Any MCP client

Fóir runs a hosted MCP server. Connect your own agent and it works inside the permissions of the person who connected it, or inside the scopes of the secret key it was given.

One hosted server

The server is hosted at https://mcp.foir.dev/mcp and speaks Streamable HTTP. Each tool calls the same platform RPCs the console and the CLI use, so validation and row-level scoping stay with the platform. Record writes land as drafts on models with publishing enabled, and publish and delete are separate tools. Your agent brings its own model, so connecting it spends no AI credits.

Two ways to authenticate

The first is signing in. Add the server's URL to your client, and the first use opens a Fóir consent screen in your browser, where you grant access up to your own level. The agent then acts as you.

The second is a secret API key, which suits CI and unattended jobs. foir mcp runs a local proxy to the hosted server and uses the key in FOIR_API_KEY when one is set. The agent's reach is then the key's own scopes. A public key is refused.

What a signed-in agent can reach

After sign-in the agent's token can only discover what you have access to. It has to enter one workspace, and optionally one project and organisation, which mints a working token carrying your effective permissions there. Working tokens last 30 minutes and are re-minted, and the workspace and project cannot be chosen per call.

The tool list is filtered on every request by what the credential holds, so two people connecting the same agent to the same project can be offered different tools.

Read-only connections

Tick Read-only on the consent screen and the agent is offered read tools only. Consent is the ceiling whatever the agent reads later, so an instruction hidden in content cannot turn a read-only grant into a write. The CLI proxy has a matching flag for a signed-in session. It cannot narrow a key.

Read the detail

The agent guide covers setup for each client, choosing a workspace and project, and what an agent can and cannot do.