Developers and agents

AutoRFP.ai API and MCP documentation

AutoRFP.ai is the accuracy-first, AI-native, source-grounded platform for RFPs, security questionnaires, and DDQs. Agents connect through a read-only Model Context Protocol server that keeps source citations and applies each user’s existing workspace permissions.

Public REST API

These endpoints are reachable without an account or API key. Unknown /api/* paths return HTTP 404 with application/problem+json so agents can parse the error instead of an HTML page.

Sandbox, trial, and credentials

The public discovery API is the no-credential sandbox: agents can fetch identity, OpenAPI, and resource links without filling a form. Workspace MCP access uses OAuth 2.0 Authorization Code with PKCE. There is no self-serve API key. Request only the read scopes your tools need. Published AutoRFP.ai plans include a 30-day money-back guarantee on thepricing page.

Streamable HTTP endpoints

Choose the region where your AutoRFP.ai workspace is hosted. Each server exposes one /mcpendpoint and accepts JSON-RPC requests over HTTP POST.

OAuth and scoped permissions

The server uses OAuth 2.0 Authorization Code with PKCE. Request only the scopes needed for the tools your agent will call. The token does not expand a user’s access, and row-level workspace permissions continue to apply.

ScopePermission
tags:readRead the workspace tag vocabulary.
projects:readRead projects and their requirements.
content:readSearch and read approved content and its usage.

Authorization metadata: OAuth server andMCP protected resource.

Request example

Send both response media types required by Streamable HTTP and include the protocol version with every request.

curl https://api.autorfp.ai/mcp \
  -X POST \
  -H "Authorization: Bearer $AUTORFP_ACCESS_TOKEN" \
  -H "MCP-Protocol-Version: 2025-11-25" \
  -H "Accept: application/json, text/event-stream" \
  -H "Content-Type: application/json" \
  --data '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'

JSON errors

Protocol and authentication failures return structured JSON. The error field is stable for programmatic handling, while error_description explains how to resolve the request.

{
  "error": "invalid_token",
  "error_description": "Missing Authorization header"
}

Public discovery resources