> ## Documentation Index
> Fetch the complete documentation index at: https://docs.perfai.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Bolt

> Connect the Perfai Cloud MCP server to Bolt via a custom connector.

Bolt is a browser-based AI app builder. MCP servers are added as **Connectors** from your account settings, and Perfai Cloud connects as a remote streamable-http server.

<Note>
  Bolt's Connectors are account-level, not per-project. Once added, `perfai-cloud` is available in every Bolt project unless you leave **Auto-enable for all projects** off and enable it per project instead.
</Note>

***

## Generate your Bearer token

The value Bolt needs is a Perfai Token (id\_token which is a JWT)

<Note>
  id\_tokens are short-lived. If Bolt later reports a connector failure after previously working, your token has likely expired — generate a fresh one with either method below and update the connector.
</Note>

<Tabs>
  <Tab title="macOS / Linux">
    ```bash theme={null}
    read -s -p "PerfAI password: " PERFAI_PASSWORD; echo
    curl -s -X POST "https://api.perfai.ai/api/v1/auth/token" \
      -H "Content-Type: application/json" \
      -d "{\"username\":\"you@example.com\",\"password\":\"$PERFAI_PASSWORD\"}" \
      | grep -o '"id_token":"[^"]*"' | cut -d'"' -f4
    ```

    `read -s` masks the password prompt so it never lands in your shell history. Copy the printed `id_token` value in full.
  </Tab>

  <Tab title="Windows (PowerShell)">
    ```powershell theme={null}
    $cred = Get-Credential -UserName "you@example.com" -Message "PerfAI password"
    $body = @{ username = $cred.UserName; password = $cred.GetNetworkCredential().Password } | ConvertTo-Json
    $resp = Invoke-RestMethod -Uri "https://api.perfai.ai/api/v1/auth/token" -Method Post -Body $body -ContentType "application/json"
    $resp.id_token
    ```

    `Get-Credential` masks the password prompt and, unlike a plain double-quoted string, won't let PowerShell mangle special characters (`$`, `` ` ``, `"`) in your password. Copy the printed `id_token` value in full.
  </Tab>
</Tabs>

Copy the resulting string — you'll paste it into Bolt's connector form as the API key value, exactly as-is (no further encoding).

***

## Installation

1. From the Bolt homepage, click the **+** icon in the chatbox.
2. Click **Connectors**, then **Manage connectors** — this opens the Connectors (MCP) page in your account settings.
3. Click **Add custom connector**.
4. Fill in:
   * **Server URL**: `https://mcp-server.perfai.ai/mcp`
   * **Transport**: Streamable HTTP
   * **Authentication**: **API Key**
   * **API Key**: paste the `id_token` from above
5. Save. Decide whether to auto-enable this connector for all projects or turn it on per project.

***

## Verify the server is connected

1. Open **Manage connectors** again and find **perfai-cloud** in your connector list.
2. It should show as connected with 19 tools discovered.
3. If it fails, re-check the API Key value for trailing whitespace, and make sure the token hasn't expired (generate a fresh `id_token` if it has).

***

## Login

<Note>
  The prompts below run **inside Bolt's chat**, not your terminal. The only setup step outside the chat is adding the connector above.
</Note>

In a Bolt project chat, with the connector enabled, type:

```
Login to Perfai
```

This calls `login` with no arguments. Confirm the session with:

```
What's my Perfai auth status?
```

***

## Register an app and run a scan

```
Register https://your-app.example.com with Perfai
```

```
Check the onboarding status for that app
```

```
Run a security test on the selected app
```

```
Show me the vulnerabilities it found
```

***

## Fix and verify

```
Generate an auto-fix plan for all critical and high findings
```

```
Mark vulnerability 3 as fixed
```

```
Give me the fix summary
```
