Opening Final Frame
Verifying your credentialsEstablishing an encrypted sessionPreparing your workspace
Secured by WorkOS
This is taking longer than usual. Your connection may be slow.

Final Frame for agents

An agent works in Final Frame through the same API, the same permissions and the same audit trail as a person in the app. It finds deals, reads titles and deliverables, puts files into placeholders, raises work orders, records rights and answers availability questions. Connect it through MCP, or call the API directly.

What an agent can do

AreaMCP toolsAPI
Discoverwhoami, rights_vocabularyGET /v1/me
Deals and titlesfind_projects, read_project, create_project, update_project, list_titles, read_title, add_title, update_title, bulk_edit_titles/v1/projects
Deliverables and fileslist_deliverables, read_deliverable, add_deliverable, update_deliverable, set_deliverable_status, start_upload, complete_upload, get_download_link/v1/projects/{id}/deliverables
Work orderslist_work_orders, create_work_order/v1/projects/{id}/work-orders
Rightslist_rights_works, read_work_rights, check_availability, rights_map, record_rights_holding, record_rights_restriction/v1/rights
Delivery specslist_delivery_specs, create_delivery_spec, update_delivery_spec, duplicate_industry_spec/v1/delivery-specs
Set-up as codeNone, by designGET and PUT /v1/config
Watchingread_closeoutAudit, close-out and webhooks

The full tool list, with the permission each needs, is on MCP. The API reference is generated from the running code.

Connecting

Value
MCP serverhttps://app.final-frame.com/api/mcp
APIhttps://app.final-frame.com/api/v1
OpenAPIhttps://app.final-frame.com/api/v1/openapi.json
API keysToday. Send Authorization: Bearer <key> to either.
OAuth sign-inComing. A client that signs in sends the person to Final Frame and acts with their access.
claude mcp add --transport http final-frame https://app.final-frame.com/api/mcp \
  --header "Authorization: Bearer <your key>"

Claude Desktop, ChatGPT, Cursor and most clients take the same two facts in their MCP settings: the URL and the header.

Keys

An administrator mints a key under Organisation settings, Integrations with only the permissions the agent needs. An organisation key acts for the organisation. A personal key acts as its owner and never does more than they may today. A key shows once and revokes in a click. More on Authentication.

Start in the Sandbox

The Sandbox is an organisation of fictional deals, titles, files and rights on the same API and MCP server. Its keys start ff_sbx_ and work nowhere else, every answer carries X-FF-Environment: sandbox, and the data resets every night. An agent can try anything there.

What an agent reads first

AddressWhat it is
/llms.txtThe platform, its vocabulary and every resource on one page, for a language model.
/.well-known/agent.jsonThe machine surfaces: API, MCP, OpenAPI and how to authenticate.
/.well-known/oauth-protected-resourceThe protected-resource metadata MCP clients read.

Safety

ControlWhat happens
Scoped keysA key carries only the permissions chosen for it. A refusal names the missing one.Live
Plain refusalsA tool outside its scope answers with a sentence, so the agent can explain rather than crash.Live
Idempotent writesA write repeated with the same key or arguments within a day returns the first answer.Live
Audit trailEvery action lands on the organisation’s action log with the credential named.Live
Pause and revokeAn administrator sees each connected app, its actions over seven days, and can pause or revoke it.Live
ApprovalsAn agent’s write becomes a proposal a person approves before it takes effect.Coming