API overview
Secret-key management uses Authorization: Bearer against the RFQ API host. Author tokens are minted at POST /api/v1/author-tokens. MCP tools: list_rfq_apps, get_rfq_app, create_rfq_app, update_rfq_draft, publish_rfq_app, get_rfq_published_config, get_rfq_install_snippet, ensure_rfq_test_publishable, list_rfq_capabilities.
The live Hosted host is https://rfq.bootstrapware.co. Prefer OAuth Connect from RFQ → Keys. Do not invent live or secret keys.