Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

be.vibedeploy/vibedeploy

REMOTE · MCP.VIBEDEPLOY.BE · SCANNED AUG 3

Deploy and host AI-built websites on EU infrastructure, straight from your AI agent.

+10 this week 78 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security94
Transport & Reachability100
Schema Quality & AI Usability59
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 7027 tokens (~180/item across 39 items; 39 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage92
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 73% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · mcp.vibedeploy.be

# add to Claude Code
claude mcp add --transport http be-vibedeploy-vibedeploy https://mcp.vibedeploy.be/mcp
# ~/.codex/config.toml
[mcp_servers.be-vibedeploy-vibedeploy]
url = "https://mcp.vibedeploy.be/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "be-vibedeploy-vibedeploy": {
      "type": "remote",
      "url": "https://mcp.vibedeploy.be/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add be-vibedeploy-vibedeploy --url https://mcp.vibedeploy.be/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  be-vibedeploy-vibedeploy:
    url: "https://mcp.vibedeploy.be/mcp"
// mcp.json
{
  "mcpServers": {
    "be-vibedeploy-vibedeploy": {
      "type": "http",
      "url": "https://mcp.vibedeploy.be/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +6
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 68

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://mcp.vibedeploy.be/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.vibedeploy.be CN=YR2,O=Let's Encrypt,C=US 25 Jun 2026 23 Sept 2026 RSA 2048 SHA256-RSA 552047ab707461cca41304bc7189c9ff19a
SANs: mcp.vibedeploy.be
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f
DNSSEC insecure

Validation of mcp.vibedeploy.be. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
be. present 45588 13 Verified
vibedeploy.be. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer realm="vibedeploy-mcp", error="invalid_token", error_description="Send Authorization: Bearer <token> using either an OAuth access token or a vd_dt_... deploy token.", resource_metadata="https://mcp.vibedeploy.be/.well-known/oauth-protected-resource/mcp"

Bearer realm="vibedeploy-mcp", error="invalid_token", error_description="Send Authorization: Bearer <token> using either an OAuth access token or a vd_dt_... deploy token.", resource_metadata="https://mcp.vibedeploy.be/.well-known/oauth-protected-resource/mcp"
Header Value
strict-transport-security max-age=31536000; includeSubDomains
content-security-policy default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy no-referrer

Protected resource metadata

Document https://mcp.vibedeploy.be/.well-known/oauth-protected-resource/mcp
Retrieved Yes
Resource https://mcp.vibedeploy.be/mcp
Authorisation server https://mcp.vibedeploy.be/
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.vibedeploy.be/mcp Verified 200
http (plaintext) http://mcp.vibedeploy.be/mcp HTTPS enforced 301 https://mcp.vibedeploy.be/mcp
MCP tools — 39 exposed · ~7,027 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
abort_deploy ~54

Discard a staging session and its scratch dir. Live site is untouched. Returns immediately; cleanup is best-effort and the sweeper will retry if it fails.

NameTypeReqDescription
deployIdstringyesSession id to abort.
NameTypeReqDescription
deployIdstringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
statusstringyes

No examples provided.

add_custom_domain ~180

Start attaching a user-owned domain to an existing site. Returns a TXT record the user must add at their DNS provider. Idempotent: calling twice with the same (siteName, domain) returns the existing record instead of creating a duplicate. After the TXT is published (typically within minutes; up to 24h), call verify_custom_domain with the returned recordId. The site itself must already exist on a platform subdomain (e.g. {name}.vibedeploy.be or {name}.vibedeploy.eu). Call deploy_site first if it doesn't.

NameTypeReqDescription
domainstringyesThe user-owned hostname to attach (e.g. 'tester.subsite.site'). Must be a valid FQDN.
siteNamestringyesThe VibeDeploy site name to attach the domain to (e.g. 'tester').
NameTypeReqDescription
alreadyAttachedbooleanTrue when the call returned an existing record instead of creating one (idempotent path).
dnsAutoConfiguredbooleanTrue when the verification TXT was written automatically because the domain is managed through VibeDeploy's Gandi account. The caller can call verify_custom_domain immediately without waiting for the…
domainstringyes
instructionsstringyesPlain-English instructions for the user.
nextCallobjectStructured hint for the next tool call (e.g. verify_custom_domain). Lets an agent chain without parsing instructions.
recordIdstringyesPass this to verify_custom_domain after the TXT is in place.
request_idstringServer-assigned request correlation id. Quote it when contacting support.
statusstringyespending_verification on first attach; verified if the domain was already set up earlier.
verificationRecordobjectOnly present when status is pending_verification.

No examples provided.

add_file_chunk ~670

Stream a single file across multiple calls when its content exceeds the per-MCP-call output budget. LAST RESORT — try these first: (1) add_files with encoding:'gzip+base64' fits ~250 KB of text source in ONE call (gzip locally, base64, send — no chunking, no ordering hazards); (2) begin_deploy's uploadUrl takes a 100 MB tarball in one HTTP POST if your sandbox can reach mcp.vibedeploy.be; (3) deploy_from_url if the files are fetchable from a public URL. Only chunk when none of those work. When you DO chunk, gzip+base64 each chunk too — it quadruples the source bytes per chunk. Mark the first chunk with isFirst=true (truncates + mkdir) and the last with isLast=true (returns assembled size). Send chunks for the same path serially — concurrent chunks interleave and corrupt the file.

NameTypeReqDescription
contentstringyesThis chunk's bytes. Either raw UTF-8 (default) or base64-encoded — set encoding accordingly. PRACTICAL CHUNK SIZE: bounded by your LLM client's tool-output token budget, NOT by VibeDeploy's server. E…
deployIdstringyesSession id returned by begin_deploy.
encodingstringutf8 (default), base64 (binary files), or gzip+base64 (compress this chunk's bytes locally first; server gunzips before append). Encoding is per-chunk — you can mix across chunks of the same file (e.…
expectedByteOffsetintegerOptional alignment check. The byte offset where THIS chunk should start in the assembled file: 0 for isFirst, otherwise the sum of all prior chunks' decoded bytes for this path. If the server's actua…
isFirstbooleanyesTrue on the FIRST chunk of a file. Truncates any existing scratch entry at this path and creates parent directories. Subsequent chunks must set false.
isLastbooleanyesTrue on the FINAL chunk. Triggers an assembled-size stat and refreshes session file count. Mid-stream chunks set false.
pathstringyesTarget path inside the site root, e.g. 'portaal-admin.html'. Same path validation as add_files.
NameTypeReqDescription
bytesWrittennumberyesDecoded bytes written by THIS chunk.
deployIdstringyes
fileSizenumberAssembled file size on the pod after this chunk. Returned only when isLast=true so the caller can verify the concat succeeded.
isLastbooleanyes
pathstringyes
remainingBudgetnumberyesBytes still available before hitting the 500 MB cap.
request_idstringServer-assigned request correlation id. Quote it when contacting support.
totalBytesnumberyesSession-wide cumulative bytes across all add_files / add_file_chunk calls.
totalFilesnumberSession-wide file count after this chunk. Returned only when isLast=true.

No examples provided.

add_files ~308

Append files to an open staging session. Call as many times as needed; commit_deploy applies them all at once. Validates path/extension/encoding on every call so a bad file fails fast. Same 500 MB cap as single-call deploys, but cumulative across the session. LARGE TEXT FILES: a file that looks too big to inline (100-250 KB of HTML/CSS/JS) usually still fits in ONE call — gzip it locally, base64 the result, send with encoding:'gzip+base64' (text compresses 3-5×, so ~250 KB of source ≈ ~70 KB on the wire). Prefer that over add_file_chunk: one call, no ordering hazards. Only chunk when a single file exceeds ~250 KB of source even after gzip, or when you have no way to gzip locally. If your environment can run shell but can't reach this host, gzip+base64 via add_files is the fastest path; if it CAN reach this host, begin_deploy's uploadUrl (tarball POST, 100 MB) beats everything.

NameTypeReqDescription
deployIdstringyesSession id returned by begin_deploy.
filesyesFiles to append to the staging scratch dir. Same wire shape as deploy_site/update_site — array form supports binary via encoding:'base64'; map form is utf8-only. Re-adding a path overwrites the previ…
NameTypeReqDescription
deployIdstringyes
filesAddednumberyesFiles written by this call.
remainingBudgetnumberyesBytes still available before hitting the 500 MB cap.
request_idstringServer-assigned request correlation id. Quote it when contacting support.
totalBytesnumberyesTotal bytes staged so far across all add_files calls.
totalFilesnumberyesTotal files now in the scratch dir.
warningsarray

No examples provided.

apply_edits ~154

Apply find/replace edits across MANY files in one tool call. Batch sibling of update_file_content. Per-file edit semantics identical (count: 1 default, -1 = all, positive int asserts exact count). Whole call is atomic across files: validation runs first, writes only proceed if every edit's count check passes.

NameTypeReqDescription
filesarrayyesFiles + edits to apply. Up to 25 files / 200 total edits per call. All-or-nothing: if any edit's match count differs from its expected count, NOTHING is written.
namestringyes
targetstringTree to edit, dist (default) or source. Same tree applies to every file in this call.
NameTypeReqDescription
filesarrayyes
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
targetstringyes
totalEditsnumberyes

No examples provided.

begin_deploy ~183

Opens a staging session for a multi-call deploy. Use when the site is too large to fit in a single deploy_site/update_site call. Pair with add_files (one or more times) OR a single tarball upload to the returned uploadUrl, then commit_deploy. Active session limit per token: 5. Default TTL: 1 hour.

NameTypeReqDescription
modestringyesHow commit_deploy will apply the staged files. 'replace' wipes the live site and atomic-renames the staged set into place. 'patch' layers staged files on top of the live site (kept files = live + sta…
namestringyesSite name to deploy to. Must already exist; multi-call sessions don't auto-create sites — use deploy_site for that, or call this against an existing site.
NameTypeReqDescription
deployIdstringyesPass this id to add_files / commit_deploy / abort_deploy / list_deploys.
expiresAtstringyesISO timestamp. The session will be auto-expired and the scratch dir cleaned at this time.
modestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
siteNamestringyes
statusstringyes
uploadTokenstringyesSame single-purpose token already embedded in uploadUrl, exposed separately if you'd rather pass it via Authorization: Bearer header than as a query parameter. Valid only for POST /upload/<this deplo…
uploadUrlstringyesPOST a tar(.gz) archive to this URL to stage many files in one HTTP call — bypasses the per-tool-call output budget that bounds add_files. The URL already embeds a single-purpose upload_token narrowl…

No examples provided.

build_and_deploy ~297

Run a build inside a hardened one-shot pod against the site's editable source tree (write source first via write_source_files / list_source_files autoPromote), then atomically swap the build output into the live dist. Reuses the same build pod the GitProject git-deploy flow uses, so the same isolation guarantees apply: no SA token, no DB/Vault reach, NetworkPolicy-restricted egress. The first run writes the chosen buildCommand/outputDir into Site.sourceManifest; subsequent calls can omit those fields.

NameTypeReqDescription
buildCommandstringOverride for the build script's `npm run build` step (e.g. 'npm run build:prod' or 'pnpm vite build'). If omitted, uses the manifest stored on the site, then falls back to 'npm run build'.
namestring
outputDirstringOverride for which directory to ship as the new dist. If omitted, uses the manifest, then auto-detects (dist > build > out > public).
rootPathstringSubdirectory inside the source tree where package.json lives. Empty string = source root. Useful for monorepos.
saveManifestbooleanIf true (default), persists the merged manifest back onto the site so future builds default to these settings. Set false to do a one-off build without changing the saved manifest.
siteIdstring
NameTypeReqDescription
buildLogstringyesCombined orchestrator + builder log; truncated to ~32 KB to fit MCP responses.
filesDeployednumberyes
manifestobjectyes
namestringyes
outputDirstringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
totalBytesnumberyes

No examples provided.

check_domain_availability ~184

Check whether a domain can be registered and get an INDICATIVE retail price. IMPORTANT: this is a read-only lookup — it does NOT buy, register, reserve, or pay for any domain, and it changes nothing. The returned price is GROSS (includes 21% VAT) and indicative only. Set alternatives:true to also check the same name across other common TLDs (be, com, net, eu, nl, io, dev, app). Requires a valid team token but is not tied to a specific site.

NameTypeReqDescription
alternativesbooleanWhen true, also check the same second-level name across a canonical TLD set (be, com, net, eu, nl, io, dev, app) and return each one's availability + indicative price.
domainstringyesThe domain to check, e.g. "example.com".
NameTypeReqDescription
alternativesarrayPresent only when alternatives:true was requested.
availablebooleanyesWhether the domain can be registered right now.
currencystringyesISO currency code for the price (e.g. EUR).
domainstringyes
notestringyesReminder that this is an indicative gross price and not a purchase.
priceCentsyesGross (incl. 21% VAT) indicative retail price in cents, or null if unavailable / no price is published.
request_idstringServer-assigned request correlation id. Quote it when contacting support.

No examples provided.

commit_deploy ~257

Atomically apply a staging session's files to the live site. Runs preflight + secret/malware scan against the complete staged set; on failure the session stays open and can be re-attempted or aborted. For replace-mode against a site with existing files, requires confirm:"I-want-to-replace-all-files".

NameTypeReqDescription
confirmstringRequired only for replace-mode commits against a site that already has files. Pass exactly "I-want-to-replace-all-files" to acknowledge that the live files will be deleted and replaced with the stage…
deletearrayPatch-mode only: site-relative paths to remove from the live site as part of this commit. Useful for renames (write new path via add_files, delete old path here).
deployIdstringyesSession id returned by begin_deploy.
dryRunbooleanIf true, preview what commit would do without touching the live site or scratch dir. Returns the diff (filesDeployed, deletedFiles) plus would-be confirmation gate / preflight outcomes. Skips the sec…
NameTypeReqDescription
deletedFilesarrayyes
deployIdstringyes
dryRunbooleanTrue if this was a dry-run; nothing was committed.
filesDeployednumberyes
modestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
urlstringyes
warningsarrayyes

No examples provided.

create_snapshot ~100

Take a point-in-time Longhorn snapshot of a site's served files. This is an additive backup — it does not change anything served. It records a manual-snapshot history entry and runs retention cleanup. Viewers cannot create snapshots. Returns NO_VOLUME if the site has no volume yet (it has never been deployed).

NameTypeReqDescription
labelstringOptional human-readable label for this backup.
namestring
siteIdstring
NameTypeReqDescription
createdbooleanyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
snapshotNamestringyesThe name of the snapshot that was created.

No examples provided.

delete_site ~132

Soft-delete a site. confirm=true is required. The site moves to status 'deleted' immediately (its hostname is freed and it stops serving), and is fully purged after the team's recovery window by a sweeper. Use this for the normal 'remove this from my dashboard' flow. The response field 'accepted' is true when the soft-delete is recorded; the response also includes 'purgesAt' so you can tell the user when recovery becomes impossible.

NameTypeReqDescription
confirmbooleanyesMust be exactly true to actually delete the site.
namestring
siteIdstring
NameTypeReqDescription
acceptedbooleanyes
namestringyes
purgesAtstringyesISO timestamp when the soft-delete becomes a hard purge (~7 days from now).
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
statusstringyes

No examples provided.

delete_source_file ~52

Remove one file from the site's editable source tree. The served dist is unchanged.

NameTypeReqDescription
namestring
pathstringyesSource-relative path to delete.
siteIdstring
NameTypeReqDescription
existedbooleanyesTrue if the file was present and removed; false if it didn't exist (no-op).
namestringyes
pathstringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes

No examples provided.

deploy_from_url ~321

Publish a website to a live URL from a public archive link. Point this at a tar(.gz) archive on github / gist / S3 and the server fetches and deploys it, no upload from your side. Server-side fetch of a tar(.gz) archive from a public HTTPS URL, then deploy its contents. Sidesteps the case where your code-execution sandbox can reach github / gist / S3 etc. but not mcp.vibedeploy.be's upload endpoint. Equivalent to begin_deploy → POST uploadUrl → commit_deploy in one call. Hostname allowlist enforced; see the archiveUrl description.

NameTypeReqDescription
archiveUrlstringyesPublic HTTPS URL of a tar(.gz) archive. The server fetches it (max 100 MB, 60s timeout), parses the tarball, and deploys its files. Allowed hosts: github.com / raw.githubusercontent.com / gist.github…
modestringyesHow the archive's files apply: replace wipes the live dist; patch merges them in.
namestringyesSite name to deploy to.
NameTypeReqDescription
archiveUrlstringyes
bytesFetchednumberyes
filesDeployednumberyes
modestringyes
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
urlstringyes

No examples provided.

deploy_site ~502

Publish a website to a live URL. Deploy a static site or single-page app you built (with AI or by hand) to your platform subdomain (e.g. {name}.vibedeploy.be or {name}.vibedeploy.eu) with automatic SSL, and optionally a custom domain. The fastest way to get a localhost project or an AI-generated site online. DESTRUCTIVE on existing sites: replaces every file on the named site with the supplied set. Files not in this call are deleted. For a new site, creates and provisions it. For an existing site, requires `confirm: "I-want-to-replace-all-files"` to proceed; without confirm the call is rejected before anything is touched. Use update_site (default mode:'patch') if you want to add or change individual files without removing the rest. Use dryRun:true to preview the diff. LARGE FILES: don't split a big text file across a placeholder deploy + chunked follow-ups — a 100-250 KB HTML/CSS/JS file fits in THIS call when sent with encoding:'gzip+base64' (gzip locally, base64 the result; text compresses 3-5×). The site is published at your platform subdomain (e.g. {name}.vibedeploy.be or {name}.vibedeploy.eu). After deploy, call add_custom_domain to also serve at a user-owned hostname.

NameTypeReqDescription
confirmstringRequired when the named site already exists. Pass exactly "I-want-to-replace-all-files" to acknowledge that every existing file will be deleted and replaced with this new fileset. Omit on first deplo…
dryRunbooleanIf true, validate input + introspect what would change but don't write or delete. Returns the same shape with `dryRun: true` and `deletedFiles` showing what *would* be removed. Strongly recommended b…
filesyesEither an array of {path, content, encoding?} entries OR a path->content map. Total payload <= 500 MB.
namestringyesSite subdomain. Lowercase, 3-63 chars, alphanumeric + hyphens. Must not start or end with a hyphen.
NameTypeReqDescription
createdbooleanyesTrue if the site was created by this call.
deletedFilesarrayyesFiles that existed before this call and were removed by it. Empty for brand-new sites.
dryRunbooleanTrue if this was a dry-run; nothing was written or deleted.
filesDeployednumberyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
urlstringyesLive URL of the deployed site.
warningsarraySurfaced issues that did not block the deploy. Common types: DOTFILE_PUBLIC (a .well-known/* file is served publicly, confirm intent), or secret-scanner findings (AWS Access Key, Stripe Key, JWT Toke…

No examples provided.

get_account ~72

Return the team's plan, its limits, and current usage. Use this BEFORE deploy_site or add_custom_domain to know whether a deploy would trip a plan limit, instead of provoking PLAN_LIMIT_EXCEEDED. Also returns the per-token MCP rate-limit ceiling (live remaining is in X-RateLimit-Remaining response header).

Input schema present but exposes no named parameters.

NameTypeReqDescription
limitsobjectyes
planstringyesEffective plan name: Free, Freemium, Maker, Studio, Business, Ultimate.
planExpiresAtyesISO timestamp when the plan downgrades to Free, or null if no expiry set.
request_idstringServer-assigned request correlation id. Quote it when contacting support.
teamobjectyes
usageobjectyes

No examples provided.

get_forms_config ~182

Read the form-to-email relay config of a site, plus the resolved delivery mode, the active From address, and (for a custom sender domain) the DNS records to publish and their verification status. Submissions: POST JSON to the returned `endpoint` with Content-Type: application/json (UTF-8). Flat object of form fields (strings/numbers/booleans; checkbox groups may be arrays of strings, joined with ', '). Max 30 fields, 5000 chars/field, 20000 total. Response: {success:true,data:{ok:true}} or {success:false,error:{code,message}}. Rate limit: 10 submits per IP per 10 minutes. Include a hidden honeypot input (default "_gotcha") and leave it empty.

NameTypeReqDescription
siteNamestringyesThe site whose forms-relay config to read.
NameTypeReqDescription
activeSenderstringyesThe From that will actually be used right now.
deliverystringyesplatform | verified-domain | verified-domain-pending | custom-relay.
enabledbooleanyes
endpointstringyesURL the site's form should POST to.
formsConfigyesStored config (smtpRelay.password redacted to hasPassword).
notesarrayyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
senderDomainobjectDNS records to publish + verification status (verified-domain path).
siteNamestringyes

No examples provided.

get_site ~39

Return name, url, plan, last deploy time, and recent deploy history.

NameTypeReqDescription
namestring
siteIdstring
NameTypeReqDescription
bandwidthobjectyes
filePathsarraySite-relative paths of every file currently on the pod (same scope as `files`). Lets a caller see what's there before deciding which paths to patch or delete, without having to download the site. Omi…
filesnumberyesNumber of files currently served by the site (live count from the pod, excluding lost+found and _staging). After update_site(mode:'patch'), this may be larger than the most recent deploy's fileCount…
historyarrayyes
lastDeployAtyes
namestringyes
planstringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
statusstringyesLifecycle state. Sites are usable only in 'active'. 'deleted' is the soft-delete recovery bucket (returned until the team's restore window expires and the sweeper purges the row). 'deleting' is the t…
urlstringyes

No examples provided.

get_site_analytics ~120

Return a privacy-safe traffic summary for a site over the last `period` days (default 7): total page views, distinct-visitor count, top pages, daily counts, device/browser breakdowns, and Web Vitals averages. Never exposes raw visitor IPs or user-agents.

NameTypeReqDescription
namestringSite name. Provide this or siteId.
periodintegerNumber of days to aggregate over (1-90). Defaults to 7.
siteIdstringSite id. Provide this or name.
NameTypeReqDescription
browsersarrayyes
dailyCountsarrayyesPage views per day.
devicesarrayyes
pageViewsnumberyesTotal page views in the window.
request_idstringServer-assigned request correlation id. Quote it when contacting support.
topPagesarrayyesUp to 10 most-viewed paths, descending.
uniqueVisitorsnumberyesDistinct-visitor COUNT (by IP). Raw IPs are never returned.
webVitalsobjectyes

No examples provided.

list_custom_domains ~51

Return all custom domains attached to a site. Each entry has a recordId you can pass to verify_custom_domain or remove_custom_domain.

NameTypeReqDescription
siteNamestringyesThe site whose custom domains to list.
NameTypeReqDescription
domainsarrayyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteNamestringyes

No examples provided.

list_deploys ~70

Return staging sessions for the team this token belongs to. Defaults to currently-active ones (open + committing). Up to 50 rows.

NameTypeReqDescription
statusstringFilter by status. Default lists 'open' and 'committing' (the actionable ones). Pass an explicit status to inspect history.
NameTypeReqDescription
request_idstringServer-assigned request correlation id. Quote it when contacting support.
sessionsarrayyes

No examples provided.

list_dns_records ~112

Read the DNS records VibeDeploy tracks for a site (the records it created/manages on your behalf), oldest first. Returns each record's host, type, and value. Any team member, including viewers, can read DNS records. This tool is read-only and does NOT create, change, or delete any DNS record.

NameTypeReqDescription
namestringSite name to look up DNS records for.
siteIdstringSite id to look up DNS records for. Provide name or siteId.
NameTypeReqDescription
namestringyes
recordsarrayyesDNS records VibeDeploy tracks for this site, oldest first. Read-only — DNS changes are not made through this tool.
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes

No examples provided.

list_file_hashes ~116

Return SHA-256 + size for every file currently served. Use BEFORE re-deploying to skip files whose content hasn't changed: hash your local files, diff against this list, and only ship the differences via update_site mode:'patch' or begin_deploy → add_files. For SPAs with content-hashed bundle names this typically reduces a full-site redeploy to a handful of files.

NameTypeReqDescription
namestringSite name or custom domain. Same lookup rules as get_site.
siteIdstring
NameTypeReqDescription
filesarrayyes
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
totalBytesnumberyes
totalFilesnumberyes

No examples provided.

list_history ~82

Return the most recent 50 deploy and snapshot history entries for a site, newest first. Includes the source (how it was triggered), an optional label, the associated Longhorn snapshot name (if any), the file count, and the number of secrets detected. Any team member can read history.

NameTypeReqDescription
namestring
siteIdstring
NameTypeReqDescription
entriesarrayyesMost recent 50 deploy/snapshot history entries, newest first.
request_idstringServer-assigned request correlation id. Quote it when contacting support.

No examples provided.

list_sites ~78

List sites for the team this connection belongs to.

NameTypeReqDescription
includeDeletedbooleanIf true, include soft-deleted sites still in their plan-specific recovery window (status: 'deleted'). Defaults to false: deleted sites can't accept deploys, so an agent rarely wants them in a working…
NameTypeReqDescription
request_idstringServer-assigned request correlation id. Quote it when contacting support.
sitesarrayyes

No examples provided.

list_snapshots ~71

List the Longhorn volume snapshots for a site. Snapshots are point-in-time backups of the site's served files. Any team member can list snapshots. Returns NO_VOLUME if the site has no volume yet (it has never been deployed).

NameTypeReqDescription
namestring
siteIdstring
NameTypeReqDescription
request_idstringServer-assigned request correlation id. Quote it when contacting support.
snapshotsarrayyesLonghorn snapshot objects for the site's volume (name, created timestamp, size, etc.).

No examples provided.

list_source_files ~228

Return SHA-256 + size for every file in the site's editable source tree (the platform's copy of the pre-build code, not the served dist). Use BEFORE editing so you know which paths exist and which haven't changed since the last build. autoPromote:true will mirror the served dist into source for static-only sites whose source tree is empty (does nothing if the dist looks built).

NameTypeReqDescription
autoPromotebooleanIf true and the site has no source tree yet but its dist looks static, copy dist → source on the fly. Default: false.
forcePromotebooleanIf true, mirror dist → source EVEN when dist looks built (e.g. minified Vite output). Use when the original source isn't recoverable and you're willing to edit the build artefact directly. Sets manif…
namestring
siteIdstring
NameTypeReqDescription
autoPromotedbooleanSet to true when this call ran the auto-promote (dist → source) before listing. Lets the caller learn the source tree was just synthesised from the served dist.
filesarrayyes
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
totalBytesnumberyes
totalFilesnumberyes

No examples provided.

read_file ~215

Return the bytes of one file currently served by the site. Use this to inspect or edit existing content (call read_file → modify → update_site mode:'patch') so a new chat can iterate on a site without re-uploading. Files larger than 5242880 bytes can't be read in one call. Use list of paths from get_site.filePaths to discover what's available.

NameTypeReqDescription
maxBytesintegerPer-file size cap. Default 1048576, hard max 5242880. If the file is larger, the call fails with FILE_TOO_LARGE rather than returning truncated bytes — splitting source mid-token would corrupt downst…
namestringSite name (subdomain) or custom domain. Same lookup rules as get_site.
pathstringyesSite-relative path of the file to read (e.g. 'index.html', 'assets/main.css'). No leading slash, no '..'.
siteIdstringAlternative to name. One of name|siteId is required.
NameTypeReqDescription
contentstringyes
encodingstringyesHow to interpret `content`. utf8 means the file is text and `content` is the raw text. base64 means the file is binary (image/font/etc.) and `content` is base64 — decode before use.
namestringyes
pathstringyesEchoes the input path, normalized (leading slash stripped, backslashes converted).
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
sizenumberyesSize in bytes of the file on the pod.

No examples provided.

read_files ~140

Batched version of read_file. Pass up to 50 paths; each is fetched independently with the same per-file rules as read_file. The whole batch is capped at 8388608 bytes total — once that's exhausted, remaining paths fail with BATCH_BUDGET_EXCEEDED so the agent can re-request them in another call.

NameTypeReqDescription
maxBytesPerFileintegerPer-file cap. Default 1048576, hard max 5242880.
namestring
pathsarrayyesSite-relative paths to read (1..50). Order is preserved in the response.
siteIdstring
NameTypeReqDescription
budgetExceededAtyesIndex of the first path that was skipped due to the cumulative byte budget, or null if everything fit.
filesarrayyesOne entry per requested path, in the same order. Each entry is independent: a missing file or oversized file fails its own entry but does not abort the whole batch. If the cumulative byte budget is e…
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
totalBytesnumberyesSum of bytes returned across successful entries.

No examples provided.

read_source_file ~128

Return the bytes of one source file (the platform's editable copy of the pre-build code), letting an AI in any future chat fetch and edit content without needing the original local files. Use list_source_files first to discover paths. For the served dist, use read_file instead.

NameTypeReqDescription
maxBytesintegerPer-file size cap. Default 1048576, hard max 5242880.
namestring
pathstringyesSite-relative path inside the source tree, e.g. 'src/App.tsx'.
siteIdstring
NameTypeReqDescription
contentstringyes
encodingstringyes
namestringyes
pathstringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
sizenumberyes

No examples provided.

read_source_files ~98

Batched read across the editable source tree (up to 50 paths). Each entry is independent: a missing/oversized file fails its own slot but doesn't abort the batch. Cumulative cap 8388608 bytes; remainder fails with BATCH_BUDGET_EXCEEDED.

NameTypeReqDescription
maxBytesPerFileinteger
namestring
pathsarrayyes
siteIdstring
NameTypeReqDescription
budgetExceededAtyes
filesarrayyes
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
totalBytesnumberyes

No examples provided.

rehost_images ~145

Download the external images a site references (e.g. from the old site it was rebuilt from), store them on this VibeDeploy site under assets/img/, and rewrite the HTML <img> references to local paths so the site no longer depends on the original. Call this once AFTER deploying a site rebuilt with the Website Converter. Auto-detects the external image URLs from the site's own HTML; downloads are SSRF-guarded, size/count/time capped, and applied atomically (patch mode). Images already hosted on vibedeploy.be are skipped.

NameTypeReqDescription
namestringyesSite name (subdomain) whose external images should be downloaded and rehosted locally.
NameTypeReqDescription
bytesHostednumberyes
failuresarrayyesExternal image URLs that could not be rehosted (left untouched in the HTML).
htmlFilesUpdatednumberyesNumber of HTML files whose img references were rewritten to local paths.
imagesHostednumberyesNumber of external images downloaded and stored on the site.
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes

No examples provided.

remove_custom_domain ~109

Remove a custom domain from a site. The site itself is unaffected; only the custom hostname is detached. The {name}.vibedeploy.be subdomain keeps serving the site.

NameTypeReqDescription
domainstringThe custom domain to remove (e.g. 'tester.subsite.site'). Provide this OR recordId.
recordIdstringThe recordId returned by add_custom_domain. Provide this OR domain.
siteNamestringyesThe site to detach the domain from.
NameTypeReqDescription
domainstringyes
removedbooleanyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.

No examples provided.

search_files ~281

Search for a literal string or basic regex across all files in either the served dist or the editable source tree. Use this BEFORE batch-reading files to find candidates — saves the 'read 14 batches just to find which 3 files matter' round trip. Pass `target: "source"` to search the editable tree (requires Site.sourceStored=true).

NameTypeReqDescription
caseInsensitivebooleanDefault: false. When true, adds -i to grep.
globstringFilename glob filter, e.g. '*.js' or '*.{js,html}'. Applied via find before grep so we don't read non-matching files.
maxMatchesintegerCap on returned matches. Default 200, hard max 1000. Truncation is reported via budgetExceeded.
namestring
patternstringyesPattern to search for. Treated literal by default; pass regex:true to use as a basic regex (BusyBox grep BRE — no PCRE features).
regexbooleanWhen true, the pattern is interpreted as a basic regular expression. Default: false (literal substring match).
siteIdstring
targetstringWhere to search. 'dist' (default) searches the served files. 'source' searches the editable source tree (requires Site.sourceStored=true).
NameTypeReqDescription
budgetExceededbooleanyesTrue if the search hit maxMatches and there are likely more matches not returned.
matchesarrayyes
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
targetstringyes
totalMatchesnumberyes

No examples provided.

set_forms_config ~260

Configure the built-in form-to-email relay, fully self-service. Supports a custom From (via a verified sender domain or your own SMTP relay), an explicit Reply-To, and full email branding (subject template, field labels/order, logo, accent color, or a custom HTML body). Requires team role owner or admin. Pass config:null to switch the relay off. If you set a custom `sender` without an `smtpRelay`, the response returns the DNS records to publish; then call verify_forms_sender_domain. Submissions: POST JSON to the returned `endpoint` with Content-Type: application/json (UTF-8). Flat object of form fields (strings/numbers/booleans; checkbox groups may be arrays of strings, joined with ', '). Max 30 fields, 5000 chars/field, 20000 total. Response: {success:true,data:{ok:true}} or {success:false,error:{code,message}}. Rate limit: 10 submits per IP per 10 minutes. Include a hidden honeypot input (default "_gotcha") and leave it empty.

NameTypeReqDescription
configyesFull config to store (replaces existing). Pass null to disable and clear.
siteNamestringyesThe site to configure.
NameTypeReqDescription
activeSenderstringyesThe From that will actually be used right now.
deliverystringyesplatform | verified-domain | verified-domain-pending | custom-relay.
enabledbooleanyes
endpointstringyesURL the site's form should POST to.
formsConfigyesStored config (smtpRelay.password redacted to hasPassword).
notesarrayyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
senderDomainobjectDNS records to publish + verification status (verified-domain path).
siteNamestringyes

No examples provided.

update_file_content ~230

Apply one or more literal find/replace edits to a single file on the site, in one tool call. Designed for tiny edits where uploading the full file would be wasteful (one nav-button reference, one encoding fix, one env var bump). Each edit must specify how many matches it expects; mismatches abort the whole call with NO writes. For dist edits the change goes live immediately; for source edits you still need to call build_and_deploy.

NameTypeReqDescription
editsarrayyesOrdered list of edits to apply atomically. Each is `{find, replace, count?}`. If any edit's match count doesn't equal its expected count, the whole call aborts with no writes.
namestringyesSite name.
pathstringyesFile-relative path inside the chosen target tree.
targetstringWhich tree to edit. 'dist' (default) edits the served file directly — visitors see the change immediately. 'source' edits the editable source tree; you'll need build_and_deploy (or it short-circuits…
NameTypeReqDescription
afterBytesnumberyes
beforeBytesnumberyes
editsarrayyes
namestringyes
pathstringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
targetstringyes

No examples provided.

update_site ~435

Patch or replace files on an existing site. Defaults to patch mode: only the listed files change; everything else stays. Pass mode:'replace' to wipe-and-replace the whole site (the legacy behaviour, surfaced explicitly so it can't happen by accident). Use `delete: [paths]` in patch mode to remove specific files without wiping the rest. Use `dryRun: true` to preview the diff before committing. LARGE FILES: a 100-250 KB text file fits in one call with encoding:'gzip+base64' (gzip locally, base64 the result) — prefer that over begin_deploy + add_file_chunk streaming. Errors if the site does not exist.

NameTypeReqDescription
deletearrayPatch-mode only: site-relative paths to remove from the pod. Files not in this list are kept. Reported back in `deletedFiles` listing only entries that actually existed. Combine with `files` to atomi…
dryRunbooleanIf true, validate input + introspect what would change but don't write or delete. Returns the same shape with `dryRun: true` and `deletedFiles` showing what *would* be removed. Use this before any de…
filesFiles to write. Array form `[{path, content, encoding?}]` (preferred) supports binary via encoding:'base64'; map form `{path: content}` is utf8-only. <= 500 MB total. Optional when `delete` is provid…
modestringpatch (default): write only the listed files; everything else stays. replace: delete all existing files and write only the listed ones. Use replace only when you genuinely want to throw away the rest…
namestringSite name (preferred).
siteIdstringSite id (alternative to name).
NameTypeReqDescription
deletedFilesarrayyesFiles removed by this call. For patch mode this is the entries from `delete` that actually existed; for replace mode it's every pre-existing file not in `files`.
dryRunbooleanTrue if this was a dry-run; nothing was written or deleted.
filesDeployednumberyes
modestringyesThe mode that was actually applied.
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
urlstringyes
warningsarraySurfaced issues that did not block the deploy (e.g. DOTFILE_PUBLIC, leaked-secret patterns).

No examples provided.

verify_custom_domain ~103

Check the TXT record the user added at step 1 and, if found, attach the domain to the site's ingress. If verification fails, the most common cause is DNS propagation delay; wait a few minutes and try again. Once verified, the domain serves the site immediately (HTTPS issues automatically within ~30s).

NameTypeReqDescription
recordIdstringyesThe recordId returned by add_custom_domain.
siteNamestringyesThe site the domain was attached to.
NameTypeReqDescription
domainstringyes
messagestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
verifiedbooleanyes

No examples provided.

verify_forms_sender_domain ~114

Check the DNS records for a site's custom sender domain (DKIM TXT + SPF include). Once the DKIM record is observed, the sender domain is marked verified and the relay sends from the custom From (DKIM-signed). Until then it falls back to the platform address. DNS can take a few minutes to propagate — re-run if it fails the first time. Not needed when the site uses a custom smtpRelay.

NameTypeReqDescription
siteNamestringyesThe site whose custom sender domain to (re)check.
NameTypeReqDescription
dkimVerifiedbooleanyes
dnsRecordsarrayyes
domainstringyes
lastErroryes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
spfVerifiedbooleanyes
statusstringyespending | verified | failed

No examples provided.

write_source_files ~154

Stage edits to a site's editable source tree (not the live dist). Use list_source_files first to discover what's there. The dist is unchanged until you re-deploy via update_site or run build_and_deploy. Sites have source storage enabled by default; if a legacy site doesn't, the call fails with SOURCE_STORAGE_NOT_ENABLED and the user should contact VibeDeploy support to enable it.

NameTypeReqDescription
filesarrayyesFiles to write into the source tree. Same wire shape as add_files. Re-writing a path overwrites the previous source. Per-file cap 5 MB; per-call cap 50 MB; max 200 files per call.
namestring
siteIdstring
NameTypeReqDescription
namestringyes
request_idstringServer-assigned request correlation id. Quote it when contacting support.
siteIdstringyes
totalBytesnumberyes
totalFilesnumberyes
writtenarrayyes

No examples provided.