Forma

The Agent API grew up: redirects, a health check, and MCP parity

Redirects and a filesystem health check existed in Forma's Agent API but weren't listed in /api/v1/help or the MCP server. Both gaps are closed.

/api/v1/redirects and /api/v1/health have existed in Forma for a while. They just weren't listed anywhere an agent would think to look. GET /api/v1/help is the documented first call for any agent working against Forma — it's supposed to be the map. If an endpoint isn't on it, an agent has no reason to believe it exists, and the Cursor MCP server, which wraps the same API, hadn't caught up either. Both gaps are closed now.

What was actually missing

Not the functionality — the discoverability:

  • /api/v1/help now lists GET/PUT /api/v1/redirects, DELETE /api/v1/redirects/{id}, and GET /api/v1/health alongside every other endpoint, with the scope each one needs.
  • The MCP server picked up five tools to match: formax_list_redirects, formax_save_redirect, formax_delete_redirect, formax_health, and formax_import_site.

An agent that reads /help before improvising — which is the whole point of having a /help endpoint — now actually sees the full surface instead of guessing at a subset of it.

Redirects, agent-side

curl -X PUT https://your-site.com/api/v1/redirects \
  -H "Authorization: Bearer fx_…" -H "Content-Type: application/json" \
  -d '{"from_path":"/old-page","to_url":"/new-page","status":301,"enabled":true}'

from_path gets normalized to a leading-slash path even if you paste a full URL. Status accepts 301, 302, 307, or 308. There's a hard guardrail baked in server-side: you cannot target /admin or /api no matter what the caller asks for, because a redirect there isn't a content decision, it's an outage.

A filesystem check sized for an agent, not a human

Settings → Server runs a thorough hosting diagnostic — PHP version, permissions, .htaccess, TLS, the works. That's a lot of surface area for an agent that just wants to know one thing after a manual FTP deploy: did a folder end up nested inside itself? GET /api/v1/health answers exactly that, fast:

{
  "ok": true,
  "checks": {
    "lib/lib/ (nested bad)": false,
    "admin/admin/ (nested bad)": false,
    "admin/css/core.css": true
  },
  "hint": "Filesystem looks good"
}

lib/lib/ and admin/admin/ are the two classic signatures of dragging a zip's contents one level too deep during a manual upload. Both false means neither happened.

Why a documentation gap is a real bug

An API that works but isn't listed anywhere is functionally the same as an API that doesn't exist, from an agent's point of view — it can't call what it doesn't know is there, and it has no way to find out short of reading PHP source it wasn't given access to. The fix here wasn't new code. It was making the map match the territory, which is the only thing GET /api/v1/help is actually for.