Forma

Connect your AI to Forma without copying a token

Paste one URL, sign in, and approve. Forma now connects to Grok and compatible AI tools through OAuth instead of hand-copied API keys.

Connecting an AI tool to a CMS used to begin with the least friendly sentence in software:

First, create an API token.

Then came the copying, the advanced authentication fields, and the quiet question nobody wanted to ask: where did I just paste the password to my website?

Forma now has a shorter answer. Copy one URL from Settings → Access, paste it into a custom or remote MCP connector, sign in to your own site, and approve the connection.

That is it. No token appears on screen. No secret goes through the conversation.

What happens after you paste the URL

The URL points to Forma's remote MCP endpoint:

https://your-site.com/api/v1/mcp

When Grok or another compatible AI tool contacts it for the first time, Forma says, in effect: “This resource needs authorization, and here is where to learn how.”

The tool reads Forma's public OAuth metadata, registers itself, and opens your site in a browser. You sign in with the same admin account you already use. Forma then shows a consent screen that names the tool and lists exactly what it wants to do.

If you approve, the tool receives a short-lived credential behind the scenes. You never have to copy it, store it in a note, or paste it into chat.

Anyone who has connected an app to GitHub, Notion, or Google has used the same basic pattern: sign in at the service you trust, review the request, then approve or cancel.

What “Site editor access” means

The chatbot connection can:

  • Read pages, posts, snippets, media, and SEO
  • Create and update pages, posts, and snippets
  • Upload media
  • Update public site identity and SEO
  • Use Forma's single last-known-good rollback point

It cannot:

  • Delete content or media
  • Change admin accounts
  • Change security settings
  • Import a site backup
  • Update Forma itself
  • Open a shell on the server

Those limits are enforced by Forma, not left to the chatbot's good intentions.

Three ways into Forma

Settings → Access now reflects the three real access paths:

  1. Admin login — a person signs into the browser with a username and password.
  2. AI chatbots — Grok, ChatGPT, Claude, Perplexity, or another compatible client connects through OAuth and MCP.
  3. API keys — Cursor, scripts, and tools without browser-based OAuth use a scoped Bearer token.

Most site owners should use the first two. API keys remain useful for developer tools and automation, but they are no longer the price of admission for a chatbot.

Grok was the first live test

The first end-to-end connection was deliberately ordinary:

  1. Open Grok's custom connector screen.
  2. Paste the Forma MCP URL.
  3. Sign in to Forma.
  4. Review “Connect Grok?”
  5. Click Allow Site editor.

Grok appeared in Forma's Connected tools list with one active connection. No client ID was typed. No authorization endpoint was copied. No token was exposed.

That boring result took a fair amount of plumbing. That is the point. Good infrastructure makes the user experience uneventful.

The old path still exists

Some clients do not support remote MCP or automatic OAuth discovery. They can still use an API key from Settings → Access.

ChatGPT is a good example of why both paths matter. A ChatGPT workspace with remote MCP connector support can use the paste-one-URL OAuth flow. A Custom GPT Action can instead import Forma's OpenAPI schema and authenticate with a Bearer key.

Same CMS. Same guarded editing surface. Different transport.

What to do after connecting

Do not begin with “redesign my whole site.”

Start with:

Read the site first. Tell me what you found, identify the three highest-impact content or SEO improvements, and do not change anything until I approve the plan.

The connection is easy on purpose. Judgment is still your job.