> ## Documentation Index
> Fetch the complete documentation index at: https://docs.perfai.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Lovable

> Connect the Perfai Cloud MCP server to Lovable via a custom chat connector.

Lovable is a browser-based AI app builder. MCP servers are added as **chat connectors** from the Connectors dashboard, and Perfai Cloud connects as a remote streamable-http server.

<Note>
  Custom MCP servers are available on every Lovable plan. If your workspace is on **Enterprise**, an admin needs to enable **Third-party MCP clients** first under Workspace settings → Security → Privacy & security — it's on by default for Free, Pro, and Business.
</Note>

***

## Generate your Bearer token

The Bearer value Lovable needs is a PerfAI Token (id\_token which is a JWT)

<Note>
  id\_tokens are short-lived. If Lovable later reports "could not connect" after previously working, your token has likely expired — generate a fresh one with either method below and update the connector.
</Note>

<Tabs>
  <Tab title="macOS / Linux">
    ```bash theme={null}
    read -s -p "PerfAI password: " PERFAI_PASSWORD; echo
    curl -s -X POST "https://api.perfai.ai/api/v1/auth/token" \
      -H "Content-Type: application/json" \
      -d "{\"username\":\"you@example.com\",\"password\":\"$PERFAI_PASSWORD\"}" \
      | grep -o '"id_token":"[^"]*"' | cut -d'"' -f4
    ```

    `read -s` masks the password prompt so it never lands in your shell history. Copy the printed `id_token` value in full.
  </Tab>

  <Tab title="Windows (PowerShell)">
    ```powershell theme={null}
    $cred = Get-Credential -UserName "you@example.com" -Message "PerfAI password"
    $body = @{ username = $cred.UserName; password = $cred.GetNetworkCredential().Password } | ConvertTo-Json
    $resp = Invoke-RestMethod -Uri "https://api.perfai.ai/api/v1/auth/token" -Method Post -Body $body -ContentType "application/json"
    $resp.id_token
    ```

    `Get-Credential` masks the password prompt and, unlike a plain double-quoted string, won't let PowerShell mangle special characters (`$`, `` ` ``, `"`) in your password. Copy the printed value in full.
  </Tab>
</Tabs>

Copy the resulting string — you'll paste it into Lovable's connector form as the Bearer token value, exactly as-is (no further encoding).

***

## Installation

1. Open the **Connectors** dashboard in Lovable and click the **+** button (top right).
2. Select **MCP server**.
3. Fill in:
   * **Server name**: `Perfai Cloud`
   * **Connection type**: **Direct connection** (default — "Lovable static IPs" is Enterprise-only and not needed here)
   * **Server URL**: `https://mcp-server.perfai.ai/mcp`
   * **Authentication**: **Bearer token or API key**
   * **Token**: paste the `id_token` from above
4. Click **Add & authorize**.

***

## Verify the server is connected

1. Reopen the Connectors dashboard and find **Perfai Cloud** in your connector list.
2. It should show as connected with 19 tools discovered.
3. If it fails, re-check the token value for trailing whitespace, confirm **Bearer token or API key** was selected, and make sure the token hasn't expired (generate a fresh `id_token` if it has).

***

## Login

<Note>
  The prompts below run **inside Lovable's project chat**, not your terminal. The only setup step outside the chat is adding the connector above.
</Note>

In a Lovable project chat, with the connector enabled, type:

```
Login to Perfai
```

This calls `login` with no arguments. Confirm the session with:

```
What's my Perfai auth status?
```

***

## Register an app and run a scan

```
Register https://your-app.example.com with Perfai
```

```
Check the onboarding status for that app
```

```
Run a security test on the selected app
```

```
Show me the vulnerabilities it found
```

***

## Fix and verify

```
Generate an auto-fix plan for all critical and high findings
```

```
Mark vulnerability 3 as fixed
```

```
Give me the fix summary
```
