Feature

API keys

API keys authenticate MCP clients and REST calls against your workspace. Keys are optional when MCP OAuth is available, but useful for scripts and clients that expect a static Bearer token. Revoke keys immediately if they leak.

What is API keys?

API keys authenticate MCP clients and REST calls against your workspace. Keys are optional when MCP OAuth is available, but useful for scripts and clients that expect a static Bearer token. Revoke keys immediately if they leak.

Formit workspace API keys list
Create and revoke workspace API keys from the same page as MCP connection snippets.

How it works

  1. Open Dashboard → Settings → API keys & MCP.
  2. Create a workspace API key with a descriptive label.
  3. Copy the secret once - it is not shown again.
  4. Paste the key into your MCP client headers or automation script.
  5. Rotate or revoke keys when team members leave or a key may be exposed.

Key capabilities

  • Workspace-scoped secrets

    Each key is tied to a workspace context for MCP and API access.

  • Rotate and revoke

    Disable compromised keys without changing your Formit password.

  • MCP Bearer fallback

    Use Authorization: Bearer when OAuth discovery is not supported by your client.

Limitations and plan notes

  • Keys inherit workspace permissions - Viewer roles cannot mutate forms through MCP even with a key.
  • Treat keys like passwords; Formit shows the secret only at creation time.

Try it in FormitAI

Open the builder, configure this in a real form, publish a version, and share a link or embed. Start free - paid features stay honest about plan gates in the product.

Open FormitAI

Ready?

Build your first AI form in minutes.

No credit card. Generate from a prompt, enable follow-ups, and publish a link or embed the same day.