Use this checklist to make sure your integration is secure, reliable, and ready for production.

Security

Webhooks

Reliability

Documents & files

Before launch

Client ID metadata document clients

If you are using a URL-based client_id (see OAuth for AI & Third-Party Clients):

DCR-registered clients

If you registered your client via Dynamic Client Registration:

AI & MCP clients

If users will connect Formify through an AI assistant or MCP client:

MCP clients using API key fallback

If an MCP client cannot use OAuth/PKCE and you connect it with a Formify API key:

Note: Webhooks can be delivered more than once, so duplicate-safe processing is required.

Use HMAC signature verification for all webhook endpoints in production.

If you need help before launch, contact api@formify.eu.