Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Kleap

REMOTE · KLEAP.CO · SCANNED SEP 22

Build, edit, publish, and manage websites and web apps with Kleap hosting, domains, and analytics.

Available components

+3 this week 80 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security89
Transport & Reachability100
Schema Quality & AI Usability77
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 7582 tokens (~261/item across 29 items; 26 tools + 3 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
  • Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety92
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 2 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "get_publish_status" implies "publish" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
  • An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
  • Supports UI / widget rendering.Pass
Install

How do I install the Kleap MCP server?

Kleap is a hosted endpoint at https://kleap.co/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · kleap.co

# add to Claude Code
claude mcp add --transport http kleaphq-kleap 'https://kleap.co/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "kleaphq-kleap": {
      "url": "https://kleap.co/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "kleaphq-kleap": {
      "type": "http",
      "url": "https://kleap.co/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.kleaphq-kleap]
url = "https://kleap.co/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "kleaphq-kleap": {
      "type": "remote",
      "url": "https://kleap.co/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add kleaphq-kleap --url 'https://kleap.co/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  kleaphq-kleap:
    url: "https://kleap.co/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "kleaphq-kleap": {
      "Transport": "http",
      "Url": "https://kleap.co/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add kleaphq-kleap -t streamable-http -u 'https://kleap.co/api/mcp'
// mcp.json
{
  "mcpServers": {
    "kleaphq-kleap": {
      "type": "http",
      "url": "https://kleap.co/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 21 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

  • 17 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 0
    • Stability: unverified → 0.03 functional
  • 15 Sept 26 77

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 22 Sept 2026 · Probed https://kleap.co/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=kleap.co CN=WE1,O=Google Trust Services,C=US 23 Aug 2026 21 Nov 2026 ECDSA 256 ECDSA-SHA256 62fe4269212f4ca91398c8acccd60a59
SANs: kleap.co, form.kleap.co, *.form.kleap.co
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of kleap.co. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
co. present 7786 8 Verified
kleap.co. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://kleap.co/.well-known/oauth-protected-resource"

Bearer resource_metadata="https://kleap.co/.well-known/oauth-protected-resource"
Header Value
referrer-policy same-origin

Protected resource metadata

Document https://kleap.co/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://kleap.co/api/mcp
Authorisation server https://kleap.co

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://kleap.co/api/mcp Verified 200
http (plaintext) http://kleap.co/api/mcp HTTPS enforced 301 https://kleap.co/api/mcp
MCP tools · 26 exposed · ~5,493 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
check_domain ~68

Check a domain's connection / DNS status for a Kleap app.

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
domainstringyesThe domain, e.g. 'mybakery.com'
NameTypeReqDescription
checks
domain
message
status
tls
url

No examples provided.

check_task ~350

Check a create/modify task. Returns quickly with the CURRENT status — report it to the user rather than calling again in the same turn; a build takes 5-15 min, so the answer to 'is it ready?' is usually 'still building, here is the progress'. The optional `wait` can shorten the hold but cannot exceed the server cap (8 seconds by default). status is one of: queued, processing, completed, failed, unknown_task (the id is unknown or aged out — that is an answer, not a failure: check the site itself with get_publish_status). On 'completed' the FILES are written; check deployment_status — 'pending' means the site is going live right now and production_url is still the PREVIOUS version, so say 'built, going live' and check once more in about a minute rather than reporting it stuck. 'deployed' means it is genuinely live. On 'failed': TASK_TIMEOUT/STALE_TASK = transient stall → retry_task (returns a NEW task_id to poll); TASK_FAILED = read error.message, retry once. (Out-of-credits is not a task failure — create/modify reject up front with 402 INSUFFICIENT_CREDITS.)

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
task_idstringyesThe task_id returned by create_app or modify_app
waitnumberOptional. Seconds to hold the connection before returning. Capped server-side at a few seconds so the call always comes back inside a single turn — asking for more has no effect. Leave it unset.
NameTypeReqDescription
app_id
deployment_status
metadata
name
palette
plan
preview_url
production_url
progress
reason
result
screenshot_url
slug
status
task_idstring

No examples provided.

connect_domain ~140

Connect a domain the user ALREADY OWNS to a live Kleap app (routing + automatic TLS). The app must be live first — a create_app/modify_app with deployment_status deployed already counts as published, so you do NOT need publish_app first. The user points the domain's A record to Kleap. Does not buy anything.

NameTypeReqDescription
app_idnumberyesThe app id (must be published)
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
domainstringyesThe domain to connect, e.g. 'mybakery.com'
NameTypeReqDescription
already_connected
app_id
dns_config
domain
status
warnings

No examples provided.

connect_search_console ~226

Use this when the user wants to connect (or reconnect) Google Search Console for a site — typically right after get_search_console reported connected:false. Returns a consent_url: give it to the user as a link and ask them to open it and approve access with the Google account that owns the domain in Search Console. That one approval MUST happen in a browser — Google does not allow it any other way, so never claim you can do it for them. Nothing else is needed afterwards: the Search Console property is bound to the site's custom domain automatically, and get_search_console starts answering. If requires_custom_domain is true the site has no custom domain yet: connecting Google would grant access to nothing, so connect a domain first (connect_domain) and publish. If it reports the site is already connected, do not send anyone through consent again — just read the numbers.

NameTypeReqDescription
app_idnumberyesThe app id to connect Search Console for
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
app_idnumber
connectedboolean
consent_url
custom_domain
expires_in_minutesnumber
google_email
message
requires_custom_domainboolean
site_selectedboolean
site_url

No examples provided.

create_app ~208

Use this when the user wants a complete, hosted website or web app built from a text description (e.g. 'build me a website for X'). Kleap's AI builds AND auto-deploys the whole site; this takes a few minutes (typically 5 to 15 min). Returns a build_url instantly so the user can watch it build live. In a widget client (ChatGPT Apps) the preview above shows real-time progress and reveals the final live URL by itself, so you do NOT need to block or keep polling check_task. Prefer this over write_files for full-site creation.

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
promptstringyesDetailed description of the website to build
visibilitystringControls discovery listing: public = discoverable, personal = unlisted. Both may be deployed to a publicly reachable URL; personal does not add access control.
NameTypeReqDescription
app_id
build_urlstring
namestring
statusstring
task_id

No examples provided.

delete_files ~250

Remove pages, components or assets from a site — the counterpart to write_files. Use it when a page should no longer exist: a wrong route, a duplicate, an outdated landing page, an image nobody references. Do NOT overwrite the file with empty content instead: that leaves a URL answering 200 with nothing, which is worse for SEO than a clean 404. Deleting a binary also removes its stored bytes. Paths Kleap owns (astro.config.mjs, package.json, tsconfig.json…) are refused — the build lays its own copy back down, so removing them changes nothing. The homepage (src/pages/index.astro) is refused too: a site with no homepage is broken — write a new one instead, writing replaces it. Returns which paths were actually deleted and which did not exist. The pages STAY LIVE until you call publish_app.

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
pathsarrayyesProject-relative paths to delete, e.g. ["src/pages/old.astro", "public/images/unused.png"]
NameTypeReqDescription
app_idnumber
deleted
missing

No examples provided.

edit_files ~230

Change PART of a file without resending it — the counterpart to write_files. Give `old_string` (exact text as in the file today) and `new_string`; Kleap reads, replaces, stores. Nothing else moves. Use it whenever the file exists and only a line, block or URL changes: resending a 30KB layout to fix one line wastes tokens and risks corrupting the rest. read_files first, copy the text EXACTLY. `old_string` must appear once — otherwise the error names the count; add context or pass replace_all:true. Edits are validated together: if any is invalid, nothing is written. Across files the writes are sequential — a late failure names what was already applied. new_string "" deletes the match. Not for new files or binaries. Then publish_app.

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
editsarrayyesEdits, in order. Validated before any write.
NameTypeReqDescription
app_idnumber
edited
edits
paths

No examples provided.

find_app ~210

Resolve a website the user refers to by its ADDRESS — a custom domain ('mysite.ch'), a kleap.io URL ('mysite.kleap.io'), or a slug — to its app_id. Use this FIRST whenever the user names a site by its address instead of an app_id (e.g. 'edit mysite.ch'), then pass the returned app_id to get_app / modify_app / publish_app. ADDRESS TO SHOW THE USER: site_url. When the owner has connected a domain, custom_domain is set and site_url is that domain — say THAT, never the {slug}.kleap.io host, which is the internal address they did not choose.

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
querystringyesA domain, full URL, or slug — e.g. 'mysite.ch', 'https://mysite.ch', or 'mysite.kleap.io'
NameTypeReqDescription
app_id
custom_domain
foundboolean
matched
name
production_url
querystring
reason
screenshot_url
site_url
slug
status

No examples provided.

generate_image ~400

Put a REAL photo or illustration on the site by describing it — no image bytes to send. Give a vivid `prompt` and a `public/` `path` (e.g. public/hero.jpg); Kleap generates it with Cloudflare FLUX.2 and stores it as a proper binary asset, exactly like write_files with encoding:"base64" but with NO base64 to transmit (a real image's base64 is too big for a model to emit reliably — this is the ONLY dependable way to add a generated picture). Use it for hero photos, section illustrations, onboarding images, OG images, or to replace a broken/ugly image. Square 768×768 by default; pass width/height (256–1440) for other ratios; hd:true uses the premium model (sharper, slower). ⚠️ To REPLACE an existing image, generate to a NEW filename (e.g. hero-2.jpg) and point the markup at it — overwriting the same path can be served stale from CDN/R2 cache. After it returns, call publish_app to deploy it live.

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
hdbooleantrue = premium model (flux-2-dev): sharper, slower. Default = fast klein model.
heightnumberPixel height 256–1440 (default 768).
pathstringyespublic/ image path to create, ending .png/.jpg/.jpeg/.webp (e.g. public/hero.jpg). Use a NEW name to replace an image.
promptstringyesVivid description of the image to generate (subject, mood, lighting, style).
widthnumberPixel width 256–1440 (default 768).
NameTypeReqDescription
bytes
model
path
size

No examples provided.

get_analytics ~189

Use this when the user asks about traffic, visitors, or which pages/referrers are performing on their PUBLISHED site. Backed by the same analytics as the Kleap dashboard's Visitors view. Returns zeroed data with configured:false if the app has never been published (analytics is set up automatically on publish). Requires the analytics:read scope — sessions connected BEFORE this tool shipped don't have it: on a 403 INSUFFICIENT_SCOPE error, tell the user to disconnect and reconnect the Kleap integration (re-authorize) to grant the scope.

NameTypeReqDescription
app_idnumberyesThe app id to fetch analytics for
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
periodstringTime window: '7d' (default), '30d', or '90d'
NameTypeReqDescription
app_idnumber
configuredboolean
pageviewsnumber
period
referrers
top_pages
visitorsnumber

No examples provided.

get_app ~193

Show a website to the user: its screenshot, name and live address. This is the ONE tool that renders the finished-site card, so call it once after a build or edit has finished and deployed (check_task says deployment_status deployed) — that is what lets the user SEE what was built. Also use it for plain details: name, slug, URLs, creation date, status. ADDRESS TO SHOW: site_url. If custom_domain is set, the owner connected that domain and it IS their site's address — never hand them the {slug}.kleap.io host instead, they did not choose it. Never call this while a build is still running: it would show the previous version as if it were the new one.

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
app_id
created_at
custom_domain
custom_domains
name
preview_url
production_url
screenshot_url
site_url
slug
status

No examples provided.

get_credits ~52

Use this when the user asks about their remaining credit balance or plan status.

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
credits
is_paid

No examples provided.

get_form_submissions ~223

Use this when the user asks who filled out their contact form, or wants to see/export leads from their live site. Returns submissions from any <form> built with KleapForm on the app, newest first. Empty list is normal for a brand new site with no visitors yet. Requires the forms:read scope (submissions contain visitor PII) — sessions connected BEFORE this tool shipped don't have it: on a 403 INSUFFICIENT_SCOPE error, tell the user to disconnect and reconnect the Kleap integration (re-authorize) to grant the scope.

NameTypeReqDescription
app_idnumberyesThe app id to fetch submissions for
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
limitnumberMax rows to return (default 20, max 100)
sincestringOnly return submissions at/after this ISO 8601 date, e.g. '2026-06-01T00:00:00Z'
NameTypeReqDescription
app_idnumber
countnumber
submissions

No examples provided.

get_publish_status ~376

Use this to check whether a website is actually published and live. Returns the published state, the live production URL, and — once a publish has run — the PUBLISH REPORT of what Kleap checked on the site it just built: broken_links (existing pages that fail), dead_nav_links (menu entries pointing at a page that was never written — 90% of real dead links, /contact most often), incoherent_pages (a page answering 200 with content that contradicts the link leading to it), checks (source findings that did NOT block the publish, each with a category and a plain sentence: forms that submit into the void, islands with no client directive so buttons do nothing, broken images, hand-rolled auth or unguarded database access, dead API routes), design_gate (was the rendered homepage looked at), live_verified (was the NEW version confirmed serving), and SEO coverage (JSON-LD pages, sitemap URL count, robots, llms.txt). report.checked:true means the audit RAN, so empty lists mean nothing was found, not that nothing was looked at. If finding_count is above zero, tell the user what was found — in the report's own words, not the rule slugs — and offer to fix it. Do NOT describe a publish as clean when the report lists findings: a site can be live, pretty and still take no leads. status is one of: published, deploying, not_published, unknown_app. Returns the state at THIS instant — report it and end the turn; publishing takes minutes, so calling it repeatedly in one turn only burns the turn.

NameTypeReqDescription
app_idnumberyesThe app ID to check
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
app_idnumber
name
production_url
reason
report
screenshot_url
slug
status

No examples provided.

get_screenshot ~144

Use this when the user wants to see a visual screenshot of their website. Rate-limited to 1/min per app. The returned image_url is a PNG on the asset host — render it as an image (![preview](image_url)) and nothing else. It is NOT the website's address, so never present it to the user as their site link, and never open, fetch or web-search it: the site's own address is production_url from get_app / find_app.

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
app_idnumber
height
image_url
name
preview_url
production_url
screenshot_url
slug
statusstring
width

No examples provided.

get_search_console ~308

Use this when the user asks how their site is doing IN GOOGLE SEARCH — keywords/queries they rank for, impressions, clicks from search, CTR, or average position. Backed by their own Google Search Console property (connected per site in Kleap's options), so it is the real Google data, not an estimate. Returns totals plus the top queries and top pages that produced them. Search Console lags real traffic by ~2 days — the newest days are always incomplete, say so rather than reporting a drop. If connected is false or site_selected is false, the site simply has no Search Console hooked up: call connect_search_console(app_id) — it returns a consent_url to hand the user, and that is the whole setup. Do NOT send them hunting through Kleap's settings for it. For visitors and pageviews on the site itself (all sources, not just Google), use get_analytics instead. Requires the analytics:read scope — on a 403 INSUFFICIENT_SCOPE error, tell the user to disconnect and reconnect the Kleap integration (re-authorize).

NameTypeReqDescription
app_idnumberyesThe app id to fetch search data for
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
periodstringTime window: '28d' (default, the window Search Console itself shows), '7d', '30d' or '90d'
NameTypeReqDescription
app_idnumber
clicksnumber
connectedboolean
ctrnumber
has_databoolean
impressionsnumber
message
note
period
positionnumber
site_selectedboolean
site_url
top_pages
top_queries

No examples provided.

list_app_files ~98

List the source file PATHS of an app (names only, no contents). See the project structure, then read_files to get contents before editing. Astro: src/pages/*.astro, src/data/*.json, src/components/*.astro, public/*.

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
app_idnumber
count
files

No examples provided.

list_apps ~84

Use this when the user wants to see all their websites with name, slug, preview URL, and production URL.

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
limitnumberNumber of apps to return (max 100)
offsetnumberPagination offset
NameTypeReqDescription
apps
total

No examples provided.

modify_app ~144

Use this when the user wants to change or update an existing website. The AI can overwrite or remove existing content and automatically publishes the result to the live site. This consumes Kleap credits. Needs the app_id — if the user named the site by its address (e.g. 'mysite.ch'), call find_app first to get the app_id.

NameTypeReqDescription
app_idnumberyesThe app ID to modify
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
messagestringyesWhat to change (e.g. 'Change colors to blue, add a contact form')
NameTypeReqDescription
app_idnumber
deployment_status
message_id
name
palette
plan
preview_url
production_url
screenshot_url
slug
statusstring
task_id

No examples provided.

publish_app ~207

Use this to take a website LIVE at its public URL. Publishing is VERIFIED-LIVE: the app is only reported published once the new version is provably serving — otherwise it reports 'not confirmed live', never a false 'it is online'. Publishing also AUDITS the built site: every internal link on every page, pages whose content contradicts the link leading to them, and JSON-LD/sitemap/robots coverage. That audit comes back through get_publish_status as `report` — read it before telling the user the launch went well, and offer to fix whatever it lists. Returns immediately. Going live takes minutes, so do NOT poll get_publish_status in a loop inside one turn: tell the user it is publishing, and check once with get_publish_status when they ask again.

NameTypeReqDescription
app_idnumberyesThe app ID to publish
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
app_idnumber
deploy_key
poll_url
status

No examples provided.

read_files ~225

Read existing file contents so you can edit them SAFELY instead of rewriting blind (which risks breaking shared components/homepages). Loop: list_app_files → read_files → edit_files (change just the lines that must change) → publish_app; use write_files instead only when you are writing a whole new file. Use it to fix headers/footers, wrong phone numbers, broken links, dead forms. Works with a Read-only key. Returns { files: [{ path, content, type, bytes, truncated?, returned_bytes? }], missing }. Text is capped at 256 KiB per file and 1 MiB per call; truncated files are explicitly marked, and files beyond the call budget must be read separately.

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
pathsarrayyesProject-relative paths to read, from list_app_files (e.g. ['src/components/Header.astro','src/components/Footer.astro'])
NameTypeReqDescription
app_idnumber
filesarray
missingarray

No examples provided.

rename_app ~109

Rename an app's display name. Does NOT change the URL — the live address ({slug}.kleap.io) and any links to it stay intact. (There is no tool to delete the entire app; delete_files removes selected source files.)

NameTypeReqDescription
app_idnumberyesThe app ID to rename
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
namestringyesThe new display name
NameTypeReqDescription
app_id
name
production_url
renamedboolean
slug

No examples provided.

retry_task ~161

Resume a failed or stalled create/modify task from where it stopped — partial files are preserved. Use this when check_task reports 'failed' instead of starting a brand-new create_app. Returns a NEW task_id — poll check_task on that NEW id (not the original). Budget: retry TASK_TIMEOUT/STALE_TASK up to TWICE; retry TASK_FAILED only ONCE; then stop and tell the user. NEVER retry a non-transient error (402 INSUFFICIENT_CREDITS, a rejected prompt).

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
task_idstringyesThe failed task_id to resume (from create_app/modify_app)
NameTypeReqDescription
app_id
attempt
files_preserved
parent_task_id
statusstring
task_id

No examples provided.

search_domains ~140

Search for available domains for a site (e.g. 'mybakery'). Returns available names across TLDs. NOTE: agents cannot buy a domain — purchase is confirmed by the user in Kleap. Use connect_domain for a domain the user already owns.

NameTypeReqDescription
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
querystringyesBase name to search, without a TLD (e.g. 'mybakery')
tldsarrayOptional TLDs to check, e.g. ['.com', '.io', '.ch']
NameTypeReqDescription
querystring
results

No examples provided.

wake_app ~78

Use this when the user's website preview is sleeping (sandboxes auto-stop after 15 min). Takes ~30-60s to restart.

NameTypeReqDescription
app_idnumberyesThe app ID to wake up
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
NameTypeReqDescription
app_idnumber
preview_url
statusstring

No examples provided.

write_files ~680

Write WHOLE files DIRECTLY — YOUR model generates the code, Kleap stores, builds and deploys it as-is. To change something in a file that ALREADY EXISTS, use edit_files instead (read_files → edit_files): it replaces just the lines you name, while write_files makes you retype the entire file and silently drops whatever you leave out — on a 30KB shared layout that is how headers and footers get wiped. No Kleap-AI step, so what ships is byte-for-byte what you wrote — the right choice when a phrase, a URL or a schema must be exact. Publishing still audits the result (see publish_app). Best for scaffolding exact pages/components — e.g. programmatic-SEO routes. Astro paths (src/pages/*.astro, src/data/*.json, src/components/*.astro, public/*). Overwrites by path. NPM PACKAGES: do not write package.json (the build replaces it) — the build installs whatever your code IMPORTS, so `import { jsPDF } from "jspdf";` is all it takes. Supported on import: @tiptap/*, jspdf, pdf-lib, html2canvas, papaparse, file-saver, jszip, @ffmpeg/*, howler, wavesurfer.js, browser-image-compression, react-dropzone, recharts, chart.js, d3, @tanstack/*, react-hook-form, three, @react-three/*, leaflet, maplibre-gl, gsap, framer-motion, zustand, date-fns, react-markdown, axios, socket.io-client, radix-ui/*, next-themes, lucide-react, @tabler/*, openai, @ai-sdk/*; anything else is refused at build with a message naming it. A client-side router is never the answer — a route is a FILE (src/pages/about.astro → /about). IMAGES AND BINARIES: set encoding:"base64" on the file and send the bytes — that is how you put a logo, a photo, an OG image, a favicon or a font on the site (png/jpg/webp/svg/ico/mp4/woff2/pdf, 512KB max each decoded). Without it you can only write text, and a site with no images looks unfinished. To ADD an image from a text prompt WITHOUT sending any bytes (a real photo's base64 is too big to emit reliably), use generate_image — Kleap generates it and stores it for you. To REMOVE a page…

NameTypeReqDescription
app_idnumberyesThe app ID
contextstringyesWhy this call, in one short sentence. Used to improve the connector; never include credentials or personal data.
filesarrayyesFiles to write/overwrite: [{ path, content, encoding? }]
NameTypeReqDescription
app_idnumber
binary
paths
written

No examples provided.

Common questions

What is the Kleap MCP server?

Kleap is an MCP server listed in the public MCP registry as io.github.kleaphq/kleap. Build, edit, publish, and manage websites and web apps with Kleap hosting, domains, and analytics. This page covers its hosted endpoint (https://kleap.co/api/mcp).

Is the Kleap MCP server safe to use?

Kleap scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Kleap MCP server expose?

Kleap exposes 26 tools: create_app, modify_app, write_files, edit_files, generate_image, and 21 more. Their descriptions and schemas cost roughly 5,493 tokens of context every time the server is loaded.

Does the Kleap MCP server require authentication?

Yes. Kleap asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the Kleap MCP server still maintained?

Kleap is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.