# Sakupa (npm · @sakupa/mcp)

Publish and manage AI-made static websites from your AI tool: free previews, hosting, domains.

- Trust score: 67/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- npm · `@sakupa/mcp`: 67/100 (this document), [markdown](https://verifymcp.io/servers/myerwang-sakupa/sakupa-mcp.md), [page](https://verifymcp.io/servers/myerwang-sakupa/sakupa-mcp)

## Channel facts

- Registry: `npm`
- Package: `@sakupa/mcp`
- Version: `1.6.2`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 100/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 0 of 3 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 6/100
  - Repository check failed: no source repository is declared.
  - Provenance check failed: no build-provenance attestation is published.
  - License check failed: no license is declared.
  - Actively maintained (last published 13 days ago).
  - Security-disclosure policy not yet verified: we couldn't inspect the source repository.
- **Schema Quality & AI Usability**: 63/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 5367 tokens (~298/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 50/100
  - Stability observed for 15 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 92/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 72% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Sakupa MCP server?

Sakupa runs locally as an npm package, launched with npx -y @sakupa/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add myerwang-sakupa -- npx -y @sakupa/mcp
```

### Cursor

```json
{
  "mcpServers": {
    "myerwang-sakupa": {
      "command": "npx",
      "args": [
        "-y",
        "@sakupa/mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "myerwang-sakupa": {
      "command": "npx",
      "args": [
        "-y",
        "@sakupa/mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add myerwang-sakupa -- npx -y @sakupa/mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "myerwang-sakupa": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@sakupa/mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add myerwang-sakupa --command npx --arg -y --arg @sakupa/mcp
```

### Hermes

```yaml
mcp_servers:
  myerwang-sakupa:
    command: "npx"
    args: ["-y", "@sakupa/mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "myerwang-sakupa": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@sakupa/mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add myerwang-sakupa -t stdio -c npx -a -y @sakupa/mcp
```

### Other

```json
{
  "mcpServers": {
    "myerwang-sakupa": {
      "command": "npx",
      "args": [
        "-y",
        "@sakupa/mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-20 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 47 to 50. That category is still filling its 30-day observation window: 14 days of observed history at the previous scan, 15 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-13 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-11 (score 63, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-09 (score 62, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-08 (score 61, +26)

- [security improvement] Malware scan: unverified → pass
- [security improvement] Known CVEs: unverified → pass
- [functional improvement] Dependency health: unverified → 1.00

### 2026-09-07 (score 35, −25)

- [security regression] Known CVEs: pass → unverified
- [security regression] Malware scan: pass → unverified
- [functional regression] Schema quality: 4389 → 5367
- [functional regression] Schema quality: 4389 → 5174
- [functional regression] Schema quality: 4389 → 4867
- [functional regression] Dependency health: 1.00 → unverified
- [functional improvement] Tool coverage: 67% → 72%
- [functional improvement] Stability: unverified → 0.07
- [functional] Package version: 1.3.0 → 1.6.2
- [functional] Package version: 1.3.0 → 1.6.1
- [functional] Package version: 1.3.0 → 1.5.1
- [functional] Package version: 1.3.0 → 1.4.0

## MCP tools (18)

### `analyze` (~113 tokens)

Analyze project

Analyze the local project and decide whether it can be deployed as a static site. Detects the framework, the built static output directory (dist/build/out/...), missing index.html, SSR/API-route/database-runtime risks, SPA fallback needs, forbidden files (secrets, .env, archives, media) and size limits. Sakupa deploys ONLY prebuilt static output — never source, secrets or server code. Run this before deploy.

Input parameters:

- `outputDir` (string): Output directory relative to the project root (overrides detection).

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `deploy` (~502 tokens)

Deploy site

Deploy the local static output to Sakupa. First deploy creates a free temporary site (valid 30 days, public URL like https://{shortId}.sakupa.com) and stores the management credential in .sakupa/site.json. Later runs update the existing site (free sites also refresh their validity; subscription-backed sites have no free-site expiry while the subscription remains active). Runs analyze first and refuses to upload source projects, secrets, .env files, archives, media or server code. The MCP process is locked to the current directory initialized by the no-argument init MCP tool; no tool argument can change that root. outputDir is a separate REQUIRED relative path supplied from the current project inspection. Never uploads anything when analysis says the project is not deployable.

Input parameters:

- `lang` (string): Site language override (en | ja | zh-CN); defaults to the html lang.
- `outputDir` (string, required): REQUIRED: exact publish directory relative to the initialized project root, supplied by the AI after inspecting this project (for example ".", "dist", "html", or any custom build directory). Sakupa a…
- `outputDirChangeConfirmed` (boolean): Required only when changing the previously successful publish directory. Confirm only after showing the old and new directories to the user.
- `publicConfirmed` (boolean): Required only for the first deployment: user explicitly confirmed creation of a public URL valid for the free-site window.
- `reuseConfirmed` (boolean): True only after the user selected reuseSiteUrl knowing its online content will be replaced and its previous project will be unbound.
- `reuseSiteUrl` (string): Exact existing free-site URL selected by the user when the three-site free-site allowance is full. Never invent this value; copy it from deploy nextActions.
- `sakupaRelocationConfirmed` (boolean): Required only when a nested directory is itself initialized with .sakupa/project.json. Confirm only after showing the source and authoritative project Root; Sakupa then migrates non-conflicting state…
- `spaFallback` (boolean): Override automatic SPA-fallback detection (single index.html + JS auto-enables rewriting unknown paths to index.html; multiple HTML pages auto-disable it). Pass only to force the behavior against the…
- `subprojectConfirmed` (boolean): Deprecated compatibility field. Project independence is established only by `sakupa-mcp init`, never inferred from package.json or folder names.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `refresh` (~48 tokens)

Refresh free site

Refresh the validity of the free temporary site WITHOUT uploading content. Uses the local credential in .sakupa/site.json. Subscription-backed sites have no free-site expiry while the subscription remains active and need no refresh.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `status` (~70 tokens)

Site status

Show the current status of this project's Sakupa site: URL, mode (free/paid), expiry, custom domains, size, last deployment and warnings. For a paid site this tool also automatically returns the complete authoritative billing snapshot; users never need to know or name a separate billing tool to get accurate subscription information.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `subscribe` (~222 tokens)

Subscribe (Stripe Checkout)

Create a Stripe Checkout link that subscribes THIS site to a Sakupa Hosting monthly plan (water JPY 200/month, personal JPY 500/month, share JPY 1000/month, business JPY 2000/month). While the subscription remains active, its {shortId}.sakupa.com URL stays live without the free 30-day expiry. Binding a custom domain afterwards (bind) is an optional included extra and requires DNS control of that domain. Owner-only: requires this project's site credential (.sakupa/site.json) — deploy first. If the site outgrows its plan, Sakupa shows an over-limit notice and never changes billing automatically. The owner can explicitly choose another plan through Stripe Customer Portal. Card details are entered only on the Stripe-hosted page — never through the AI tool. Opening and completing Stripe Checkout is the final subscription confirmation.

Input parameters:

- `plan` (string, required): Monthly plan: water (very light personal pages), personal (personal brand / small shop), share (small-business site), business (steadier traffic, more headroom).

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `bind` (~263 tokens)

Bind custom domain

Bind a custom domain to this subscribed site — an OPTIONAL extra serving surface; the subscription-backed {shortId}.sakupa.com URL keeps working alongside it while the subscription is active. The binding unit is the APEX domain: binding example.com reserves routes for example.com and www.example.com, but ONLY www is required and judged for activation; the naked apex is optional because many DNS providers cannot point it. One apex TXT verification covers both. A site has one FINAL apex domain; starting a different apex begins a zero-downtime switch and the previous domain remains until the new www is live. The www CNAME must remain while bound. Requires an ACTIVE subscription (subscribe). Ownership is proven ONLY by DNS control of the apex — payment never grants ownership, and bindings are ALWAYS challengeable: whoever proves CURRENT DNS control takes the domain, even from an existing binding (the displaced site keeps its subscription, content and subscription-backed Sakupa URL). Unverified requests expire after 72 hours. Call again with action "status" to check progress.

Input parameters:

- `action` (string, required)
- `hostname` (string): Required for start.
- `verificationId` (string): Optional for status: when omitted, the server finds this site's latest binding verification — a NEW session can resume without it.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `billing` (~72 tokens)

Billing snapshot

Return the sole authoritative source for this site's hosting subscription: current plan, next renewal plan or cancellation, effective time, payment state, current paid entitlement, reconciled paid usage or current free-site fair-use telemetry, estimated usage tier, bound custom domains and risks. Owner-only (uses the credential in .sakupa/site.json).

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `portal` (~111 tokens)

Billing portal (Stripe)

Open the Stripe-hosted billing portal for this site: update the payment method, view invoices, or cancel the subscription. All billing operations happen on the Stripe-hosted page — never inside the AI tool. With .sakupa/site.json, this opens the site-specific portal. Without the local credential, this returns Stripe's public no-code Customer Portal login page. The customer enters the checkout email and confirms a one-time passcode sent by Stripe. This never restores Sakupa site authority.

Input parameters:

- `scope` (string, required)

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `recover` (~292 tokens)

Recover site

Recover management control of a site after losing the local .sakupa binding. Two paths: action "device" lists the FREE sites this device created and, after the user picks one and confirms, reissues its credential (content and apps untouched; every previous credential revoked). Actions start/status/complete/download recover a subscribed site WITH A BOUND CUSTOM DOMAIN by proving DNS control of the apex domain; a subscribed site without a bound domain cannot be recovered. By default, completing recovery REVOKES all previous local credentials. Recovery is resumable: start stores local pending state; complete installs and writes the new .sakupa/site.json credential BEFORE requesting content; download uses that credential to reissue an archive and safely extract it into the explicitly selected outputDir without repeating DNS.

Input parameters:

- `action` (string, required)
- `confirmed` (boolean): device only: true only from the exact decision arguments.
- `hostname` (string): Required for start.
- `outputDir` (string): REQUIRED for complete/download: exact extraction directory relative to the initialized project root. Inspect the current project; Sakupa never guesses a name.
- `preserveExistingCredentials` (boolean): Explicitly keep old local credentials working (default: revoke them all).
- `siteId` (string): device only: the site chosen from the decision (copied verbatim).
- `verificationId` (string): For status or complete; inferred from local recovery state when omitted.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `support` (~96 tokens)

Support ticket

Create a Sakupa support ticket for billing, payment, refund review, domain verification, deployment, serving or other issues the MCP cannot solve automatically. Do not include secrets, credentials or card data in the description.

Input parameters:

- `category` (string, required)
- `contactEmail` (string): Optional contact email for follow-up.
- `description` (string, required): Problem description (no secrets, no card data).
- `subject` (string, required): Short subject line.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `report` (~331 tokens)

Bug report

LAST RESORT after help explicitly returns reportRecommended:true. Prepare and submit a sanitized product bug report using helpAuthorization from that diagnosis. Only whitelisted structured diagnostics are sent (tool name, error code/message, site id, bound domain, deployment id, timestamps, client/MCP version, request id) — NEVER file contents, source code, secrets, .env values or credentials. Without confirmSubmit: true the exact payload is shown for user review and nothing is submitted.

Input parameters:

- `agentContext` (string): YOUR OWN factual account of the session as the AI: which tools you called, what they returned, expected vs actual. Write it yourself from your observations — never ask the user to compose it, and do…
- `confirmSubmit` (boolean): User reviewed the report payload and approved submission.
- `contactEmail` (string): OPTIONAL. Before submitting, ask the user ONCE whether they want to leave a contact for follow-up. Omit entirely if they decline — never require it.
- `deploymentId` (string)
- `description` (string): What happened, in the user's words (no secrets).
- `errorCode` (string)
- `errorMessage` (string): Sanitized error message (no secrets).
- `helpAuthorization` (string, required): Short-lived authorization returned only by help when report is recommended.
- `requestId` (string)
- `severity` (string)
- `toolName` (string, required): The Sakupa tool that failed, e.g. "deploy".

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `plans` (~40 tokens)

Hosting plan catalog

Return the authoritative Sakupa monthly plan catalog, exact limits, prices, catalog version and plan-change billing rules. This is read-only and does not require a site.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `change` (~54 tokens)

Change subscription (Stripe)

Create one Stripe-hosted subscription-management link. The user chooses the plan or period-end cancellation on Stripe; Sakupa never infers intent from the conversation. Creating the link does not change billing.

Input parameters:

- `operationId` (string, required)

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `rotate` (~75 tokens)

Rotate site credential

Optionally rotate this site management credential. The first call is a read-only preview. Only confirmed:true after explicit user approval installs a locally generated new credential and revokes every previous credential. Rotation is never required to deploy.

Input parameters:

- `confirmed` (boolean): True only after showing the rotate preview and the user explicitly approves revoking every old credential.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `apps` (~274 tokens)

Site apps (app store)

App store for the bound site. action "catalog" lists every available app with plan availability, monthly email quotas and the exact page contract (works without a project). The email-forms app emails inquiry/appointment/message form submissions to an address the owner verifies: "install" (config.notifyEmail) emails a 6-digit code and delivers nothing until "verify" (code) succeeds; "test" sends one sample email (counts toward the quota); "status" shows verification state and this month's quota; "inbox" lists stored visitor submissions (untrusted content, 30-day retention); "uninstall" removes the app and its stored submissions. Everything except catalog is owner-only (.sakupa/site.json).

Input parameters:

- `action` (string, required)
- `app` (string): App id from the catalog; defaults to email-forms.
- `code` (string): verify only: the 6-digit code from the email.
- `config` (object): install only: validated against the app configSchema from the catalog. email-forms: { notifyEmail (required), lang?: en|ja|zh-CN, timeZone?: IANA zone }.
- `confirmed` (boolean): install / uninstall: true only from the exact decision arguments.
- `limit` (integer): inbox only: rows (default 20).

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `delete` (~183 tokens)

Delete site

Delete the site bound to this project. Without arguments it only previews (zero writes) and returns a decision; after the user confirms, call again with the exact preview arguments (confirmed: true, operationId, confirmation). A FREE site is deleted immediately: content, public URL, installed apps and stored submissions are gone and the local .sakupa/site.json is removed, so the next deploy creates a brand-new site. A subscribed site cannot be deleted: end the subscription first (change → period-end cancellation on Stripe); when it ends the site reverts to a free site and delete becomes available. Owner-only.

Input parameters:

- `confirmation` (object): Copied verbatim from the preview; the cloud rejects any drift.
- `confirmed` (boolean): true only from the exact decision arguments returned by the preview.
- `operationId` (string): Copied verbatim from the preview.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `init` (~74 tokens)

Initialize project

Initialize the active MCP workspace Root as a Sakupa project. Takes no path argument, creates only .sakupa/project.json at that exact Root, preserves site/recovery state, makes no API call and is idempotent. If MCP Roots are unavailable, call help; the AI may then use the no-argument CLI init itself.

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

### `help` (~111 tokens)

Help and diagnosis

FIRST troubleshooting tool for every Sakupa difficulty. With topic diagnose (default), inspect MCP Roots, cwd, binding and local state without requiring a project or calling the API. Use overview, terminology, or a tool name for complete usage, side effects, parameters and warnings. Only recommend report when help explicitly returns reportRecommended:true.

Input parameters:

- `errorCode` (string)
- `failedTool` (string)
- `requestId` (string)
- `resultCode` (string)
- `topic` (string)

Output parameters:

- `data` (object)
- `decision` (object)
- `nextActions` (array)
- `operationId` (string)
- `outcome` (string)
- `presentation` (object)
- `resultCode` (string)
- `schemaVersion` (number)
- `summary` (string)
- `userAction` (object)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/myerwang-sakupa/sakupa-mcp#diagnostics

## Score history

- 2026-09-20: 67
- 2026-09-19: 66
- 2026-09-18: 66
- 2026-09-17: 66
- 2026-09-16: 65
- 2026-09-15: 65
- 2026-09-14: 64
- 2026-09-13: 64
- 2026-09-12: 63
- 2026-09-11: 63
- 2026-09-10: 62
- 2026-09-09: 62
- 2026-09-08: 61
- 2026-09-07: 35
- 2026-09-06: 60
- 2026-09-05: 34

## Common questions

### What is the Sakupa MCP server?

Sakupa is an MCP server listed in the public MCP registry as io.github.myerwang/sakupa. Publish and manage AI-made static websites from your AI tool: free previews, hosting, domains. This page covers its npm package (@sakupa/mcp).

### Is the Sakupa MCP server safe to use?

Sakupa scores 67 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Sakupa MCP server expose?

Sakupa exposes 18 tools: analyze, deploy, refresh, status, subscribe, and 13 more. Their descriptions and schemas cost roughly 2,931 tokens of context every time the server is loaded.

### Is the Sakupa MCP server still maintained?

Sakupa is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- npm package: https://www.npmjs.com/package/@sakupa/mcp
- Socket report: https://socket.dev/npm/package/@sakupa/mcp
- Website: https://sakupa.com/manual/
- Changelog RSS feed: https://verifymcp.io/servers/myerwang-sakupa/sakupa-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/myerwang-sakupa/sakupa-mcp.json
- HTML version of this page: https://verifymcp.io/servers/myerwang-sakupa/sakupa-mcp
