OAUTH 2.0
FILES & DOCUMENTS
Connect to Typeform MCP to create, update, and retrieve forms and responses from your AI workflows using Typeform's conversational survey platform.
` - `class="email-cta-wrapper"` on the `
` (required)
- `href`: destination URL on the ``
- `target="_blank" rel="noopener noreferrer nofollow"` on the `` (required)
- `class="email-cta"` on the `` (required)
- Inner text of ``: button label
### Plain links
For a plain inline hyperlink (no button styling), use this structure inside the body:
```html
```
- `data-id`: unique UUID v4 on the ` `
- `href`: destination URL on the ``
- `target="_blank" rel="noopener noreferrer nofollow"` on the `` (required)
- No `class` on the `` (distinguishes link from CTA button)
- Inner text of ``: link label (often the URL itself)
Use plain links for inline references; use the CTA structure above when the user asks for a button
or prominent call-to-action.
## "self" scope validation
When scope is "self", the "to" array MUST contain at least one real, valid email address.
Do NOT use placeholders like `
` - `class="email-cta-wrapper"` on the `
` (required)
- `href`: destination URL on the ``
- `target="_blank" rel="noopener noreferrer nofollow"` on the `` (required)
- `class="email-cta"` on the `` (required)
- Inner text of ``: button label
### Plain links
For a plain inline hyperlink (no button styling), use this structure inside the body:
```html
```
- `data-id`: unique UUID v4 on the ` `
- `href`: destination URL on the ``
- `target="_blank" rel="noopener noreferrer nofollow"` on the `` (required)
- No `class` on the `` (distinguishes link from CTA button)
- Inner text of ``: link label (often the URL itself)
Use plain links for inline references; use the CTA structure above when the user asks for a button
or prominent call-to-action.
from langchain_mcp_adapters.client import MultiServerMCPClient
from scalekit import ScalekitClient
client = ScalekitClient(env_url=ENV_URL, client_id=CLIENT_ID, client_secret=SECRET)
token = client.agent.get_token(user_id="user_id", connector="typeformmcp")
mcp = MultiServerMCPClient({
"typeformmcp": {
"url": "https://mcp.scalekit.com/typeformmcp",
"headers": {"Authorization": "Bearer " + token}
}
})
tools = await mcp.get_tools()import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";
const client = new ScalekitClient({ envUrl, clientId, clientSecret });
const token = await client.agent.getToken({ userId: "user_id", connector: "typeformmcp" });
const openai = new OpenAI();
// Connect to MCP at https://mcp.scalekit.com/typeformmcp
// Pass: Authorization: Bearer + tokenimport Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";
const client = new ScalekitClient({ envUrl, clientId, clientSecret });
const token = await client.agent.getToken({ userId: "user_id", connector: "typeformmcp" });
const anthropic = new Anthropic();
// Connect to MCP at https://mcp.scalekit.com/typeformmcp
// Pass: Authorization: Bearer + tokenfrom google.adk.agents import LlmAgent
from scalekit import ScalekitClient
client = ScalekitClient(env_url=ENV_URL, client_id=CLIENT_ID, client_secret=SECRET)
token = client.agent.get_token(user_id="user_id", connector="typeformmcp")
# Connect to MCP at https://mcp.scalekit.com/typeformmcp
# Pass: Authorization: Bearer + token// shared token
audit → bot_service_account
// scalekit
audit → user_abc ✓// authn only
has_token? yes
call → 200 (anything)
// scalekit
scope ⊃ tool? yes
call → 200 (allowed)vault/
tenant_acme/ → isolated
tenant_globex/ → isolated
// cross-tenant: denied// DIY: N tools
connector_oauth.py ȕ100
// scalekit
client.tools.execute_tool(
tool_name="any_tool",
) → 100+ tools
Does the agent access Typeform as the user or as a shared key?
As the user. Each workspace member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.
Where is the Typeform OAuth token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Tokens never appear in prompts, logs, or LLM context.
Can I limit what the agent is allowed to do in Typeform?
Yes. Pass a tool name filter to listScopedTools so the productivity agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches Typeform.
What happens when a user revokes Typeform access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Can the agent read responses from any form?
Only forms in workspaces the authorizing user can access. Response reads, contact list updates, and webhook changes follow Typeform workspace roles at request time.



We use cookies, so things load fast, we learn what to fix, and you can always reach us on chat