Dynamic client registration is supported for compatible MCP clients.

  • Authorization metadata: /.well-known/oauth-authorization-server
  • Protected resource: /.well-known/oauth-protected-resource
  • Authorization endpoint: /oauth/authorize
  • Token endpoint: /api/oauth/token
  • Dynamic registration: /api/oauth/register

Scopes

  • forms:read — list and inspect forms owned by the connected account.
  • responses:read — retrieve human responses submitted to owned forms.
  • forms:write — create and publish forms; the Actions API also supports private drafts and explicit publishing.
  • offline_access — keep a revocable account connection available to later agent sessions.

Credential boundaries

Never place OAuth tokens or per-form agent tokens in public respondent URLs or browser embed code. Public respondents do not sign in. Account operations remain protected, and the anonymous bridge uses a private askId plus agentToken pair for creator-side reads.

Self-serve onboarding

Install the authenticated MCP endpoint, complete the browser OAuth approval, and return to the agent. Codex, Claude Code, Cursor, and compatible clients can then use the account-scoped tools without a manual API key.

codex mcp add superforms --url https://superforms.co/mcp/account --oauth-resource https://superforms.co/mcp/account
codex mcp login superforms --scopes forms:read,responses:read,forms:write