generated: '2026-09-19' method: searched source: https://www.forcedream.com/developers/security sources: - openapi/forcedream-ai-openapi.yml (securitySchemes.bearerAuth) - https://www.forcedream.com/developers/security - https://www.forcedream.com/developers/quickstart - well-known/forcedream-ai-oauth-authorization-server.json (RFC 8414) - well-known/forcedream-ai-oauth-protected-resource.json (RFC 9728) - a2a/forcedream-ai-agent-card.json (securitySchemes, self-service-credentials extension) - https://github.com/forcedreamai/forcedream-mcp/blob/main/README.md - https://github.com/forcedreamai/forcedream-docs/blob/main/docs/security/README.md - https://www.forcedream.com/trust/controls docs: https://www.forcedream.com/developers/security description: >- ForceDream authenticates three ways. REST calls carry a bearer key — either an fd_live_ billing key that spends balance or an sk_fd_ account key for management, both issued together by an anonymous POST /api/signup and shown once. MCP clients use OAuth 2.1 authorization code + PKCE against https://api.forcedream.ai with RFC 7591 dynamic client registration (no pre-shared credential, no human step) and scopes mcp:invoke / mcp:tools; the A2A card names the same flow with scope agent.execute. Discovery, pricing, reliability and proof verification require no credential at all. Human sign-in to the console is GitHub or Google OAuth ("No password storage"). Keys are stored as SHA-256 hashes, revocable immediately. summary: types: [http, oauth2] anonymous_surface: true self_service_issuance: true schemes: - name: bearerAuth type: http scheme: bearer description: An `fd_live_` billing key (from signup) or `sk_fd_` account key. header: 'Authorization: Bearer ' key_types: - prefix: fd_live_ role: billing / metered — required for any route or MCP tool that spends balance (invoke, execute_plan, paid search sources) env: FD_API_KEY (MCP server), FD_LIVE_KEY (CLI) - prefix: sk_fd_ format: sk_fd_{40_hex_characters} role: account management — "Distinct from live_key and not interchangeable with it" (agent card) env: FORCEDREAM_API_KEY (SDKs) issuance: 'POST /api/signup {"email": "..."} -> {live_key, api_key, user_id}; no card, email not verified before issue; rate-limited 5 per IP per hour' storage: '"API keys are hashed with SHA-256 before storage. The raw key is never stored — only the hash. Key rotation is instant." Shown exactly once at signup.' revocation: POST /v1/account/keys/revoke (immediate); multiple keys per account; recovery via POST /api/recover-key sources: - openapi/forcedream-ai-openapi.yml - https://www.forcedream.com/developers/security - name: oauth2 type: oauth2 description: OAuth 2.1 authorization code with PKCE for MCP clients (and the A2A card); tokens are presented as bearer tokens to https://api.forcedream.ai/v1/mcp. flows: authorizationCode: authorizationUrl: https://api.forcedream.ai/v1/oauth/authorize tokenUrl: https://api.forcedream.ai/v1/oauth/token refreshUrl: https://api.forcedream.ai/v1/oauth/token scopes: 'mcp:invoke': Invoke tools that spend balance (AS metadata scopes_supported) 'mcp:tools': Access the tool surface (AS metadata scopes_supported) 'agent.execute': Discover, price and execute ForceDream agents, and retrieve the signed record of what ran (A2A card) issuer: https://api.forcedream.ai metadata: well-known/forcedream-ai-oauth-authorization-server.json protected_resource_metadata: well-known/forcedream-ai-oauth-protected-resource.json registration_endpoint: https://api.forcedream.ai/v1/oauth/register dynamic_client_registration: RFC 7591 — "Registration requires no pre-shared credential and no human step. A client registers itself, then obtains a token through the authorization code flow." pkce: S256 grant_types: [authorization_code, refresh_token] token_endpoint_auth_methods: [none, client_secret_post] detail: scopes/forcedream-ai-scopes.yml sources: - well-known/forcedream-ai-oauth-authorization-server.json - a2a/forcedream-ai-agent-card.json - https://github.com/forcedreamai/forcedream-mcp/blob/main/README.md - name: anonymous type: none description: No credential required. applies_to: - GET /v1/agents/list, GET /v1/agents/reliability, POST /v1/procure, GET /v1/workforce/proof/{task_id}/public, GET /v1/workforce/proof/public-key, GET /v1/health, GET /v1/status, GET /v1/capabilities, GET /v1/factory/dashboard - MCP tools forcedream_search_agents, forcedream_search_costs, forcedream_search_reliability, forcedream_search_providers, forcedream_plan_work, forcedream_verify_proof, forcedream_get_execution; MCP initialize / tools/list / prompts/list / resources/list - A2A card and per-agent cards; an anonymous message/send returns an agent greeting console_login: methods: [GitHub OAuth, Google OAuth, email] note: '"OAuth: GitHub and Google. No password storage." (trust/controls)' machine_credential_errors: rest: '401 {"error":"auth_required"} / {"error":"Invalid API key"}' mcp: 'JSON-RPC -32001 authentication_required with data.acquisition (signup endpoint, credential field, credit grant) — see errors/forcedream-ai-problem-types.yml'