Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

com.floot/floot

REMOTE · MCP.FLOOT.COM · SCANNED SEP 22

Build and publish full-stack web and mobile apps on Floot from any MCP client. Building is free.

Available components

+4 this week 81 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security89
Transport & Reachability100
Schema Quality & AI Usability42
  • 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Fail
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 10904 tokens (~198/item across 55 items; 45 tools + 10 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management84
  • Stability check failed: schema churn in the 26 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 0 additions. See how to fix → Fail
Tool Coverage73
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 18% of tool parameters carry a description.Partial
Tool Safety96
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 5 of 6 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "get_publish_status" implies "publish" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
  • An AI judge read all 47 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
  • Supports UI / widget rendering.Pass
Install

How do I install the com.floot/floot MCP server?

com.floot/floot is a hosted endpoint at https://mcp.floot.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.floot.com

# add to Claude Code
claude mcp add --transport http com-floot-floot 'https://mcp.floot.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-floot-floot": {
      "url": "https://mcp.floot.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-floot-floot": {
      "type": "http",
      "url": "https://mcp.floot.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-floot-floot]
url = "https://mcp.floot.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-floot-floot": {
      "type": "remote",
      "url": "https://mcp.floot.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-floot-floot --url 'https://mcp.floot.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-floot-floot:
    url: "https://mcp.floot.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-floot-floot": {
      "Transport": "http",
      "Url": "https://mcp.floot.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-floot-floot -t streamable-http -u 'https://mcp.floot.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-floot-floot": {
      "type": "http",
      "url": "https://mcp.floot.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 22 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 81 to 84.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 74 to 78.

  • 19 Sept 26 0
    • Tool “publish_app” rewrote its description, which is the text the model reads security
    • “publish_app” dropped the optional parameter “skipPaymentsOnboarding” cosmetic
  • 18 Sept 26 +1
    • Tool “publish_app” rewrote its description, which is the text the model reads security
    • Tool “request_external_resource” rewrote its description, which is the text the model reads security
    • “publish_app” added an optional parameter “skipPaymentsOnboarding” cosmetic
    • “request_external_resource” reworded the description of “secret_env_vars” cosmetic
  • 17 Sept 26 0
    • Tool “update_project_metadata” rewrote its description, which is the text the model reads security
    • “update_project_metadata” added an optional parameter “analyticsMode” cosmetic
  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 61 to 64.

  • 14 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 54 to 58.

  • 12 Sept 26 0
    • Stability: 0.50 → fail security
    • A breaking change shipped without a version bump: still 1.0.0 security
    • Tool “republish_app” was removed security
    • Tool “get_publish_status” rewrote its description, which is the text the model reads security
    • Tool “publish_app” rewrote its description, which is the text the model reads security
    • Tool “publish_app” is now declared destructive security
    • “publish_app” reworded the description of “domain” cosmetic
    • “publish_app” reworded the description of “domain_type” cosmetic
    • “publish_app” reworded the description of “mobile” cosmetic
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 22 Sept 2026 · Probed https://mcp.floot.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=floot.com CN=Amazon RSA 2048 M01,O=Amazon,C=US 1 Jul 2026 14 Jan 2027 RSA 2048 SHA256-RSA 902d2fdfbf107a3d1db1dc0c72ee93a
SANs: floot.com, combini.ai, *.combini.ai, combini.dev, *.floot.com, *.combini.dev
CN=Amazon RSA 2048 M01,O=Amazon,C=US (CA) CN=Amazon Root CA 1,O=Amazon,C=US 23 Aug 2022 23 Aug 2030 RSA 2048 SHA256-RSA 77312380b9d6688a33b1ed9bf9ccda68e0e0f
CN=Amazon Root CA 1,O=Amazon,C=US (CA) CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US 25 May 2015 31 Dec 2037 RSA 2048 SHA256-RSA 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.floot.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
floot.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://mcp.floot.com/.well-known/oauth-protected-resource"

Bearer resource_metadata="https://mcp.floot.com/.well-known/oauth-protected-resource"
Header Value
www-authenticate Bearer resource_metadata="https://mcp.floot.com/.well-known/oauth-protected-resource"

Protected resource metadata

Document https://mcp.floot.com/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://mcp.floot.com/mcp
Authorisation server https://mcp.floot.com

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.floot.com/mcp Verified 200
http (plaintext) http://mcp.floot.com/mcp HTTPS enforced 301 https://mcp.floot.com/mcp
MCP tools · 45 exposed · ~10,353 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_dependency ~177

Add npm packages to the project (validated against Floot's supported set — rejected packages get a supported alternative named; some versions are pinned/substituted). Avoid node-gyp/native packages (exception: sharp is supported, auto-pinned), WASM modules, and packages bundling large binaries (e.g. ffmpeg/ffprobe); pure JS/TS preferred. A bare `kysely` installs 0.26.3, the version the generated db/schema helpers are written against; pass an explicit `kysely@<version>` only when upgrading it deliberately. Installs on the project VM and persists resolved versions. After a slow install completes as a job, call add_dependency again with the same packages — the second call is fast and persists.

NameTypeReqDescription
packagesarrayyes
projectIdstringyes

No output schema declared.

No examples provided.

apply_patch ~263

Apply a V4A patch to a Floot project — create, update, and delete multiple files in ONE atomic operation. Format: "*** Begin Patch" envelope with "*** Add File: path" (+ prefixed lines), "*** Update File: path" (hunks: optional "@@ anchor" locator, space-prefixed context, -/+ lines, optional "*** End of File"), "*** Delete File: path", then "*** End Patch". Paths follow the Floot item scheme (see read_file). To replace a file wholesale use Add File on its own — Add OVERWRITES. Never Delete+Add the same path: Delete is item-scoped (deleting components/X.tsx deletes the whole item, its .module.css included), so it is both unnecessary before an Add and destructive to the siblings. Move to: is not supported — to RENAME, Add File at the new path and Delete File the old one. Keep each patch MODEST (a few files / few hundred lines): chat clients cap per-message output, and a patch cut off mid-way is rejected whole ("missing *** End Patch") — split big changes across several apply_patch calls.

NameTypeReqDescription
expected_versioninteger
patchstringyes
projectIdstringyes

No output schema declared.

No examples provided.

cancel_request ~89

Withdraw a pending request you created — a credential request from request_external_resource, a custom-domain setup request from publish_app, or an open screenshot job from screenshot_preview (jobId from that tool). Only pending requests can be cancelled — completed ones are final. Use when the user says to stop or they don't want to proceed.

NameTypeReqDescription
jobIdstringyes
projectIdstringyes

No output schema declared.

No examples provided.

card_upload_asset ~110

Internal bridge for the upload card (not for agents — use request_user_upload / upload_asset). phase 'presign' mints the PUT URL for the picked file; phase 'complete' verifies the object landed and finishes the request_user_upload call with the publicUrl.

NameTypeReqDescription
content_typestring
file_namestring
jobIdstringyes
phasestringyes
projectIdstringyes
size_bytesinteger

No output schema declared.

No examples provided.

copy_file ~85

Copy one or more items to new names (e.g. {from:'components/Card', to:'components/BigCard'}). Item names without extensions; same type only. Importers of the source are left unchanged. Pass several copies to apply them in one call.

NameTypeReqDescription
copiesarrayyes
expected_versioninteger
projectIdstringyes

No output schema declared.

No examples provided.

create_checkpoint ~163

Create a NAMED checkpoint — a labeled restore point the user sees in the project's Checkpoints panel and can revert to later. All file/dependency changes since the previous checkpoint are grouped under it. Call this AFTER completing a coherent unit of work (a feature, a fix, a requested change set) — not after every file write. Give it a short user-meaningful title describing what was accomplished (e.g. 'Added login page with email auth'), optionally a description with detail. No-op when nothing changed since the last checkpoint. Restoring a checkpoint reverts code and project config only — database rows, uploaded assets and published deployments are not rolled back.

NameTypeReqDescription
descriptionstring
projectIdstringyes
titlestringyes

No output schema declared.

No examples provided.

create_project ~150

Create a new Floot project (pre-seeded with the shared component library) and return its id. `initial_prompt` is the USER'S ORIGINAL REQUEST verbatim — it grounds the project (served back as <project-instructions> in list_files) and is preserved for the record; don't paraphrase it away. The result renders a live preview card for the user and includes the first-build playbook: a fresh project is EMPTY until pages are written, so a session normally continues straight into get_guides("design") and the first page rather than ending at the card.

NameTypeReqDescription
initial_promptstringyesThe user's original request that started this project, verbatim.
namestringyes

No output schema declared.

No examples provided.

delete_file ~79

Delete a project file. Deleting an item's main code file (e.g. components/Foo.tsx) removes the whole item including its css/tests; deleting an aux file (e.g. Foo.module.css) only clears that part.

NameTypeReqDescription
expected_versioninteger
pathstringyes
projectIdstringyes

No output schema declared.

No examples provided.

edit_file ~114

Replace old_string with new_string in a project file. old_string must match the current content exactly (including whitespace) and be unique unless replace_all is set. Prefer this over write_file for changes to existing files.

NameTypeReqDescription
expected_versioninteger
new_strstring
new_stringstring
old_strstring
old_stringstring
pathstringyes
projectIdstringyes
replace_allboolean

No output schema declared.

No examples provided.

execute_sql ~222

Run a WRITE SQL statement against the project's Postgres database — CREATE/ALTER TABLE, INSERT, UPDATE, DELETE, DROP, migrations. Destructive statements are allowed but your MCP client will show the user the SQL and ask them to approve it (they can allow once or for the session). Schema-changing statements (CREATE/ALTER/DROP of tables, types, …) automatically re-pull the typed schema helper and return the updated schema — no separate pull_database_schema call needed. Pass `database` only if the project has more than one. The query runs in a single transaction by default; set no_transaction for statements that cannot run inside a transaction block (VACUUM, CREATE INDEX CONCURRENTLY, …). Queries are killed after 90 seconds either way.

NameTypeReqDescription
databasestring
no_transactionbooleanRun the statement without a wrapping transaction — required for VACUUM, CREATE INDEX CONCURRENTLY, and other statements Postgres rejects inside a transaction block.
projectIdstringyes
querystringyes

No output schema declared.

No examples provided.

fetch ~59

Fetch a search result by id: a project overview ('<projectId>') or a file ('<projectId>:<path>'). For direct access to a known file or project, read_file/list_files give more detail.

NameTypeReqDescription
idstringyes

No output schema declared.

No examples provided.

generate_image ~169

Generate AI image assets directly into the project. Each image is written to the project's own asset storage and registered in its asset manifest; the tool returns the project-relative asset paths (/_cdn/static/...), which only resolve on the app's own domain — reference them in code or set one as the app/PWA icon via update_project_metadata (iconUrl). Use this for PROJECT-SPECIFIC imagery (mascots, tailored illustrations, app/PWA icons, imagery in a particular style); for generic stock imagery (nature, textures, generic people) use Unsplash URLs instead; if you already HAVE an image as a local file (generated or downloaded yourself), use upload_asset. Generate BEFORE building the components that use the images.

NameTypeReqDescription
imagesarrayyes
projectIdstringyes

No output schema declared.

No examples provided.

get_current_context ~230

What the user is looking at RIGHT NOW in their open Floot editor: the active page/component, the preview element they selected (mapped to source file:line), the preview device size, whether they drew a screenshot annotation for you, whether they REVERTED recent changes (undoing edits — re-read before editing if so), and any requests they queued via editor action buttons ("Fix with Floot" etc.). Call this FIRST when the user refers to something without naming it ("this", "here", "the button"), reports a problem without saying where ("it's broken", "looks wrong"), or implies they triggered something in Floot ("go", "I clicked fix", "I undid that"). Cheap and text-only. With several windows open, one answers (the result says which) — but a selection made in ANY window is merged in, so a "no selection" from the answering window plus a deposited selection from another window means the deposited one is what the user means. If it reports a pending annotation, call view_annotation to see the image.

NameTypeReqDescription
projectIdstringyes

No output schema declared.

No examples provided.

get_guide ~59

Compatibility alias of get_guides — the identical tool under its common misspelling. Prefer get_guides; see it for full usage.

NameTypeReqDescription
projectIdstring
topicstring
topicsarray

No output schema declared.

No examples provided.

get_guides ~148

Floot documentation for agents. Call with no arguments to list available guides. Pass `topic` for one guide (e.g. topic:'floot-overview') or `topics` (an array of ids) to fetch several at once. floot-overview explains how Floot projects work — read it before your first code change. Skill guides that ship seed code (marked in the list) AUTO-INJECT it into the project the first time they're loaded with a projectId — pass projectId whenever you're working on a project; idempotent, never overwrites existing files.

NameTypeReqDescription
projectIdstring
topicstring
topicsarray

No output schema declared.

No examples provided.

get_job_status ~142

Poll a pending tool call by its jobId. Each poll either returns the final result (succeeded/failed/cancelled), or reports the call as still running — call it again until you get the result. Failed calls return their stored error message. A jobId belongs to exactly ONE task: it never blocks other tools or other jobs (run them freely in parallel), and once terminal it is frozen history — a NEW user request means a fresh call on the originating tool, never re-polling an old jobId. Legacy v!/b! job ids are also accepted.

NameTypeReqDescription
jobIdstringyes
wait_secondsinteger

No output schema declared.

No examples provided.

get_logs ~305

Your FIRST step when debugging any runtime problem — a 500, a failed request, a blank page, or 'it doesn't work' from the user. Call this before theorizing from an error message alone. Reads the project's runtime logs. source 'server' (default): the dev backend's request logs from the last hour — method, URL, status, duration, and per-request server log lines (pass log_reference_id from a previous listing for one request's full logs); includes background jobs (queueTask/scheduled/failure). source 'browser': console output AND client-side network requests (each fetch as `⇄ METHOD url → status`, with the error body for failed/4xx/5xx ones — the client-side view server logs miss, e.g. CORS/timeouts/third-party calls) captured from the user's open editor session. A browser network line's `ref=<id>` is a log_reference_id you can pass back with source 'server' for that request's full server logs. Empty if no editor is open. NOT CloudWatch: entries live ~1 hour and cover the dev backend + live session only — for the PUBLISHED app's logs, use run_code_in_vm's `_floot.getProdBackendLogs` (details: get_guides('prod-backend-logs')).

NameTypeReqDescription
limitinteger
log_reference_idstring
projectIdstringyes
sourcestring

No output schema declared.

No examples provided.

get_preview_url ~226

Show the user a live preview card and return the preview link. On an EXISTING project this is typically called EARLY, before the first change, so the user watches edits live from the start; the result is informational and a working session normally continues past it. Do NOT call it right after create_project — that result already showed the same card; calling both duplicates it. The preview URL carries an access token in its query string and only works shared EXACTLY as returned (no Floot login, view-only — which is also what lets it open on a phone); it live-updates as you edit, so it also suits an in-app browser tab if your client has one. The result additionally includes the sandbox API base for your own headless /_api/* testing — the frontend does not render there and it is not a user-facing URL; the preview link is the one meant for the user. Floot HOSTS the app — to go to production use publish_app; never suggest deploying a Floot app to an external host.

NameTypeReqDescription
projectIdstringyes

No output schema declared.

No examples provided.

get_publish_status ~334

Read-only publish snapshot for a project: published (true/false, with the live URL when published), customDomains (the user's own domains attached to the project — apex and www are listed separately; empty when none), paid (the workspace owner has a paid plan, which allows removing the Floot badge), plan (free | pro | power — `paid` cannot tell Pro from Power), nativeBuilds (the owner's remaining monthly iOS/Android app-build allowance; `unlimited` is true on plans where the ceiling is only a fair-use backstop, and while an Action Boost is live (`boostUntil` says until when; builds started before then never count toward the allowance) — read this BEFORE passing mobile: true, and on a metered plan build only when the user asked for a native/TestFlight/Play build), displayFlootLogo (whether the live app shows the 'Made with Floot' badge; true until a paid owner turns it off), and mobileBuild (the published app's latest native app build: building, succeeded, or failed with what to fix — an app build finishes minutes AFTER the publish job it rode on, so read this to learn how it ended before telling the user it worked). This is the ONLY tool that reports attached custom domains — read it before telling a user whether their domain is connected, and never conclude a domain is unattached from any other output. The publish card calls this on load to render fresh state; also check it before publishing to know whether publish_app will publish fresh or publish the live app again.

NameTypeReqDescription
projectIdstringyes

No output schema declared.

No examples provided.

list_files ~102

List a Floot project's virtual file tree with sizes, plus its dependencies, current version (pass the version to write tools as expected_version), and current project metadata — title, description, app icon (iconUrl), splash screen, mobile app id, SSR, iOS Info.plist overrides, share target (iOS + Android), native system bars. This is where to look up those settings; update_project_metadata changes them.

NameTypeReqDescription
projectIdstringyes

No output schema declared.

No examples provided.

list_projects ~91

List your Floot projects (id, name, last-updated, whether an app icon is set), most recently updated first. name_filter is a case-insensitive substring match on the stored name, which is often not the name the user uses for a project — on a small account a filter that matches nothing returns the whole list instead.

NameTypeReqDescription
limitinteger
name_filterstring

No output schema declared.

No examples provided.

list_resources ~159

List the env vars a project's code can use and the resources behind them: (1) resources CONNECTED to the project — usable as process.env.<NAME> in endpoint code now; (2) the owner's other account-level credentials — reusable, but not usable in code until connected; (3) everything Floot can add. Call it to learn what env vars exist before writing backend code, and BEFORE provisioning or requesting any credential (the owner may already have the one you need). Pass query (case-insensitive substring over names, descriptions, types, and env var names) to filter when the account has many resources. Read-only. Details: get_guides('resources').

NameTypeReqDescription
projectIdstringyes
querystring

No output schema declared.

No examples provided.

navigate_preview ~360

Point the user's OPEN Floot preview at a page URL, a component's examples, or a page's examples — use it to SHOW the user what you just built ("here's the new dashboard page", "here's the Button component's states"), and pair it with screenshot_preview to see the result yourself. targetType "page" navigates the app's router to `path` — a URL path with optional query/hash ("/", "/user/123?tab=settings#top"; pages/user.$id.tsx serves /user/<id>). targetType "component" renders the component's .example.tsx showcase for `name` ("HeroSection", exactly as list_files shows it; tell the user if it has no example — you can create one). targetType "page-examples" renders the staged screens in pages/<name>.__example.tsx for the page `name` ("dashboard", "_index") — the same view as the preview's Live/Examples switch, so it needs that file to exist. Requires a Floot window to be open for this project; fails fast with guidance when none answers. Does not modify the project.

NameTypeReqDescription
namestringThe item name without folder prefix or extension, exactly as list_files shows it. For targetType "component" a component — e.g. "HeroSection". For targetType "page-examples" a page — e.g. "dashboard"…
pathstringFor targetType "page": the URL path to navigate to, starting with "/" — query and hash allowed, e.g. "/user/123?tab=settings#top".
projectIdstringyes
targetTypestringyes

No output schema declared.

No examples provided.

provision_resource ~389

Provision a Floot-managed backend resource for the project — fully server-side (Floot mints all secrets; no keys to paste). Also seeds the working code for it. Available: - database — A Floot-managed Postgres database (Neon). FLOOT_DATABASE_URL is set for the app. - auth — Email/password + session auth (JWT_SECRET, auto-provisions a database if none). Injects auth pages, endpoints, and helpers. - oauth-login — Sign in with Google via Floot's brokered OAuth (FLOOT_OAUTH). Injects OAuth provider classes, login buttons, helpers. - microsoft-login — Sign in with Microsoft via Floot's brokered login (FLOOT_MICROSOFT_LOGIN). Injects button + auth endpoints. - google-integration — Google API access (Gmail/Calendar/etc.) via Floot's brokered Google OAuth (FLOOT_GOOGLE_INTEGRATIONS). Injects Connect button + endpoints. - microsoft-integration — Microsoft Graph access (Outlook/Teams/etc.) via Floot's brokered Microsoft OAuth (FLOOT_MICROSOFT_INTEGRATIONS). Injects Connect button + endpoints. - push-notifications — Web + native push (FLOOT_PUSH). Mints VAPID keys, injects helpers/pushClient (subscribe/unsubscribe) + a service worker. Enum values not listed above are beta-gated and unavailable on most accounts. SENDING email from the app is NOT a resource — the builtin @floot/email handles it with zero setup (get_guides("email")). For a user's OWN external key (their OpenAI key, an external database), this is NOT the tool — use request_external_resource instead. Idempotent: re-running returns the existing resource and skips seed files that already exist.

NameTypeReqDescription
projectIdstringyes
resourcestringyes

No output schema declared.

No examples provided.

publish_app ~591

Publish the app to production — call for the first publish, to publish again after changes the user wants live, and to set up a custom domain. Omit domain and the user gets the publish form in the editor. Pass mobile: true whenever the user mentions iOS, Android, TestFlight, App Store, Google Play, or a mobile/native app — with no store account connected that returns a Connect card; with one connected it publishes with the store builds attached. When the project takes payments and its owner has not finished Stripe setup, the publish is refused and a Set up payments card is returned (nothing published): tell the owner to click the button on the card and finish Stripe setup, then call publish_app again. Read get_guides('publishing') for modes, inputs, and statuses before your first call.

NameTypeReqDescription
add_anotherbooleancustom_domain only: the project ALREADY has a custom domain and the user has explicitly asked for an ADDITIONAL one. Without it, a custom_domain call on a project that already has domains returns tho…
domainstringfloot_subdomain only: subdomain label (lowercase, digits, hyphens, max 40). Omit to show the user the publish form instead; on a published app a different subdomain is refused (unpublish_app first, c…
domain_typestringOmit for the floot subdomain (shows the publish form in the editor when domain is omitted). 'custom_domain' for domain setup — a paid-plan feature (get_publish_status reports `paid`); it fails for fr…
include_made_with_flootbooleanfalse removes the 'Made with Floot' badge (paid plans only — fails for free accounts). Omit to keep the current setting.
mobilebooleanSet true whenever the request mentions iOS, Android, TestFlight, App Store, Google Play, Play Store, a native or mobile app, or a phone build — they all mean a mobile build. No store account connecte…
projectIdstringyes

No output schema declared.

No examples provided.

pull_database_schema ~179

Introspect the database and write a typed schema helper the app uses for queries (kysely on current projects; some legacy projects use drizzle or snake_case kysely — the pull matches whatever the project already uses). Usually NOT needed after execute_sql — schema-changing statements re-pull automatically. Use it to refresh manually, or with helper_name to generate the helper for an additional/external database. The helper is GENERATED — never hand-edit it or cast around its types: if a column's type is too loose (e.g. role as string when code expects "user" | "admin"), fix the DATABASE (CREATE TYPE … AS ENUM + ALTER COLUMN … TYPE) and re-pull, and the union type falls out.

NameTypeReqDescription
databasestring
helper_namestring
projectIdstringyes

No output schema declared.

No examples provided.

query_database ~102

Run a READ-ONLY SQL query against the project's Postgres database (SELECT, EXPLAIN, etc.). Writes are rejected — use execute_sql for those. Returns JSON: `{rows, rowCount, command, truncated?}` (or `{results: [...]}` for multi-statement queries). Pass `database` only if the project has more than one.

NameTypeReqDescription
databasestring
projectIdstringyes
querystringyes

No output schema declared.

No examples provided.

read_file ~325

Read a file from a Floot project (cat -n style). Paths follow the item scheme: components/Name.tsx, components/Name.module.css, helpers/Name.tsx, pages/name.tsx, pages/name.pageLayout.tsx, endpoints/route_POST.ts, endpoints/route_POST.schema.ts, static/file.txt, base.css. Use offset/limit for large files. Pass include_references:true to also list which project files reference this one (static import graph plus queueTask/runCode name references and, for endpoints, URL-path string usage) — check it before renaming or deleting a file, or use rename_file which rewrites importers itself. Hosted assets are readable too: pass the project-relative asset path (/_cdn/<name>, as returned by upload_asset / generate_image or used in the app's <img src>; private/<name> for private storage) and a png/jpeg/gif/webp image is returned as an image you can see (≤3.75 MB), text-typed assets as text, other binaries as a size/type summary. For a .ts/.tsx file, the file's CURRENT type errors are appended when the project's compute VM is already warm (so you see latent errors before editing); pass diagnostics:"off" to skip, or "wait" to boot the VM and force the check.

NameTypeReqDescription
diagnosticsstring
include_referencesboolean
limitinteger
offsetinteger
pathstringyes
projectIdstringyes

No output schema declared.

No examples provided.

read_files ~236

Read MULTIPLE files from a Floot project in ONE call — much cheaper than repeated read_file (the whole project is loaded once, one round-trip). Prefer this whenever you need several files together (e.g. an endpoint + its .schema.ts + the hook that calls it, or orienting in a feature). Pass up to 20 paths (same item scheme as read_file; /_cdn/<name> asset paths are accepted too and images come back as image blocks). Each file is returned cat -n style under a header. Each .ts/.tsx file's current type errors are appended when the compute VM is warm (diagnostics:"off" to skip, "wait" to force). include_references:true appends each file's referencing files (same analysis as read_file). Output is capped overall; if the batch is too large, whole files at the end are omitted and listed by name so you can read them individually.

NameTypeReqDescription
diagnosticsstring
include_referencesboolean
limitinteger
pathsarrayyes
projectIdstringyes

No output schema declared.

No examples provided.

remove_dependency ~40

Remove npm packages from a Floot project's dependency record (record-only; nothing runs).

NameTypeReqDescription
packagesarrayyes
projectIdstringyes

No output schema declared.

No examples provided.

rename_file ~122

Rename one or more items and automatically rewrite every file that imports them. Use item names WITHOUT extensions (e.g. {from:'components/OldName', to:'components/NewName'}). Preferred over delete+create — preserves content and fixes importers. Same type only. Pass several renames to apply them atomically in ONE pass; importer rewrites are resolved across the whole batch (including chains where one rename's target is another's source).

NameTypeReqDescription
expected_versioninteger
projectIdstringyes
renamesarrayyes

No output schema declared.

No examples provided.

request_external_resource ~728

Request the USER'S OWN external credential for this project — their OpenAI or Anthropic API key, an external Postgres connection string, or any other service's key (type GENERIC, e.g. Stripe/Resend — secret_env_vars is REQUIRED for GENERIC and the call is refused without it; a var the user can only produce LATER, like a webhook signing secret, goes in optional_env_vars so the dialog doesn't demand it up front). NOT for Floot-managed resources (database/auth/push/oauth/…) — use provision_resource for those; they need no user input. REUSE FIRST: if the project owner already has a matching credential on their account (list_resources section 2), this connects it silently and returns the env var names — no link, no user action, nothing to poll. Pass the name exactly as list_resources shows it to make that happen. Reusing a POSTGRES credential also seeds helpers/db, installs the query stack, and pulls the typed schema helper, so do NOT write those yourself afterwards. Otherwise it returns a secure connect link: SHOW it to the user (UI-capable hosts render a Connect button automatically; on terminal hosts with shell access open it in the user's default browser yourself and paste the URL as plain text) and ask them to open it. The call completes only when the user finishes the connect flow — it never expires. Do NOT block on it: request the credential EARLY, keep building everything that doesn't need the secret (the env var names are known now — reference process.env.X in code before the secret exists), and check the request between tasks; the user may never connect it, and the build must not stall. NEVER ask the user to paste a secret into the chat. On completion you get the env var names — never the secret values. Re-calling with the same type returns the same pending request. If the credential is already connected and holds every value you asked for, you get those env var names and their value SHAPES back immediately and the user is not interrupted — to reopen a dialog…

NameTypeReqDescription
instructionsstringWhy the key is needed / where the user can find it — shown to the user in the dialog.
namestringDisplay name for GENERIC requests, e.g. 'Stripe'.
optional_env_varsarrayGENERIC only: env vars the user may leave blank at connect time and fill in later — e.g. a webhook signing secret that only exists after the webhook endpoint is created. Rendered as optional fields;…
projectIdstringyes
secret_env_varsarrayREQUIRED for GENERIC (the call is refused without it): the env var name(s) the secret(s) should be exposed as — e.g. ["STRIPE_SECRET_KEY"]. Name what you will actually reference as process.env.<NAME>…
typestringyes

No output schema declared.

No examples provided.

request_user_upload ~287

Show the user an inline upload card so they can hand you a file from their device (image/font/audio/…) — it lands in the project's hosted assets and the card gives you the hosted publicUrl. This is the path for any file the user has: an image they attached in this chat (attachments never reach MCP servers — you see them through vision only, so the user re-picks the same file here), a file on their machine, or a user-provided file you hold but can't upload yourself (over the 3 MB inline cap with no S3 egress — the card uploads from their browser, which is never egress-blocked). Returns a jobId — poll get_job_status; it stays running until they upload, then returns the publicUrl to reference in code. When you show the card, tell the user in a sentence why you're asking — e.g. that you can see their image but the file itself doesn't reach Floot, so re-adding it here is a one-click step — and ask them to say "uploaded" when done in case your polling ends before they finish. For files you hold yourself, use upload_asset; for AI-generated imagery, use generate_image.

NameTypeReqDescription
descriptionstringShown in the card — what you're asking for, e.g. "the logo image you attached".
projectIdstringyes

No output schema declared.

No examples provided.

run_code_in_browser ~432

Run a TypeScript snippet inside the RUNNING APP's preview document in the user's open Floot editor (`document`/`window` ARE the live app's DOM — query `document` directly; do NOT look for a preview iframe, there is none from the snippet's point of view). This is the CANONICAL way to read the live app's DOM — measuring elements, reading computed styles, inspecting rendered output. If you ALSO have your own browser/DevTools automation, it CANNOT reach into the Floot preview (it renders in a cross-origin iframe — your clicks silently no-op and its DOM is invisible to you), so use THIS tool for anything inside the app, not those. `_floot.*` helpers are available. The snippet MUST `export default async function` and return a string — the returned value is the tool result (unlike run_code_in_vm, which is a plain script returning stdout). It can import project files by relative path from the root (e.g. `./helpers/foo`). Requires the user to have the project open in the editor — fails fast with guidance if no browser is connected; prefer run_code_in_vm for anything that doesn't need the DOM. Simple interaction checks work well: element.click() a button, await a beat, then read the resulting DOM/state to verify a flow end-to-end — do this instead of asking the user to test basic interactions. Multi-step e2e journeys and typed text input are where simulation gets unreliable (React controlled inputs ignore assigned values) — leave THOSE to the user.

NameTypeReqDescription
codestringyesA TypeScript module that exports a default async function returning a string; that string is the tool result. Runs at the project root, so import other files by relative path. No top-level `return` (…
projectIdstringyes

No output schema declared.

No examples provided.

run_code_in_vm ~727

Run a Node.js snippet on the project's compute VM (headless — no browser needed). The project's npm dependencies are importable; network access works, so you can call the project's /_api/* endpoints (get_preview_url → apiBaseUrl). ESM by default; bare require() snippets run as CJS. Returns stdout+stderr. Calls to the project's /_api/* are rate-guarded exactly like the browser preview: more than 20 calls to one endpoint or 150 total within 5s rejects that fetch and every later /_api/* fetch in the snippet with 'Backend endpoint is called too frequently'. This is a hard guard, not a retry hint — do NOT loop fetch() over rows/ids or fire many parallel calls; batch into one endpoint call, or use _floot.runSQLQuery for bulk reads/writes. Runs in an ISOLATED temp dir, NOT the project root, with NO access to the project's environment: `process.env` carries none of the project's env vars or secrets (only PATH/HOME/NODE_ENV are set — anything like `process.env.POSTHOG_API_KEY` reads back `undefined`), and project source files are NOT importable by relative path (`import './helpers/foo'` fails with ERR_MODULE_NOT_FOUND — only npm dependencies resolve; contrast run_code_in_browser, which runs at the project root and CAN import project files). For anything that needs project secrets, env config, or DB access, use the `_floot` helpers below (they proxy to the project's server context) or fetch the project's /_api/* endpoints over the network — those run server-side WITH the full env; the VM snippet itself never sees it. A `_floot` global is available with project-scoped server-data helpers (no DB creds needed, no HTTP wiring): `await _floot.runSQLQuery({ query, resourceName?, reasonAndExplanationForNotReadOnly?, dryRun? })` (omit the reason for a read-only query; pass it to allow NON-DESTRUCTIVE writes — INSERT, CREATE TABLE, additive ALTER — e.g. programmatic seeding loops. DESTRUCTIVE statements — DELETE/UPDATE/TRUNCATE/DROP — are rejected here because the user never sees…

NameTypeReqDescription
codestringyes
projectIdstringyes
timeout_secondsinteger

No output schema declared.

No examples provided.

run_tests ~173

Run the project's Jasmine spec files (helpers/*.spec.tsx) headlessly on the project VM (jsdom — no browser needed). Frontend AND backend code is testable: specs may render components (@testing-library/react) or import endpoint handlers/backend helpers and call them directly. Limits: fetch throws inside tests (mock with spyOn(globalThis, "fetch")), process.env secrets are absent, and specs importing @floot/* service modules are skipped (no mocks yet). Returns per-file PASS/FAIL with failing expectations. Defaults to all spec files except hook specs (file name contains "use" — those need real React scheduling and are excluded, matching the in-editor checker); pass `paths` to run specific spec files, including hook specs.

NameTypeReqDescription
pathsarray
projectIdstringyes

No output schema declared.

No examples provided.

screenshot_preview ~52

Capture a screenshot of the user app. Call it whenever you want to SEE what the app currently looks like (layout, styling, rendered state) or want to debug the app.

NameTypeReqDescription
projectIdstringyes

No output schema declared.

No examples provided.

search ~47

Search your Floot projects and their code. Returns result ids usable with fetch. For richer options, list_projects enumerates projects and search_code does code-level search.

NameTypeReqDescription
querystringyes

No output schema declared.

No examples provided.

search_code ~80

Search a Floot project's files (string or regex) with optional glob filters (e.g. ['components/*', 'endpoints/**']). Returns file:line excerpts plus filename matches; capped at 40 results.

NameTypeReqDescription
globarray
projectIdstringyes
querystringyes
regexboolean

No output schema declared.

No examples provided.

typecheck ~46

Typecheck the project (incremental tsc on the project VM). Type errors don't block the app from running.

NameTypeReqDescription
pathsarray
projectIdstringyes

No output schema declared.

No examples provided.

unpublish_app ~45

Take the published app offline and release its subdomain — destructive, confirm with the user first. Details: get_guides('publishing').

NameTypeReqDescription
projectIdstringyes

No output schema declared.

No examples provided.

update_project_metadata ~1,056

Update project settings (current values appear at the top of list_files). Keys: title (2-100 chars), description, iconUrl, splashUrl, mobileAppId, enableSSR (boolean), flootAiDisallowed (boolean — true opts the project out of @floot/ai), and iOS Info.plist purpose strings (NS…UsageDescription — set to a string, or null to remove) plus boolean Info.plist keys (UIViewControllerBasedStatusBarAppearance — set to a boolean, or null to restore the template default). Invalid keys/values are reported and skipped. NOTE: these take effect on the published app only after the next publish (publish_app, or the user's Publish button). The iosInfoPlist keys only affect builds made before the first iOS publish; after the iOS app is published, edit the project file `static/__dev/native/ios-info.plist` directly with write_file/edit_file (see get_guides('ios-info-plist')). Likewise, after the first Android publish, edit `static/__dev/native/android-manifest.xml` directly for manifest changes (see get_guides('android-manifest')). `shareTarget` makes the native app appear in the iOS and Android share sheets (other apps can share photos/videos/files/text into it): pass { enabled: true, mimeTypes?, allowMultiple? } to register, { enabled: false } to remove; receiving the shared items still needs the handler in app code — read get_guides('share-target') first and ship both together. `nativeSystemBars` controls how the native app treats the status bar / Android navigation bar: mode 'inset' (default) keeps the app below the bars and paints the exposed strips `color` (default black — set it to the app's header color for a seamless look); mode 'edge-to-edge' runs the app under the bars, which REQUIRES the app to pad by var(--safe-area-inset-top/bottom) itself — read get_guides('native-system-bars') first and ship both changes together. Not superseded by the __dev/native files. `serverMemoryMb` sets the memory (MB) of the project's server Lambda, which runs every endpoint, queued task, schedul…

NameTypeReqDescription
analyticsModestringBuilt-in visitor analytics mode for the published app: 'storage' (default, session id in localStorage — needs a consent banner for EU/UK visitors), 'memory' (nothing stored on the device, no consent…
nativeSystemBarsobjectNative system-bars config. Omit to leave unchanged; { mode: 'inset' } with no color restores the default.
projectIdstringyes
serverMemoryMbMemory (MB) of the project's server Lambda, 512–4096. EXPERT SETTING: only on an explicit user request to change the server memory (see the tool description for the risks); never touch it otherwise.…
shareTargetobjectShare-sheet target config (iOS Share Extension + Android share sheet). Omit to leave unchanged; { enabled: false } removes it.
updatesobjectFlat metadata fields (see the tool description).

No output schema declared.

No examples provided.

upload_asset ~680

Upload a binary asset (image, font, audio, …) to the project's hosted storage. This uploads bytes you actually hold — a file you generated, downloaded, or read yourself. Chat attachments don't qualify: the user's attachments never reach MCP servers (you see attached images through vision only; there is no file, id, or URL behind them you can read), so for those use request_user_upload instead and the user re-picks the file in a card that uploads from their browser. Three modes. ChatGPT conversation files — a generated image, a file ChatGPT itself holds: pass the file as the `file` parameter and the host attaches a download link itself; this server fetches the bytes directly, at full quality (nothing goes through your sandbox or through base64 in arguments; content_type and size_bytes are optional here). Never downscale or re-encode a generated image to fit the inline cap — pass it as `file` instead. Files up to 3 MB you hold yourself — pass content_base64 plus size_bytes (the decoded byte count) and the upload completes in this call, returning publicUrl. Larger files — pass size_bytes alone to get an uploadUrl; PUT the raw bytes to it with the same content_type and exact byte count (e.g. `curl -X PUT -H 'Content-Type: image/png' --data-binary @file.png '<uploadUrl>'`), then reference publicUrl. Some sandboxes (claude.ai Cowork, ChatGPT containers) block egress to S3: if the PUT fails in any way — connection failure, proxy error, or a response without an x-amz-request-id header — that block is permanent for the session, so switch paths instead of retrying or re-encoding smaller: the `file` parameter in ChatGPT for any file that exists in this conversation, content_base64 for files under 3 MB, request_user_upload for user-provided files, or a PUT from inside the project VM via run_code_in_vm (re-mint the URL first; it is short-lived). For AI imagery generated fresh, use generate_image. A single file can be at most 100 MB via the presigned mode (the inline content_bas…

NameTypeReqDescription
content_base64stringThe file's bytes, base64-encoded (≤3 MB decoded). When set, the upload completes in this call.
content_typestringRequired unless `file` is set (in that mode the type is derived from the downloaded bytes; pass this only as a hint).
fileobjectChatGPT only: a file from this conversation (e.g. a generated image). The ChatGPT host fills download_url/file_id when you reference the file; the values are host-issued and cannot be constructed by…
file_namestringyes
projectIdstringyes
size_bytesintegerRequired unless `file` is set. Exact byte count of the file, as measured from the file itself (e.g. stat/ls -l). With content_base64 it must equal the decoded length; in presigned mode the PUT must s…

No output schema declared.

No examples provided.

view_annotation ~67

View a screenshot annotation the user drew on the app preview (annotationId comes from get_current_context). Returns the annotated image — the user's drawings/text point at what they mean. Annotations expire after ~1 day.

NameTypeReqDescription
annotationIdstringyes
projectIdstringyes

No output schema declared.

No examples provided.

write_file ~113

Create or fully overwrite a file in a Floot project. Content is written literally. Paths must follow the item scheme (see read_file); invalid paths are rejected with the rule they broke. Pass expected_version (from list_files/read_file) to detect concurrent edits. Writing components/Name.module.css sets the css of components/Name — other properties of the item are preserved.

NameTypeReqDescription
contentstringyes
expected_versioninteger
pathstringyes
projectIdstringyes

No output schema declared.

No examples provided.

Common questions

What is the com.floot/floot MCP server?

com.floot/floot is an MCP server listed in the public MCP registry as com.floot/floot. Build and publish full-stack web and mobile apps on Floot from any MCP client. Building is free. This page covers its hosted endpoint (https://mcp.floot.com/mcp).

Is the com.floot/floot MCP server safe to use?

com.floot/floot scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the com.floot/floot MCP server expose?

com.floot/floot exposes 45 tools: search, fetch, list_projects, list_resources, list_files, and 40 more. Their descriptions and schemas cost roughly 10,353 tokens of context every time the server is loaded.

Does the com.floot/floot MCP server require authentication?

Yes. com.floot/floot asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the com.floot/floot MCP server still maintained?

com.floot/floot is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.