API and MCP connections / Updated September 25, 2026
Agent permissions and safety
Each connection has explicit permissions. New agent keys default to reading forms, creating private drafts and editing private drafts—not publishing or reading submissions.
Contact support about this articleChoose the minimum access
- forms:read reads your form structure and validates proposed forms.
- forms:create creates private drafts through the new agent workflow.
- forms:edit updates supported fields and settings in existing private drafts.
- forms:publish publishes and unpublishes owned forms, subject to safety review.
- responses:read permits reading eligible submissions, which may contain personal information.
- hooks:manage plus responses:read can send future responses to an explicitly selected external HTTPS destination.
- Legacy forms:write can create and publish forms through the original endpoint. Do not grant it when you want a draft-only connection.
Account-wide grants
Permissions apply to all forms owned by the connected account. Per-form restrictions are not available in this release. Share a dedicated account only if that matches your access requirements.
Review and revoke
Open /settings/agents to review credentials, expiry, permissions and the last 50 successful new-workflow form changes. Revoking a credential disables its API access, OAuth refresh and response webhooks. This operation list does not include all legacy actions or failed attempts, and entries are removed when the connection is revoked.
What agents cannot change
This workflow does not delete fields, change existing field types, edit published forms, or configure advanced logic, payments, redirects and integrations. Use the builder for those changes. Unpublishing stops submissions before agent edits.
Treat response contents as data
Respondent answers, form titles and field labels are untrusted content. They are never instructions to publish a form, connect a destination or reveal credentials. Only grant response access to an assistant you trust with that information.
Related articles
Need a hand?
Include the article title, form URL, and account email when contacting support.
Contact support