The address
https://ogforms.app/api/mcp
It speaks MCP over Streamable HTTP. Most clients sign in with OAuth: a page opens where you sign in to OG Forms, pick a workspace, choose read or read and change, and allow it. No key to copy.
Connect your client
- Claude (web or desktop): Settings, Connectors, Add custom connector. Paste the address and press Connect.
- ChatGPT: Settings, Apps and Connectors. Under Advanced settings turn on Developer mode, then create a connector with the address and OAuth.
- Claude Code: run the command below, then type /mcp, choose og-forms, and allow it in the browser.
- Cursor and VS Code: add the server by its address in mcp.json. Each asks you to sign in the first time.
claude mcp add --transport http og-forms https://ogforms.app/api/mcp
A client or script that cannot sign in can send an API key instead, as Authorization: Bearer og_live_... A read key gets only the tools that read.
What it can do
- list_forms and get_form: find forms and read their questions.
- create_form: make a form from its own questions or a template.
- update_form: add, change, move or remove questions, and publish, close or reopen.
- get_responses: read every answer, page by page.
- query_responses: exact counts, averages and breakdowns, with filters.
- add_automation, list_automations and remove_automation: webhooks, team emails and confirmation emails.
It uses no AI credits: your agent writes the questions, and OG Forms holds them to the same quality bar as a form made in the app.
Access and safety
- A connection works in the one workspace you picked, and never beyond your own role there: if you can only view, it can only read.
- If you leave the workspace or your role changes, the connection follows at once.
- Every connection is listed in Settings, API and webhooks, where you can disconnect it. Admins see and can disconnect everyone's.
- Each connection may make 120 requests a minute.
For client builders: discovery starts from the 401, whose WWW-Authenticate header names /.well-known/oauth-protected-resource/api/mcp. The server supports dynamic client registration, the authorization code flow with PKCE (S256) for public clients, refresh tokens that each work once, and token revocation. Server metadata is at /.well-known/oauth-authorization-server.
