Final Frame for agents
An agent works in Final Frame through the same API, the same permissions and the same audit trail as a person in the app. It finds deals, reads titles and deliverables, puts files into placeholders, raises work orders, records rights and answers availability questions. Connect it through MCP, or call the API directly.
What an agent can do
| Area | MCP tools | API |
|---|---|---|
| Discover | whoami, rights_vocabulary | GET /v1/me |
| Deals and titles | find_projects, read_project, create_project, update_project, list_titles, read_title, add_title, update_title, bulk_edit_titles | /v1/projects |
| Deliverables and files | list_deliverables, read_deliverable, add_deliverable, update_deliverable, set_deliverable_status, start_upload, complete_upload, get_download_link | /v1/projects/{id}/deliverables |
| Work orders | list_work_orders, create_work_order | /v1/projects/{id}/work-orders |
| Rights | list_rights_works, read_work_rights, check_availability, rights_map, record_rights_holding, record_rights_restriction | /v1/rights |
| Delivery specs | list_delivery_specs, create_delivery_spec, update_delivery_spec, duplicate_industry_spec | /v1/delivery-specs |
| Set-up as code | None, by design | GET and PUT /v1/config |
| Watching | read_closeout | Audit, close-out and webhooks |
The full tool list, with the permission each needs, is on MCP. The API reference is generated from the running code.
Connecting
| Value | |
|---|---|
| MCP server | https://app.final-frame.com/api/mcp |
| API | https://app.final-frame.com/api/v1 |
| OpenAPI | https://app.final-frame.com/api/v1/openapi.json |
| API keys | Today. Send Authorization: Bearer <key> to either. |
| OAuth sign-in | Coming. A client that signs in sends the person to Final Frame and acts with their access. |
claude mcp add --transport http final-frame https://app.final-frame.com/api/mcp \ --header "Authorization: Bearer <your key>"
Claude Desktop, ChatGPT, Cursor and most clients take the same two facts in their MCP settings: the URL and the header.
Keys
An administrator mints a key under Organisation settings, Integrations with only the permissions the agent needs. An organisation key acts for the organisation. A personal key acts as its owner and never does more than they may today. A key shows once and revokes in a click. More on Authentication.
Start in the Sandbox
The Sandbox is an organisation of fictional deals, titles, files and rights on the same API and MCP server. Its keys start ff_sbx_ and work nowhere else, every answer carries X-FF-Environment: sandbox, and the data resets every night. An agent can try anything there.
What an agent reads first
| Address | What it is |
|---|---|
| /llms.txt | The platform, its vocabulary and every resource on one page, for a language model. |
| /.well-known/agent.json | The machine surfaces: API, MCP, OpenAPI and how to authenticate. |
/.well-known/oauth-protected-resource | The protected-resource metadata MCP clients read. |
Safety
| Control | What happens | |
|---|---|---|
| Scoped keys | A key carries only the permissions chosen for it. A refusal names the missing one. | Live |
| Plain refusals | A tool outside its scope answers with a sentence, so the agent can explain rather than crash. | Live |
| Idempotent writes | A write repeated with the same key or arguments within a day returns the first answer. | Live |
| Audit trail | Every action lands on the organisation’s action log with the credential named. | Live |
| Pause and revoke | An administrator sees each connected app, its actions over seven days, and can pause or revoke it. | Live |
| Approvals | An agent’s write becomes a proposal a person approves before it takes effect. | Coming |