Form Builder MCP returns 403 in 2025.1.2 PE -- missing configuration?

27 views
Skip to first unread message

Aaron Spike

unread,
Sep 22, 2026, 5:14:08 PMSep 22
to Orbeon Forms

I’m trying to enable the Form Builder MCP server in Orbeon Forms 2025.1.2 PE (build 202606221236), running on Tomcat behind Apache with header-based authentication.

I have configured:

<property as="xs:boolean" name="oxf.fb.mcp.enable" value="true"/>
<property as="xs:string" name="oxf.fb.mcp.token.password" value="..."/>
<property as="xs:integer" name="oxf.fb.mcp.token.validity" value="525600"/>

However, an MCP initialize POST to /forms/fr/mcp/builder, with an Authorization: Bearer header, returns HTTP 403 with an empty body.

Apache exempts this endpoint from our login redirect and permits my workstation’s IP. The logs confirm the request reaches Orbeon, which logs:

PageFlowControllerProcessor - HTTP status code 403 {
 controller: "oxf:/apps/fr/page-flow.xml",
 method: "POST",
 path: "/fr/mcp/builder",
 status-code: "403"
}

The MCP route in the bundled apps/fr/page-flow.xml is:

<service
 path="/fr/mcp/builder"
 methods="POST DELETE"
 class="org.orbeon.oxf.fb.mcp.FormBuilderMcpRoute"
/>

Could the absence of public-methods="POST DELETE" cause the page-flow controller to reject external requests before the MCP handler validates the bearer token?

Is this expected behavior requiring additional authorization configuration, or should the bundled route include that attribute? Is there anything else needed for MCP when using header-based authentication behind a reverse proxy?

Thanks!

Aaron Spike


This electronic communication, including any attached documents, may contain confidential and/or legally privileged information that is intended only for use by the recipient(s) named above. If you have received this communication in error, please notify the sender immediately and delete the communication and any attachments. Views expressed by the author do not necessarily represent those of Martin Luther College.

Erik Bruchez

unread,
Sep 23, 2026, 3:15:54 PMSep 23
to orb...@googlegroups.com
Aaron,

Try also adding:

    <!-- Enable MCP token -->
    <property
        as="xs:boolean"
        name="oxf.fb.mcp.token.enable"
        value="true"/>

In addition, if that doesn't work, try adding to your web.xml's  <web-resource-collection> without any constraints:

    <url-pattern>/fr/mcp/builder</url-pattern>

The idea is to prevent that path from requiring authentication at the web.xml level.

Regarding the public-methods attribute, you raise a good point. If the above doesn't work, try setting this:

    <property
        as="xs:string"
        processor-name="oxf:page-flow"
        name="service-public-methods"
        value="GET HEAD POST PUT DELETE"/>

Does any of the above solve the problem?

-Erik

--
You received this message because you are subscribed to the Google Groups "Orbeon Forms" group.
To unsubscribe from this group and stop receiving emails from it, send an email to orbeon+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/orbeon/092c57fd-7a90-453b-9859-07f96c467b21n%40googlegroups.com.

Aaron Spike

unread,
Sep 24, 2026, 4:02:08 PMSep 24
to Orbeon Forms
Thanks for the suggestions. I tried each in turn and the MCP only started working after setting the service-public-methods property. Is the global service-public-methods property the recommended configuration for enabling MCP? Does allowing these methods globally have any security or behavioral implications I should consider? Or perhaps this is just a test?

Additionally after the MCP stopped returning 403, I tried form_new for a blank form returned a session ID, but list_available_toolbox_form_controls returned {"controls":[]}. Calling form_get_structure with the same session ID then failed with java.util.NoSuchElementException: None.get. I closed the session without saving.

This test did not involve importing an existing form. Form Builder works in the browser, and I was previously able to create a form using its browser-based WebMCP tools. Does the behavior above suggest another configuration setting is needed for the standalone MCP server?

Aaron Spike

ebruchez

unread,
Sep 25, 2026, 2:47:38 PMSep 25
to Orbeon Forms
Aaron,

Thanks for the suggestions. I tried each in turn and the MCP only started working after setting the service-public-methods property. Is the global service-public-methods property the recommended configuration for enabling MCP? Does allowing these methods globally have any security or behavioral implications I should consider? Or perhaps this is just a test?

Good to hear. I entered and fixed issue #7898. That was an oversight. Security is handled by token, so incoming requests must go directly to the MCP endpoint without other authorization checks (including web.xml or page flow).
 
Additionally after the MCP stopped returning 403, I tried form_new for a blank form returned a session ID, but list_available_toolbox_form_controls returned {"controls":[]}. Calling form_get_structure with the same session ID then failed with java.util.NoSuchElementException: None.get. I closed the session without saving.

This test did not involve importing an existing form. Form Builder works in the browser, and I was previously able to create a form using its browser-based WebMCP tools. Does the behavior above suggest another configuration setting is needed for the standalone MCP server?

No, it should "just work", and the fact that you got `None.get` seems to indicate. Some other problem. Can you share a stack trace?

-Erik
Reply all
Reply to author
Forward
0 new messages