Kleap
REMOTE · KLEAP.CO · SCANNED SEP 22
Build, edit, publish, and manage websites and web apps with Kleap hosting, domains, and analytics.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 7582 tokens (~261/item across 29 items; 26 tools + 3 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
- Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety92
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 2 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "get_publish_status" implies "publish" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
- An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
How do I install the Kleap MCP server?
Kleap is a hosted endpoint at https://kleap.co/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · kleap.co
claude mcp add --transport http kleaphq-kleap 'https://kleap.co/api/mcp'
{
"mcpServers": {
"kleaphq-kleap": {
"url": "https://kleap.co/api/mcp"
}
}
} {
"servers": {
"kleaphq-kleap": {
"type": "http",
"url": "https://kleap.co/api/mcp"
}
}
} [mcp_servers.kleaphq-kleap] url = "https://kleap.co/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"kleaphq-kleap": {
"type": "remote",
"url": "https://kleap.co/api/mcp",
"enabled": true
}
}
} openclaw mcp add kleaphq-kleap --url 'https://kleap.co/api/mcp' --transport streamable-http
mcp_servers:
kleaphq-kleap:
url: "https://kleap.co/api/mcp" {
"McpServers": {
"kleaphq-kleap": {
"Transport": "http",
"Url": "https://kleap.co/api/mcp"
}
}
} assistant mcp add kleaphq-kleap -t streamable-http -u 'https://kleap.co/api/mcp'
{
"mcpServers": {
"kleaphq-kleap": {
"type": "http",
"url": "https://kleap.co/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 15 Sept 26 77
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://kleap.co/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=kleap.co | CN=WE1,O=Google Trust Services,C=US | 23 Aug 2026 | 21 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 62fe4269212f4ca91398c8acccd60a59 |
| SANs: kleap.co, form.kleap.co, *.form.kleap.co | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of kleap.co. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| co. | present | 7786 | 8 | Verified |
| kleap.co. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://kleap.co/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://kleap.co/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| referrer-policy | same-origin |
Protected resource metadata
| Document | https://kleap.co/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://kleap.co/api/mcp |
| Authorisation server | https://kleap.co |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://kleap.co/api/mcp | Verified | 200 | |
| http (plaintext) | http://kleap.co/api/mcp | HTTPS enforced | 301 | https://kleap.co/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_domain Check Domain ~68
Check a domain's connection / DNS status for a Kleap app.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| domain | string | yes | The domain, e.g. 'mybakery.com' |
| Name | Type | Req | Description |
|---|---|---|---|
| checks | – | – | – |
| domain | – | – | – |
| message | – | – | – |
| status | – | – | – |
| tls | – | – | – |
| url | – | – | – |
No examples provided.
check_task Check Build Status ~350
Check a create/modify task. Returns quickly with the CURRENT status — report it to the user rather than calling again in the same turn; a build takes 5-15 min, so the answer to 'is it ready?' is usually 'still building, here is the progress'. The optional `wait` can shorten the hold but cannot exceed the server cap (8 seconds by default). status is one of: queued, processing, completed, failed, unknown_task (the id is unknown or aged out — that is an answer, not a failure: check the site itself with get_publish_status). On 'completed' the FILES are written; check deployment_status — 'pending' means the site is going live right now and production_url is still the PREVIOUS version, so say 'built, going live' and check once more in about a minute rather than reporting it stuck. 'deployed' means it is genuinely live. On 'failed': TASK_TIMEOUT/STALE_TASK = transient stall → retry_task (returns a NEW task_id to poll); TASK_FAILED = read error.message, retry once. (Out-of-credits is not a task failure — create/modify reject up front with 402 INSUFFICIENT_CREDITS.)
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| task_id | string | yes | The task_id returned by create_app or modify_app |
| wait | number | – | Optional. Seconds to hold the connection before returning. Capped server-side at a few seconds so the call always comes back inside a single turn — asking for more has no effect. Leave it unset. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | – | – | – |
| deployment_status | – | – | – |
| metadata | – | – | – |
| name | – | – | – |
| palette | – | – | – |
| plan | – | – | – |
| preview_url | – | – | – |
| production_url | – | – | – |
| progress | – | – | – |
| reason | – | – | – |
| result | – | – | – |
| screenshot_url | – | – | – |
| slug | – | – | – |
| status | – | – | – |
| task_id | string | – | – |
No examples provided.
connect_domain Connect Domain ~140
Connect a domain the user ALREADY OWNS to a live Kleap app (routing + automatic TLS). The app must be live first — a create_app/modify_app with deployment_status deployed already counts as published, so you do NOT need publish_app first. The user points the domain's A record to Kleap. Does not buy anything.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app id (must be published) |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| domain | string | yes | The domain to connect, e.g. 'mybakery.com' |
| Name | Type | Req | Description |
|---|---|---|---|
| already_connected | – | – | – |
| app_id | – | – | – |
| dns_config | – | – | – |
| domain | – | – | – |
| status | – | – | – |
| warnings | – | – | – |
No examples provided.
connect_search_console Connect Google Search Console ~226
Use this when the user wants to connect (or reconnect) Google Search Console for a site — typically right after get_search_console reported connected:false. Returns a consent_url: give it to the user as a link and ask them to open it and approve access with the Google account that owns the domain in Search Console. That one approval MUST happen in a browser — Google does not allow it any other way, so never claim you can do it for them. Nothing else is needed afterwards: the Search Console property is bound to the site's custom domain automatically, and get_search_console starts answering. If requires_custom_domain is true the site has no custom domain yet: connecting Google would grant access to nothing, so connect a domain first (connect_domain) and publish. If it reports the site is already connected, do not send anyone through consent again — just read the numbers.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app id to connect Search Console for |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| connected | boolean | – | – |
| consent_url | – | – | – |
| custom_domain | – | – | – |
| expires_in_minutes | number | – | – |
| google_email | – | – | – |
| message | – | – | – |
| requires_custom_domain | boolean | – | – |
| site_selected | boolean | – | – |
| site_url | – | – | – |
No examples provided.
create_app Create Website ~208
Use this when the user wants a complete, hosted website or web app built from a text description (e.g. 'build me a website for X'). Kleap's AI builds AND auto-deploys the whole site; this takes a few minutes (typically 5 to 15 min). Returns a build_url instantly so the user can watch it build live. In a widget client (ChatGPT Apps) the preview above shows real-time progress and reveals the final live URL by itself, so you do NOT need to block or keep polling check_task. Prefer this over write_files for full-site creation.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| prompt | string | yes | Detailed description of the website to build |
| visibility | string | – | Controls discovery listing: public = discoverable, personal = unlisted. Both may be deployed to a publicly reachable URL; personal does not add access control. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | – | – | – |
| build_url | string | – | – |
| name | string | – | – |
| status | string | – | – |
| task_id | – | – | – |
No examples provided.
delete_files Delete Files ~250
Remove pages, components or assets from a site — the counterpart to write_files. Use it when a page should no longer exist: a wrong route, a duplicate, an outdated landing page, an image nobody references. Do NOT overwrite the file with empty content instead: that leaves a URL answering 200 with nothing, which is worse for SEO than a clean 404. Deleting a binary also removes its stored bytes. Paths Kleap owns (astro.config.mjs, package.json, tsconfig.json…) are refused — the build lays its own copy back down, so removing them changes nothing. The homepage (src/pages/index.astro) is refused too: a site with no homepage is broken — write a new one instead, writing replaces it. Returns which paths were actually deleted and which did not exist. The pages STAY LIVE until you call publish_app.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| paths | array | yes | Project-relative paths to delete, e.g. ["src/pages/old.astro", "public/images/unused.png"] |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| deleted | – | – | – |
| missing | – | – | – |
No examples provided.
edit_files Edit Files In Place ~230
Change PART of a file without resending it — the counterpart to write_files. Give `old_string` (exact text as in the file today) and `new_string`; Kleap reads, replaces, stores. Nothing else moves. Use it whenever the file exists and only a line, block or URL changes: resending a 30KB layout to fix one line wastes tokens and risks corrupting the rest. read_files first, copy the text EXACTLY. `old_string` must appear once — otherwise the error names the count; add context or pass replace_all:true. Edits are validated together: if any is invalid, nothing is written. Across files the writes are sequential — a late failure names what was already applied. new_string "" deletes the match. Not for new files or binaries. Then publish_app.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| edits | array | yes | Edits, in order. Validated before any write. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| edited | – | – | – |
| edits | – | – | – |
| paths | – | – | – |
No examples provided.
find_app Find Website by Address ~210
Resolve a website the user refers to by its ADDRESS — a custom domain ('mysite.ch'), a kleap.io URL ('mysite.kleap.io'), or a slug — to its app_id. Use this FIRST whenever the user names a site by its address instead of an app_id (e.g. 'edit mysite.ch'), then pass the returned app_id to get_app / modify_app / publish_app. ADDRESS TO SHOW THE USER: site_url. When the owner has connected a domain, custom_domain is set and site_url is that domain — say THAT, never the {slug}.kleap.io host, which is the internal address they did not choose.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| query | string | yes | A domain, full URL, or slug — e.g. 'mysite.ch', 'https://mysite.ch', or 'mysite.kleap.io' |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | – | – | – |
| custom_domain | – | – | – |
| found | boolean | – | – |
| matched | – | – | – |
| name | – | – | – |
| production_url | – | – | – |
| query | string | – | – |
| reason | – | – | – |
| screenshot_url | – | – | – |
| site_url | – | – | – |
| slug | – | – | – |
| status | – | – | – |
No examples provided.
generate_image Generate Image ~400
Put a REAL photo or illustration on the site by describing it — no image bytes to send. Give a vivid `prompt` and a `public/` `path` (e.g. public/hero.jpg); Kleap generates it with Cloudflare FLUX.2 and stores it as a proper binary asset, exactly like write_files with encoding:"base64" but with NO base64 to transmit (a real image's base64 is too big for a model to emit reliably — this is the ONLY dependable way to add a generated picture). Use it for hero photos, section illustrations, onboarding images, OG images, or to replace a broken/ugly image. Square 768×768 by default; pass width/height (256–1440) for other ratios; hd:true uses the premium model (sharper, slower). ⚠️ To REPLACE an existing image, generate to a NEW filename (e.g. hero-2.jpg) and point the markup at it — overwriting the same path can be served stale from CDN/R2 cache. After it returns, call publish_app to deploy it live.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| hd | boolean | – | true = premium model (flux-2-dev): sharper, slower. Default = fast klein model. |
| height | number | – | Pixel height 256–1440 (default 768). |
| path | string | yes | public/ image path to create, ending .png/.jpg/.jpeg/.webp (e.g. public/hero.jpg). Use a NEW name to replace an image. |
| prompt | string | yes | Vivid description of the image to generate (subject, mood, lighting, style). |
| width | number | – | Pixel width 256–1440 (default 768). |
| Name | Type | Req | Description |
|---|---|---|---|
| bytes | – | – | – |
| model | – | – | – |
| path | – | – | – |
| size | – | – | – |
No examples provided.
get_analytics Get Site Analytics ~189
Use this when the user asks about traffic, visitors, or which pages/referrers are performing on their PUBLISHED site. Backed by the same analytics as the Kleap dashboard's Visitors view. Returns zeroed data with configured:false if the app has never been published (analytics is set up automatically on publish). Requires the analytics:read scope — sessions connected BEFORE this tool shipped don't have it: on a 403 INSUFFICIENT_SCOPE error, tell the user to disconnect and reconnect the Kleap integration (re-authorize) to grant the scope.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app id to fetch analytics for |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| period | string | – | Time window: '7d' (default), '30d', or '90d' |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| configured | boolean | – | – |
| pageviews | number | – | – |
| period | – | – | – |
| referrers | – | – | – |
| top_pages | – | – | – |
| visitors | number | – | – |
No examples provided.
get_app Get Website Details ~193
Show a website to the user: its screenshot, name and live address. This is the ONE tool that renders the finished-site card, so call it once after a build or edit has finished and deployed (check_task says deployment_status deployed) — that is what lets the user SEE what was built. Also use it for plain details: name, slug, URLs, creation date, status. ADDRESS TO SHOW: site_url. If custom_domain is set, the owner connected that domain and it IS their site's address — never hand them the {slug}.kleap.io host instead, they did not choose it. Never call this while a build is still running: it would show the previous version as if it were the new one.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | – | – | – |
| created_at | – | – | – |
| custom_domain | – | – | – |
| custom_domains | – | – | – |
| name | – | – | – |
| preview_url | – | – | – |
| production_url | – | – | – |
| screenshot_url | – | – | – |
| site_url | – | – | – |
| slug | – | – | – |
| status | – | – | – |
No examples provided.
get_credits Check Credits ~52
Use this when the user asks about their remaining credit balance or plan status.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| credits | – | – | – |
| is_paid | – | – | – |
No examples provided.
get_form_submissions Get Form Submissions ~223
Use this when the user asks who filled out their contact form, or wants to see/export leads from their live site. Returns submissions from any <form> built with KleapForm on the app, newest first. Empty list is normal for a brand new site with no visitors yet. Requires the forms:read scope (submissions contain visitor PII) — sessions connected BEFORE this tool shipped don't have it: on a 403 INSUFFICIENT_SCOPE error, tell the user to disconnect and reconnect the Kleap integration (re-authorize) to grant the scope.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app id to fetch submissions for |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| limit | number | – | Max rows to return (default 20, max 100) |
| since | string | – | Only return submissions at/after this ISO 8601 date, e.g. '2026-06-01T00:00:00Z' |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| count | number | – | – |
| submissions | – | – | – |
No examples provided.
get_publish_status Check Publish Status ~376
Use this to check whether a website is actually published and live. Returns the published state, the live production URL, and — once a publish has run — the PUBLISH REPORT of what Kleap checked on the site it just built: broken_links (existing pages that fail), dead_nav_links (menu entries pointing at a page that was never written — 90% of real dead links, /contact most often), incoherent_pages (a page answering 200 with content that contradicts the link leading to it), checks (source findings that did NOT block the publish, each with a category and a plain sentence: forms that submit into the void, islands with no client directive so buttons do nothing, broken images, hand-rolled auth or unguarded database access, dead API routes), design_gate (was the rendered homepage looked at), live_verified (was the NEW version confirmed serving), and SEO coverage (JSON-LD pages, sitemap URL count, robots, llms.txt). report.checked:true means the audit RAN, so empty lists mean nothing was found, not that nothing was looked at. If finding_count is above zero, tell the user what was found — in the report's own words, not the rule slugs — and offer to fix it. Do NOT describe a publish as clean when the report lists findings: a site can be live, pretty and still take no leads. status is one of: published, deploying, not_published, unknown_app. Returns the state at THIS instant — report it and end the turn; publishing takes minutes, so calling it repeatedly in one turn only burns the turn.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID to check |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| name | – | – | – |
| production_url | – | – | – |
| reason | – | – | – |
| report | – | – | – |
| screenshot_url | – | – | – |
| slug | – | – | – |
| status | – | – | – |
No examples provided.
get_screenshot Screenshot Website ~144
Use this when the user wants to see a visual screenshot of their website. Rate-limited to 1/min per app. The returned image_url is a PNG on the asset host — render it as an image () and nothing else. It is NOT the website's address, so never present it to the user as their site link, and never open, fetch or web-search it: the site's own address is production_url from get_app / find_app.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| height | – | – | – |
| image_url | – | – | – |
| name | – | – | – |
| preview_url | – | – | – |
| production_url | – | – | – |
| screenshot_url | – | – | – |
| slug | – | – | – |
| status | string | – | – |
| width | – | – | – |
No examples provided.
get_search_console Get Google Search Performance ~308
Use this when the user asks how their site is doing IN GOOGLE SEARCH — keywords/queries they rank for, impressions, clicks from search, CTR, or average position. Backed by their own Google Search Console property (connected per site in Kleap's options), so it is the real Google data, not an estimate. Returns totals plus the top queries and top pages that produced them. Search Console lags real traffic by ~2 days — the newest days are always incomplete, say so rather than reporting a drop. If connected is false or site_selected is false, the site simply has no Search Console hooked up: call connect_search_console(app_id) — it returns a consent_url to hand the user, and that is the whole setup. Do NOT send them hunting through Kleap's settings for it. For visitors and pageviews on the site itself (all sources, not just Google), use get_analytics instead. Requires the analytics:read scope — on a 403 INSUFFICIENT_SCOPE error, tell the user to disconnect and reconnect the Kleap integration (re-authorize).
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app id to fetch search data for |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| period | string | – | Time window: '28d' (default, the window Search Console itself shows), '7d', '30d' or '90d' |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| clicks | number | – | – |
| connected | boolean | – | – |
| ctr | number | – | – |
| has_data | boolean | – | – |
| impressions | number | – | – |
| message | – | – | – |
| note | – | – | – |
| period | – | – | – |
| position | number | – | – |
| site_selected | boolean | – | – |
| site_url | – | – | – |
| top_pages | – | – | – |
| top_queries | – | – | – |
No examples provided.
list_app_files List App Files ~98
List the source file PATHS of an app (names only, no contents). See the project structure, then read_files to get contents before editing. Astro: src/pages/*.astro, src/data/*.json, src/components/*.astro, public/*.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| count | – | – | – |
| files | – | – | – |
No examples provided.
list_apps List My Websites ~84
Use this when the user wants to see all their websites with name, slug, preview URL, and production URL.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| limit | number | – | Number of apps to return (max 100) |
| offset | number | – | Pagination offset |
| Name | Type | Req | Description |
|---|---|---|---|
| apps | – | – | – |
| total | – | – | – |
No examples provided.
modify_app Modify Website ~144
Use this when the user wants to change or update an existing website. The AI can overwrite or remove existing content and automatically publishes the result to the live site. This consumes Kleap credits. Needs the app_id — if the user named the site by its address (e.g. 'mysite.ch'), call find_app first to get the app_id.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID to modify |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| message | string | yes | What to change (e.g. 'Change colors to blue, add a contact form') |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| deployment_status | – | – | – |
| message_id | – | – | – |
| name | – | – | – |
| palette | – | – | – |
| plan | – | – | – |
| preview_url | – | – | – |
| production_url | – | – | – |
| screenshot_url | – | – | – |
| slug | – | – | – |
| status | string | – | – |
| task_id | – | – | – |
No examples provided.
publish_app Publish Website ~207
Use this to take a website LIVE at its public URL. Publishing is VERIFIED-LIVE: the app is only reported published once the new version is provably serving — otherwise it reports 'not confirmed live', never a false 'it is online'. Publishing also AUDITS the built site: every internal link on every page, pages whose content contradicts the link leading to them, and JSON-LD/sitemap/robots coverage. That audit comes back through get_publish_status as `report` — read it before telling the user the launch went well, and offer to fix whatever it lists. Returns immediately. Going live takes minutes, so do NOT poll get_publish_status in a loop inside one turn: tell the user it is publishing, and check once with get_publish_status when they ask again.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID to publish |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| deploy_key | – | – | – |
| poll_url | – | – | – |
| status | – | – | – |
No examples provided.
read_files Read File Contents ~225
Read existing file contents so you can edit them SAFELY instead of rewriting blind (which risks breaking shared components/homepages). Loop: list_app_files → read_files → edit_files (change just the lines that must change) → publish_app; use write_files instead only when you are writing a whole new file. Use it to fix headers/footers, wrong phone numbers, broken links, dead forms. Works with a Read-only key. Returns { files: [{ path, content, type, bytes, truncated?, returned_bytes? }], missing }. Text is capped at 256 KiB per file and 1 MiB per call; truncated files are explicitly marked, and files beyond the call budget must be read separately.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| paths | array | yes | Project-relative paths to read, from list_app_files (e.g. ['src/components/Header.astro','src/components/Footer.astro']) |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| files | array | – | – |
| missing | array | – | – |
No examples provided.
rename_app Rename Website ~109
Rename an app's display name. Does NOT change the URL — the live address ({slug}.kleap.io) and any links to it stay intact. (There is no tool to delete the entire app; delete_files removes selected source files.)
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID to rename |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| name | string | yes | The new display name |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | – | – | – |
| name | – | – | – |
| production_url | – | – | – |
| renamed | boolean | – | – |
| slug | – | – | – |
No examples provided.
retry_task Retry Build ~161
Resume a failed or stalled create/modify task from where it stopped — partial files are preserved. Use this when check_task reports 'failed' instead of starting a brand-new create_app. Returns a NEW task_id — poll check_task on that NEW id (not the original). Budget: retry TASK_TIMEOUT/STALE_TASK up to TWICE; retry TASK_FAILED only ONCE; then stop and tell the user. NEVER retry a non-transient error (402 INSUFFICIENT_CREDITS, a rejected prompt).
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| task_id | string | yes | The failed task_id to resume (from create_app/modify_app) |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | – | – | – |
| attempt | – | – | – |
| files_preserved | – | – | – |
| parent_task_id | – | – | – |
| status | string | – | – |
| task_id | – | – | – |
No examples provided.
search_domains Search Domains ~140
Search for available domains for a site (e.g. 'mybakery'). Returns available names across TLDs. NOTE: agents cannot buy a domain — purchase is confirmed by the user in Kleap. Use connect_domain for a domain the user already owns.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| query | string | yes | Base name to search, without a TLD (e.g. 'mybakery') |
| tlds | array | – | Optional TLDs to check, e.g. ['.com', '.io', '.ch'] |
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | – | – |
| results | – | – | – |
No examples provided.
wake_app Wake Website ~78
Use this when the user's website preview is sleeping (sandboxes auto-stop after 15 min). Takes ~30-60s to restart.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID to wake up |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| preview_url | – | – | – |
| status | string | – | – |
No examples provided.
write_files Write Files Directly ~680
Write WHOLE files DIRECTLY — YOUR model generates the code, Kleap stores, builds and deploys it as-is. To change something in a file that ALREADY EXISTS, use edit_files instead (read_files → edit_files): it replaces just the lines you name, while write_files makes you retype the entire file and silently drops whatever you leave out — on a 30KB shared layout that is how headers and footers get wiped. No Kleap-AI step, so what ships is byte-for-byte what you wrote — the right choice when a phrase, a URL or a schema must be exact. Publishing still audits the result (see publish_app). Best for scaffolding exact pages/components — e.g. programmatic-SEO routes. Astro paths (src/pages/*.astro, src/data/*.json, src/components/*.astro, public/*). Overwrites by path. NPM PACKAGES: do not write package.json (the build replaces it) — the build installs whatever your code IMPORTS, so `import { jsPDF } from "jspdf";` is all it takes. Supported on import: @tiptap/*, jspdf, pdf-lib, html2canvas, papaparse, file-saver, jszip, @ffmpeg/*, howler, wavesurfer.js, browser-image-compression, react-dropzone, recharts, chart.js, d3, @tanstack/*, react-hook-form, three, @react-three/*, leaflet, maplibre-gl, gsap, framer-motion, zustand, date-fns, react-markdown, axios, socket.io-client, radix-ui/*, next-themes, lucide-react, @tabler/*, openai, @ai-sdk/*; anything else is refused at build with a message naming it. A client-side router is never the answer — a route is a FILE (src/pages/about.astro → /about). IMAGES AND BINARIES: set encoding:"base64" on the file and send the bytes — that is how you put a logo, a photo, an OG image, a favicon or a font on the site (png/jpg/webp/svg/ico/mp4/woff2/pdf, 512KB max each decoded). Without it you can only write text, and a site with no images looks unfinished. To ADD an image from a text prompt WITHOUT sending any bytes (a real photo's base64 is too big to emit reliably), use generate_image — Kleap generates it and stores it for you. To REMOVE a page…
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | yes | The app ID |
| context | string | yes | Why this call, in one short sentence. Used to improve the connector; never include credentials or personal data. |
| files | array | yes | Files to write/overwrite: [{ path, content, encoding? }] |
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | number | – | – |
| binary | – | – | – |
| paths | – | – | – |
| written | – | – | – |
No examples provided.
What is the Kleap MCP server?
Kleap is an MCP server listed in the public MCP registry as io.github.kleaphq/kleap. Build, edit, publish, and manage websites and web apps with Kleap hosting, domains, and analytics. This page covers its hosted endpoint (https://kleap.co/api/mcp).
Is the Kleap MCP server safe to use?
Kleap scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Kleap MCP server expose?
Kleap exposes 26 tools: create_app, modify_app, write_files, edit_files, generate_image, and 21 more. Their descriptions and schemas cost roughly 5,493 tokens of context every time the server is loaded.
Does the Kleap MCP server require authentication?
Yes. Kleap asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Kleap MCP server still maintained?
Kleap is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.