Connect Quaflo MCP in AI assistants like Claude, ChatGPT, WorkBuddy, and editors like Cursor, Claude Code, Trae, Qoder, and CodeBuddy
MCP (Model Context Protocol) is an open protocol that allows AI assistants to access external services and data sources through standardized interfaces. With Quaflo MCP service, you can manage survey data directly in AI editors like Cursor and Claude Code without switching to the web interface.
| Aspect | OAuth ConnectorRecommended | Personal Access Token |
|---|---|---|
| Authorization | Browser sign-in, no secret to copy | Paste a token into a config file |
| Token lifetime | Short-lived + auto-refresh | Long-lived (rotate manually) |
| Permissions | Pick scopes on the consent screen | Set scopes when creating the token |
| Revoke | One-click revoke per connector in settings | Delete or disable the token |
| Best for | Hosts with a connector UI (Claude, ChatGPT, WorkBuddy) | Config-file clients (Cursor, Trae, Qoder, CodeBuddy, Windsurf) |
Open your host's connector settings and choose "Add custom / remote connector".
Paste the MCP server URL below and save:
https://api.quaflo.com/api/v1/mcpThe host opens the authorization page: sign in to Quaflo → pick the scopes to grant → approve, then it returns automatically.
Review each connector's scopes and last-used time — and revoke in one click — under Account Settings → Authorized Apps.
Click the gear icon in the bottom left, select "Settings" → "Features" → "MCP Servers"
In MCP Servers configuration, add the following configuration:
{
"mcpServers": {
"quaflo": {
"url": "https://api.quaflo.com/api/v1/mcp",
"transport": "streamable-http",
"headers": {
"Authorization": "Bearer YOUR_PERSONAL_ACCESS_TOKEN"
}
}
}
}After saving the configuration, restart Cursor to apply the changes.
After restart, you can ask in the AI chat: "List my surveys". If configured correctly, the AI will be able to access your survey data.
In Claude Code, open Settings → MCP Configuration
Add Quaflo MCP server configuration:
{
"mcpServers": {
"quaflo": {
"url": "https://api.quaflo.com/api/v1/mcp",
"transport": "streamable-http",
"headers": {
"Authorization": "Bearer YOUR_PERSONAL_ACCESS_TOKEN"
}
}
}
}Save configuration and reload MCP servers.
Try asking the AI: "Show my survey list" to verify the connection is successful.
Open Windsurf Settings (⌘+, on macOS, Ctrl+, on Windows/Linux), search for "MCP" to find the MCP Servers section. You can also browse the MCP Marketplace directly.
Click "View raw config" to open the configuration file (located at ~/.codeium/windsurf/mcp_config.json), and add the following configuration:
{
"mcpServers": {
"quaflo": {
"url": "https://api.quaflo.com/api/v1/mcp",
"transport": "streamable-http",
"headers": {
"Authorization": "Bearer YOUR_PERSONAL_ACCESS_TOKEN"
}
}
}
}After saving the configuration, fully restart Windsurf, then click "Refresh" in the MCP Servers section to load the new configuration.
Ask in Cascade chat: "List my surveys" to verify the connection is successful.
Press Ctrl+U (⌘+U on macOS) to open the Agents panel, click the gear icon to enter "AI Management" → "MCP", then select "Configure Manually".
Paste the following configuration in the MCP settings (you can also create a .trae/mcp.json file in your project root):
{
"mcpServers": {
"quaflo": {
"url": "https://api.quaflo.com/api/v1/mcp",
"transport": "streamable-http",
"headers": {
"Authorization": "Bearer YOUR_PERSONAL_ACCESS_TOKEN"
}
}
}
}After saving the configuration, restart Trae to apply the changes.
Ask in the AI chat: "List my surveys". If configured correctly, the AI will be able to access your survey data.
In WorkBuddy's MCP service management, choose to add a custom MCP (edit mcp.json).
Add the mcpServers config below (token-based auth):
{
"mcpServers": {
"quaflo": {
"url": "https://api.quaflo.com/api/v1/mcp",
"transport": "streamable-http",
"headers": {
"Authorization": "Bearer YOUR_PERSONAL_ACCESS_TOKEN"
}
}
}
}Click "Trust" in the MCP service list; after editing mcp.json, exit and re-enter the current session. WorkBuddy also supports the OAuth connector (Option 1), which is preferred.
Ask in chat: "List my surveys" — success means the connection works.
In Qoder's MCP panel choose "Manual configuration" / "Add MCP server" (follow your build's UI).
Choose Streamable HTTP (SSE on older builds) and enter the endpoint below as the URL. If the panel supports custom headers, add Authorization: Bearer <your token>; if it does not, use the OAuth connector method above or another client. If your build accepts pasted JSON, paste the config below:
{
"mcpServers": {
"quaflo": {
"url": "https://api.quaflo.com/api/v1/mcp",
"transport": "streamable-http",
"headers": {
"Authorization": "Bearer YOUR_PERSONAL_ACCESS_TOKEN"
}
}
}
}Save, then confirm the server shows as connected in the MCP list; if not, check that the token is still valid.
Ask in chat: "List my surveys". A list means the connection works.
In CodeBuddy IDE settings open MCP, choose "Add MCP server" and edit the config.
Use type streamableHttp and add the mcpServers block below (the token goes in headers):
{
"mcpServers": {
"quaflo": {
"type": "streamableHttp",
"url": "https://api.quaflo.com/api/v1/mcp",
"headers": {
"Authorization": "Bearer YOUR_PERSONAL_ACCESS_TOKEN"
}
}
}
}Save, then start a new chat and confirm the MCP server is loaded.
Ask in chat: "List my surveys". A list means the connection works.
Check if the API token is correctly filled in, ensure the token is valid and not expired. Check token status in account settings.
Ensure JSON format is correct, pay attention to commas, quotes, and bracket matching. Use a JSON validator tool to check.
Ensure necessary scopes were selected when creating the token. For full functionality, select all relevant permissions.
Confirm the server address is correct. The MCP endpoint for your environment is: https://api.quaflo.com/api/v1/mcp
The server validates the Origin header of browser-based clients against the MCP_ALLOWED_ORIGINS allowlist. When unset, ANY request carrying an Origin header is rejected with 403. Desktop editors (Cursor/Claude Code) normally send no Origin and are unaffected; browser-based clients need the allowlist configured by an administrator.
MCP rate-limits per authenticated user (tunable via MCP_RATE_LIMIT / MCP_RATE_WINDOW), with tighter per-scope caps on writes and publishes. On 429, wait for the Retry-After response header before retrying.