ForceDream authenticates three ways. REST calls carry a bearer key — either an fd_live_ billing key that spends balance or an sk_fd_ account key for management, both issued together by an anonymous POST /api/signup and shown once. MCP clients use OAuth 2.1 authorization code + PKCE against https://api.forcedream.ai with RFC 7591 dynamic client registration (no pre-shared credential, no human step) and scopes mcp:invoke / mcp:tools; the A2A card names the same flow with scope agent.execute. Discovery, pricing, reliability and proof verification require no credential at all. Human sign-in to the console is GitHub or Google OAuth ("No password storage"). Keys are stored as SHA-256 hashes, revocable immediately.
ForceDream secures its APIs with http and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions.
AI AgentsAgent MarketplaceMCPA2ACryptographic ProofsAI Inference RoutingAgentic PaymentsAgentic CommerceAgent-NativeUnited Kingdom
Methods: http, oauth2Schemes: 3OAuth flows: API key in:
generated: '2026-09-19'
method: searched
source: https://www.forcedream.com/developers/security
sources:
- openapi/forcedream-ai-openapi.yml (securitySchemes.bearerAuth)
- https://www.forcedream.com/developers/security
- https://www.forcedream.com/developers/quickstart
- well-known/forcedream-ai-oauth-authorization-server.json (RFC 8414)
- well-known/forcedream-ai-oauth-protected-resource.json (RFC 9728)
- a2a/forcedream-ai-agent-card.json (securitySchemes, self-service-credentials extension)
- https://github.com/forcedreamai/forcedream-mcp/blob/main/README.md
- https://github.com/forcedreamai/forcedream-docs/blob/main/docs/security/README.md
- https://www.forcedream.com/trust/controls
docs: https://www.forcedream.com/developers/security
description: >-
ForceDream authenticates three ways. REST calls carry a bearer key — either an fd_live_ billing key that
spends balance or an sk_fd_ account key for management, both issued together by an anonymous POST /api/signup
and shown once. MCP clients use OAuth 2.1 authorization code + PKCE against https://api.forcedream.ai with
RFC 7591 dynamic client registration (no pre-shared credential, no human step) and scopes mcp:invoke /
mcp:tools; the A2A card names the same flow with scope agent.execute. Discovery, pricing, reliability and
proof verification require no credential at all. Human sign-in to the console is GitHub or Google OAuth
("No password storage"). Keys are stored as SHA-256 hashes, revocable immediately.
summary:
types: [http, oauth2]
anonymous_surface: true
self_service_issuance: true
schemes:
- name: bearerAuth
type: http
scheme: bearer
description: An `fd_live_` billing key (from signup) or `sk_fd_` account key.
header: 'Authorization: Bearer <key>'
key_types:
- prefix: fd_live_
role: billing / metered — required for any route or MCP tool that spends balance (invoke, execute_plan, paid search sources)
env: FD_API_KEY (MCP server), FD_LIVE_KEY (CLI)
- prefix: sk_fd_
format: sk_fd_{40_hex_characters}
role: account management — "Distinct from live_key and not interchangeable with it" (agent card)
env: FORCEDREAM_API_KEY (SDKs)
issuance: 'POST /api/signup {"email": "..."} -> {live_key, api_key, user_id}; no card, email not verified before issue; rate-limited 5 per IP per hour'
storage: '"API keys are hashed with SHA-256 before storage. The raw key is never stored — only the hash. Key rotation is instant." Shown exactly once at signup.'
revocation: POST /v1/account/keys/revoke (immediate); multiple keys per account; recovery via POST /api/recover-key
sources:
- openapi/forcedream-ai-openapi.yml
- https://www.forcedream.com/developers/security
- name: oauth2
type: oauth2
description: OAuth 2.1 authorization code with PKCE for MCP clients (and the A2A card); tokens are presented as bearer tokens to https://api.forcedream.ai/v1/mcp.
flows:
authorizationCode:
authorizationUrl: https://api.forcedream.ai/v1/oauth/authorize
tokenUrl: https://api.forcedream.ai/v1/oauth/token
refreshUrl: https://api.forcedream.ai/v1/oauth/token
scopes:
'mcp:invoke': Invoke tools that spend balance (AS metadata scopes_supported)
'mcp:tools': Access the tool surface (AS metadata scopes_supported)
'agent.execute': Discover, price and execute ForceDream agents, and retrieve the signed record of what ran (A2A card)
issuer: https://api.forcedream.ai
metadata: well-known/forcedream-ai-oauth-authorization-server.json
protected_resource_metadata: well-known/forcedream-ai-oauth-protected-resource.json
registration_endpoint: https://api.forcedream.ai/v1/oauth/register
dynamic_client_registration: RFC 7591 — "Registration requires no pre-shared credential and no human step. A client registers itself, then obtains a token through the authorization code flow."
pkce: S256
grant_types: [authorization_code, refresh_token]
token_endpoint_auth_methods: [none, client_secret_post]
detail: scopes/forcedream-ai-scopes.yml
sources:
- well-known/forcedream-ai-oauth-authorization-server.json
- a2a/forcedream-ai-agent-card.json
- https://github.com/forcedreamai/forcedream-mcp/blob/main/README.md
- name: anonymous
type: none
description: No credential required.
applies_to:
- GET /v1/agents/list, GET /v1/agents/reliability, POST /v1/procure, GET /v1/workforce/proof/{task_id}/public, GET /v1/workforce/proof/public-key, GET /v1/health, GET /v1/status, GET /v1/capabilities, GET /v1/factory/dashboard
- MCP tools forcedream_search_agents, forcedream_search_costs, forcedream_search_reliability, forcedream_search_providers, forcedream_plan_work, forcedream_verify_proof, forcedream_get_execution; MCP initialize / tools/list / prompts/list / resources/list
- A2A card and per-agent cards; an anonymous message/send returns an agent greeting
console_login:
methods: [GitHub OAuth, Google OAuth, email]
note: '"OAuth: GitHub and Google. No password storage." (trust/controls)'
machine_credential_errors:
rest: '401 {"error":"auth_required"} / {"error":"Invalid API key"}'
mcp: 'JSON-RPC -32001 authentication_required with data.acquisition (signup endpoint, credential field, credit grant) — see errors/forcedream-ai-problem-types.yml'
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.