Skip to content

AI agents (MCP)

A coding agent such as Claude Code, Cursor or Codex can set Formward up for you: create the form, drop the snippet into your site, add a webhook and confirm that a test submission arrived. It talks to Formward over the Model Context Protocol with a key that you approve once in the dashboard and that is pinned to one workspace.

The agent has no read access to what your visitors submit: no tool and no scope on its key returns submission content, only counts. The one indirect path is a webhook it adds, which receives future submissions like any webhook you add yourself, so review the form's webhook list after a setup run. Pairing is available on every plan, Free included, and the forms it creates follow your plan's limits like any other form.

Pairing

  1. In the dashboard open More → AI agents (/dashboard/connected-agents) and create a pairing code. Codes are single use and expire after 10 minutes.
  2. In your project, run the CLI with that code. It claims the code and waits.
    npx @formward/mcp pair ABCD-EFGH
  3. Approve the claim in the dashboard. You see the agent's name and the machine it runs on. The CLI stores the 30-day key for your user and never prints it.
  4. Register the server with your agent:
    # Claude Code
    claude mcp add formward -- npx -y @formward/mcp
    
    # Codex CLI
    codex mcp add formward -- npx -y @formward/mcp
    
    # Cursor and other clients (mcp.json)
    { "mcpServers": { "formward": { "command": "npx", "args": ["-y", "@formward/mcp"] } } }

Then ask the agent, in plain words, to add a contact form to your site. A typical run: it lists templates, creates the form with your notification address, fetches the snippet for your framework, edits your page, sends a test submission and checks the count. You confirm the notification address from the verification email and read the test message in your inbox.

Tools

ToolWhat it does
list_formsForms in the workspace with endpoint and hosted page URLs.
list_templatesBuilt-in templates and their field lists.
create_formCreate a form from explicit fields or a template; optionally publish a hosted page.
get_form_snippetPaste-ready markup with the real endpoint, for html, react, vue, svelte, astro, nextjs, nuxt, tailwind, shopify or webflow.
get_form_statsSubmission counts and the time of the latest one. Nothing else.
list_webhooks / add_webhookWebhook destinations (Professional plan and above, same URL checks as the dashboard).
send_test_submissionRuns locally in the CLI: posts one test to the endpoint from the developer's machine.

What an agent key can and cannot do

  • Can: through the MCP tools, list and create forms, fetch snippets, read counts and add webhooks where the plan allows them. The key's scopes (forms, automations and hosted pages, read and write) also work against the REST API directly, for example to update a form definition or an automation.
  • Cannot: read submission content (no tool or scope returns it; a webhook it adds is the only way future submissions reach a destination of its choosing), change billing or team membership, or touch any workspace other than the one it was paired with. Those requests get a 403.
  • Lifetime: 30 days, then the agent has to pair again. Revoke earlier at any time from the same page; every pairing and revocation is in the audit log.

Using your own key

On the Professional plan and above you can skip pairing and point the CLI at a classic REST API key with the FORMWARD_API_KEY environment variable. Such a key is not pinned to one workspace and follows its own scopes, including submission reads if you grant them.

MCP endpoint

The CLI is a thin bridge: every JSON-RPC message goes to POST https://formward.eu/api/v1/mcp with Authorization: Bearer <key>. The endpoint is stateless (no session, no streaming) and speaks protocol revisions 2024-11-05 through 2025-06-18, so any MCP client that can call an HTTP endpoint with a bearer token can use it directly. Creating and listing forms, the snippet, the counts and the webhooks are also plain REST routes under /api/v1/forms (see the REST API). The template list exists only as an MCP tool, and the test submission is posted by the CLI straight to the form endpoint, not through the API.

Data protection

On Formward's side nothing changes: the bridge talks to the same EU-hosted API as the dashboard, and no submission content is returned through it. What the agent does see is form metadata: names, field lists, notification addresses, webhook URLs and submission counts. Your coding agent typically forwards tool results to its model provider, so whether pairing adds a processor to your records depends on the agent you chose and how it is deployed, not on Formward. Treat it like any other tool you give that agent access to. The pairing code is stored hashed, the key is retrievable by the agent only for a short window after approval, and the dashboard shows which agent paired, from where and when.

AI agents (MCP) for form setup | Formward Docs