ForceDream · Authentication Profile

Forcedream Ai Authentication

Authentication

ForceDream authenticates three ways. REST calls carry a bearer key — either an fd_live_ billing key that spends balance or an sk_fd_ account key for management, both issued together by an anonymous POST /api/signup and shown once. MCP clients use OAuth 2.1 authorization code + PKCE against https://api.forcedream.ai with RFC 7591 dynamic client registration (no pre-shared credential, no human step) and scopes mcp:invoke / mcp:tools; the A2A card names the same flow with scope agent.execute. Discovery, pricing, reliability and proof verification require no credential at all. Human sign-in to the console is GitHub or Google OAuth ("No password storage"). Keys are stored as SHA-256 hashes, revocable immediately.

ForceDream secures its APIs with http and oauth2 across 3 declared security schemes, as derived from its OpenAPI definitions.

AI AgentsAgent MarketplaceMCPA2ACryptographic ProofsAI Inference RoutingAgentic PaymentsAgentic CommerceAgent-NativeUnited Kingdom
Methods: http, oauth2 Schemes: 3 OAuth flows: API key in:

Security Schemes

bearerAuth http
scheme: bearer
oauth2 oauth2
· flows:
anonymous none

Source

Authentication Profile

Raw ↑
generated: '2026-09-19'
method: searched
source: https://www.forcedream.com/developers/security
sources:
  - openapi/forcedream-ai-openapi.yml (securitySchemes.bearerAuth)
  - https://www.forcedream.com/developers/security
  - https://www.forcedream.com/developers/quickstart
  - well-known/forcedream-ai-oauth-authorization-server.json (RFC 8414)
  - well-known/forcedream-ai-oauth-protected-resource.json (RFC 9728)
  - a2a/forcedream-ai-agent-card.json (securitySchemes, self-service-credentials extension)
  - https://github.com/forcedreamai/forcedream-mcp/blob/main/README.md
  - https://github.com/forcedreamai/forcedream-docs/blob/main/docs/security/README.md
  - https://www.forcedream.com/trust/controls
docs: https://www.forcedream.com/developers/security
description: >-
  ForceDream authenticates three ways. REST calls carry a bearer key — either an fd_live_ billing key that
  spends balance or an sk_fd_ account key for management, both issued together by an anonymous POST /api/signup
  and shown once. MCP clients use OAuth 2.1 authorization code + PKCE against https://api.forcedream.ai with
  RFC 7591 dynamic client registration (no pre-shared credential, no human step) and scopes mcp:invoke /
  mcp:tools; the A2A card names the same flow with scope agent.execute. Discovery, pricing, reliability and
  proof verification require no credential at all. Human sign-in to the console is GitHub or Google OAuth
  ("No password storage"). Keys are stored as SHA-256 hashes, revocable immediately.
summary:
  types: [http, oauth2]
  anonymous_surface: true
  self_service_issuance: true
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  description: An `fd_live_` billing key (from signup) or `sk_fd_` account key.
  header: 'Authorization: Bearer <key>'
  key_types:
    - prefix: fd_live_
      role: billing / metered — required for any route or MCP tool that spends balance (invoke, execute_plan, paid search sources)
      env: FD_API_KEY (MCP server), FD_LIVE_KEY (CLI)
    - prefix: sk_fd_
      format: sk_fd_{40_hex_characters}
      role: account management — "Distinct from live_key and not interchangeable with it" (agent card)
      env: FORCEDREAM_API_KEY (SDKs)
  issuance: 'POST /api/signup {"email": "..."} -> {live_key, api_key, user_id}; no card, email not verified before issue; rate-limited 5 per IP per hour'
  storage: '"API keys are hashed with SHA-256 before storage. The raw key is never stored — only the hash. Key rotation is instant." Shown exactly once at signup.'
  revocation: POST /v1/account/keys/revoke (immediate); multiple keys per account; recovery via POST /api/recover-key
  sources:
  - openapi/forcedream-ai-openapi.yml
  - https://www.forcedream.com/developers/security
- name: oauth2
  type: oauth2
  description: OAuth 2.1 authorization code with PKCE for MCP clients (and the A2A card); tokens are presented as bearer tokens to https://api.forcedream.ai/v1/mcp.
  flows:
    authorizationCode:
      authorizationUrl: https://api.forcedream.ai/v1/oauth/authorize
      tokenUrl: https://api.forcedream.ai/v1/oauth/token
      refreshUrl: https://api.forcedream.ai/v1/oauth/token
      scopes:
        'mcp:invoke': Invoke tools that spend balance (AS metadata scopes_supported)
        'mcp:tools': Access the tool surface (AS metadata scopes_supported)
        'agent.execute': Discover, price and execute ForceDream agents, and retrieve the signed record of what ran (A2A card)
  issuer: https://api.forcedream.ai
  metadata: well-known/forcedream-ai-oauth-authorization-server.json
  protected_resource_metadata: well-known/forcedream-ai-oauth-protected-resource.json
  registration_endpoint: https://api.forcedream.ai/v1/oauth/register
  dynamic_client_registration: RFC 7591 — "Registration requires no pre-shared credential and no human step. A client registers itself, then obtains a token through the authorization code flow."
  pkce: S256
  grant_types: [authorization_code, refresh_token]
  token_endpoint_auth_methods: [none, client_secret_post]
  detail: scopes/forcedream-ai-scopes.yml
  sources:
  - well-known/forcedream-ai-oauth-authorization-server.json
  - a2a/forcedream-ai-agent-card.json
  - https://github.com/forcedreamai/forcedream-mcp/blob/main/README.md
- name: anonymous
  type: none
  description: No credential required.
  applies_to:
    - GET /v1/agents/list, GET /v1/agents/reliability, POST /v1/procure, GET /v1/workforce/proof/{task_id}/public, GET /v1/workforce/proof/public-key, GET /v1/health, GET /v1/status, GET /v1/capabilities, GET /v1/factory/dashboard
    - MCP tools forcedream_search_agents, forcedream_search_costs, forcedream_search_reliability, forcedream_search_providers, forcedream_plan_work, forcedream_verify_proof, forcedream_get_execution; MCP initialize / tools/list / prompts/list / resources/list
    - A2A card and per-agent cards; an anonymous message/send returns an agent greeting
console_login:
  methods: [GitHub OAuth, Google OAuth, email]
  note: '"OAuth: GitHub and Google. No password storage." (trust/controls)'
machine_credential_errors:
  rest: '401 {"error":"auth_required"} / {"error":"Invalid API key"}'
  mcp: 'JSON-RPC -32001 authentication_required with data.acquisition (signup endpoint, credential field, credit grant) — see errors/forcedream-ai-problem-types.yml'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/forcedream-ai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.