Dealership profile
Public business profile, verified website, hours, and location.
AutoFire automotive MCP
Give approved AI clients read-only access to one dealership’s inventory and workflows. AutoFire never gives the client a database password or service-role key.
[mcp_servers.autofire]
url = "https://mcp.goautofire.com/mcp"
bearer_token_env_var = "AUTOFIRE_MCP_TOKEN"
required = true
tool_timeout_sec = 30Available tools
Search inventory, review lead statuses, check test-drive records, and read recent dealership reports from an MCP client. Each key exposes only the tools and data permissions selected by a dealership owner or admin.
Want to see the day-to-day dealership workflows first? Read how dealership owners use AutoFire MCP.
Public business profile, verified website, hours, and location.
Search up to 50 dealership-owned vehicles per request without exposing VINs.
Review lead statuses and linked vehicles without contact details by default.
Return a single lead’s contact data only with the explicit leads:pii scope.
Read scheduling workflow and vehicle context without customer identity or notes.
Retrieve recent dealership reports without customer-level records.
More MCP features are rolling out soon. Have something specific in mind? Contact us.
AutoFire exposes focused operations instead of a general SQL or table API. Queries are parameterized, paginated, size-limited, and filtered to the dealership encoded in the credential.
Access controls
Personal access keys work with headless and local clients. AutoFire will advertise the OAuth 2.1 resource-server option only after the production Supabase OAuth and asymmetric signing rollout is verified.
Use the same HTTPS endpoint with a separate credential per client. Each guide includes client-specific configuration and verification steps.
No. Every key is permanently bound to one dealership. Create a separate key for each dealership connection.
No. The dashboard shows it once, then stores only an HMAC-SHA-256 digest.
Not in the initial release. Every published tool is read-only and annotated as non-destructive.
Owners and admins choose 30, 60, or 90 days. Keys cannot be extended and can be revoked immediately.
Start with a 30-day, read-only key and only the scopes your client needs.