> ## Documentation Index
> Fetch the complete documentation index at: https://docs.perfai.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Replit

> Connect the Perfai Cloud MCP server to Replit Agent via a custom MCP connector.

Replit Agent is a browser-based AI coding agent. MCP servers are added as custom connectors from the **Integrations** pane, and Perfai Cloud connects as a remote streamable-http server with a custom Bearer header.

<Note>
  Replit connects MCP servers at the **account level**, not per project — a server you add once is available to Agent across every Repl you build, and Agent fetches the tool list itself.
</Note>

***

## Generate your Bearer token

The value Replit needs is a PerfAI Token (id\_token which is a JWT).

<Note>
  id\_tokens are short-lived. If Agent later reports the connector failing after previously working, your token has likely expired — generate a fresh one with either method below and update the connector.
</Note>

<Tabs>
  <Tab title="macOS / Linux">
    ```bash theme={null}
    read -s -p "PerfAI password: " PERFAI_PASSWORD; echo
    curl -s -X POST "https://api.perfai.ai/api/v1/auth/token" \
      -H "Content-Type: application/json" \
      -d "{\"username\":\"you@example.com\",\"password\":\"$PERFAI_PASSWORD\"}" \
      | grep -o '"id_token":"[^"]*"' | cut -d'"' -f4
    ```

    `read -s` masks the password prompt so it never lands in your shell history. Copy the printed `id_token` value in full.
  </Tab>

  <Tab title="Windows (PowerShell)">
    ```powershell theme={null}
    $cred = Get-Credential -UserName "you@example.com" -Message "PerfAI password"
    $body = @{ username = $cred.UserName; password = $cred.GetNetworkCredential().Password } | ConvertTo-Json
    $resp = Invoke-RestMethod -Uri "https://api.perfai.ai/api/v1/auth/token" -Method Post -Body $body -ContentType "application/json"
    $resp.id_token
    ```

    `Get-Credential` masks the password prompt and, unlike a plain double-quoted string, won't let PowerShell mangle special characters (`$`, `` ` ``, `"`) in your password. Copy the printed `id_token` value in full — it wraps across multiple terminal lines, but that's just visual wrapping, not truncation.
  </Tab>
</Tabs>

Copy the resulting string — you'll paste it into Replit's authentication field as `Bearer <id_token>`, or into a bare token field exactly as-is depending on how Replit's form is laid out.

***

## Installation

1. Open any Repl and go to the **Integrations** pane.
2. Scroll to **MCP Servers for Replit Agent** and click **Add MCP server**.
3. Paste the endpoint:
   * **URL**: `https://mcp-server.perfai.ai/mcp`
4. In the authentication section, add a header:
   * **Header name**: `Authorization`
   * **Header value**: `Bearer <id_token>`
5. Optionally test a read-only endpoint (like `auth_status`) before saving, then save.

<Warning>
  Credentials go in the authentication fields only — never in the connector's description or in Agent instructions, since those are visible in plain text.
</Warning>

***

## Verify the server is connected

1. Reopen the Integrations pane and find **perfai-cloud** under your connected MCP servers.
2. It should show as connected with 19 tools discovered.
3. If it fails, re-check the header value for trailing whitespace, and make sure the token hasn't expired (generate a fresh `id_token` if it has).

***

## Login

<Note>
  The prompts below run **inside Replit Agent's chat**, not your terminal. The only setup step outside the chat is adding the connector above.
</Note>

In Agent's chat, with the connector enabled, type:

```
Login to Perfai
```

This calls `login` with no arguments. Confirm the session with:

```
What's my Perfai auth status?
```

***

## Register an app and run a scan

```
Register https://your-app.example.com with Perfai
```

```
Check the onboarding status for that app
```

```
Run a security test on the selected app
```

```
Show me the vulnerabilities it found
```

***

## Fix and verify

```
Generate an auto-fix plan for all critical and high findings
```

```
Mark vulnerability 3 as fixed
```

```
Give me the fix summary
```
