Govforms MCP capabilities
MCP API units: Each tools/call is charged by the operation it runs. Initialization, tool discovery, resources and prompts do not use monthly units.
MCP API units
| Tool operation | Units |
|---|---|
| Darcy calls; status, summary, permission and export polling | 1 |
| Lists, searches, full service reads, Response Hub pages up to 100 records and ordinary changes | 5 |
| Full-definition saves, pages over 100 records, export start/download and roster stage/apply | 25 |
Every tools/call in a JSON-RPC batch is admitted and charged separately. Successful results include _meta.govformsApiUsage. Quota errors include the equivalent usage fields in JSON-RPC error.data. Operations affecting more than one account charge once per affected account and group authorised libraries that share each balance.
Govforms MCP lets an AI agent inspect and manage Govforms through structured, permission-aware tools. It can work with form designs and with Response Hub data while keeping those two areas separate.
What an agent can do
Depending on the access granted, an agent can:
- find libraries, services and reusable patterns;
- inspect form structure, settings, conditions, actions and deployment status;
- create and update forms through structured Govforms tools;
- prepare deployments and undeployments;
- list Response Hub data collection services and collections;
- manage collection lifecycle, cohorts, respondent assignments and roster imports;
- read immutable submitted response versions and review issues;
- claim, return, accept, release, reassign or complete Response Hub reviews;
- inspect respondent communications and the collection audit trail.
Govforms also exposes guidance resources that help an agent understand the platform model and choose a safe tool before making changes.
You choose the access
Interactive MCP uses your Govforms sign-in. When connecting an MCP client, every library has two independent access choices:
Form designs
- No access — the agent cannot see forms in that library.
- Read-only — the agent can inspect forms and deployment status.
- Full access — the agent may update forms or prepare deployments where the signed-in person's Govforms role also allows it.
Response Hub data
- No access — the agent cannot see collections, respondents or submissions.
- Read-only — the agent can inspect collections, submitted responses, reviews, communications and audit history.
- Full access — the agent may manage collections, assignments, rosters and reviews where the signed-in person's Govforms role also allows it.
Nothing is selected by default. Govforms checks both the connection grant and the person's current library role on every call. If that role changes or is removed, the connection immediately follows the new access.
This makes it possible to let an agent improve a form without exposing live respondent data, let an operational agent triage submissions without access to unrelated form designs, or give an audit agent read-only access to both areas.
Ways to connect
Interactive OAuth is recommended for people using an agent directly. Connect the MCP client to:
https://govforms.uk/builder/mcp
The person signs in to Govforms, selects libraries, then separately chooses form-design and Response Hub access for each one.
API-key MCP is designed for controlled server-side integrations. Its endpoint is:
https://govforms.uk/builder/libraries/{libraryId}/mcp
API key permissions separately control form reads, form writes, deployments, Response Hub reads and Response Hub writes. The tool catalogue only includes operations allowed by that key.
Response Hub tools
Read tools list services, collections, cohorts, assignments, immutable submitted response versions, reviews, communications, audit events and applied form-revision metadata.
Write tools create or update services and collections, change collection lifecycle, apply saved forms, manage cohorts and assignments, stage and apply rosters, and perform review actions.
Creating a collection also requires form-write access. Applying a collection form also requires deployment access. These extra checks prevent Response Hub access from becoming an indirect route to unrelated form-design changes.
Safety boundaries
- Every operation is restricted to the selected library.
- Response Hub records are also restricted to one data collection service, collection and environment.
- Read-only grants cannot invoke mutating tools.
- Form-design access does not imply Response Hub access, or the reverse.
- The signed-in person's current Govforms role remains the upper limit for interactive MCP.
- Applying a collection form to QA, Staging or Production returns a human approval step.
- Submitted Response Hub versions and audit records remain immutable.
- Tools identify read-only, destructive and externally visible operations for MCP clients.
Treat agent access as sensitive. Start with read-only access, select only the libraries and areas needed, inspect planned changes, and grant full access only to workflows that are understood and supervised.
