Setup

Switch the server on and authenticate the client

  1. Enabling it
  2. Authentication

Enabling it

Set ENABLE_MCP to 1 and restart. The endpoint is:

POST <your url>/api/v2/mcp

It uses stateless Streamable HTTP with plain JSON responses, so GET and DELETE return 405.

Authentication

Every request needs an AnsibleForms access token:

Authorization: Bearer <token>

Obtain one in the usual way (POST /api/v2/auth/login, or the OIDC / Entra ID flows) and refresh it with POST /api/v2/token. There is deliberately no login tool: a password passed as a tool argument would end up in the language model’s context and its chat history.

  • A chat backend logs the user in itself, keeps the refresh token and passes the access token on every MCP call.
  • An IDE client needs a token that lasts long enough to be configured once. With a role that has the extendedTokenExpiration option, create one under Profile > API token, or log in with ?expiryDays=<n> on the login URL for a token valid that many days.

To connect a coding agent with such a token:

Add the server with the token as a header:

claude mcp add --transport http ansibleforms https://af.example.com/api/v2/mcp \
  --header "Authorization: Bearer <token>"

Copyright © 2023-2026 AnsibleForms. All rights reserved.

This site uses Just the Docs, a documentation theme for Jekyll.