Setup
Switch the server on and authenticate the client
Enabling it
Set ENABLE_MCP to 1 and restart. The endpoint is:
POST <your url>/api/v2/mcp
It uses stateless Streamable HTTP with plain JSON responses, so GET and DELETE return 405.
Authentication
Every request needs an AnsibleForms access token:
Authorization: Bearer <token>
Obtain one in the usual way (POST /api/v2/auth/login, or the OIDC / Entra ID flows) and refresh it with POST /api/v2/token. There is deliberately no login tool: a password passed as a tool argument would end up in the language model’s context and its chat history.
- A chat backend logs the user in itself, keeps the refresh token and passes the access token on every MCP call.
- An IDE client needs a token that lasts long enough to be configured once. With a role that has the
extendedTokenExpirationoption, create one under Profile > API token, or log in with?expiryDays=<n>on the login URL for a token valid that many days.
To connect a coding agent with such a token:
Add the server with the token as a header:
claude mcp add --transport http ansibleforms https://af.example.com/api/v2/mcp \
--header "Authorization: Bearer <token>"
Add the server to ~/.codex/config.toml, with the token read from an environment variable:
[mcp_servers.ansibleforms]
url = "https://af.example.com/api/v2/mcp"
bearer_token_env_var = "ANSIBLEFORMS_TOKEN"
Then set the variable before you start Codex:
export ANSIBLEFORMS_TOKEN=<token>