Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

DreamAgent

REMOTE · MCP.DREAMAGENT.CLOUD · SCANNED OCT 7

Build and deploy websites, Telegram and Discord bots from chat via the DreamAgent platform.

−1 this week 76 Trust /100

Recent critical change

Authorization (16 Aug 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability66
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4580 tokens (~229/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage90
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 64% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the DreamAgent MCP server?

DreamAgent is a hosted endpoint at https://mcp.dreamagent.cloud/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.dreamagent.cloud

# add to Claude Code
claude mcp add --transport http nivethaug-dreamagent 'https://mcp.dreamagent.cloud/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "nivethaug-dreamagent": {
      "url": "https://mcp.dreamagent.cloud/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "nivethaug-dreamagent": {
      "type": "http",
      "url": "https://mcp.dreamagent.cloud/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.nivethaug-dreamagent]
url = "https://mcp.dreamagent.cloud/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "nivethaug-dreamagent": {
      "type": "remote",
      "url": "https://mcp.dreamagent.cloud/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add nivethaug-dreamagent --url 'https://mcp.dreamagent.cloud/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  nivethaug-dreamagent:
    url: "https://mcp.dreamagent.cloud/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "nivethaug-dreamagent": {
      "Transport": "http",
      "Url": "https://mcp.dreamagent.cloud/mcp"
    }
  }
}
# add to Vellum
assistant mcp add nivethaug-dreamagent -t streamable-http -u 'https://mcp.dreamagent.cloud/mcp'
// mcp.json
{
  "mcpServers": {
    "nivethaug-dreamagent": {
      "type": "http",
      "url": "https://mcp.dreamagent.cloud/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Oct 26 −1
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “dreamagent_chat” rewrote its description, which is the text the model reads security
    • Tool “dreamagent_create_project” rewrote its description, which is the text the model reads security
    • Tool “dreamagent_list_project_env” rewrote its description, which is the text the model reads security
    • Tool coverage: 100% → 64% ▼ functional
    • Schema quality: 271 → 229 ▲ functional
    • Destructive annotations: pass → 100 functional
    • New tool “dreamagent_build_publish” functional
    • New tool “dreamagent_delete_file” functional
    • New tool “dreamagent_design_mode” functional
    • New tool “dreamagent_get_file_diff” functional
    • New tool “dreamagent_list_files” functional
    • New tool “dreamagent_list_superpowers” functional
    • New tool “dreamagent_read_file” functional
    • New tool “dreamagent_write_file” functional
    • “dreamagent_create_project” reworded the description of “project_type” cosmetic
  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 14 Sept 26 0
    • Stability: 0.97 → pass security
  • 13 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 9 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

  • 7 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 7 Oct 2026 · Probed https://mcp.dreamagent.cloud/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=dreamagent.cloud CN=YE1,O=Let's Encrypt,C=US 24 Sept 2026 23 Dec 2026 ECDSA 256 ECDSA-SHA384 68e26d1f8acaa2d6bc3377fde7dc21a93ac
SANs: *.dreamagent.cloud, dreamagent.cloud
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.dreamagent.cloud. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
cloud. present 7041 13 Verified
dreamagent.cloud. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.dreamagent.cloud/mcp Verified 200
http (plaintext) http://mcp.dreamagent.cloud/mcp HTTPS enforced 301 https://mcp.dreamagent.cloud/mcp
MCP tools · 20 exposed · ~3,930 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
dreamagent_build_publish ~132

WRITE ACTION — build & publish a DreamAgent project: rebuilds the app from the current source files and pushes the new version live. Use after finishing file edits (dreamagent_write_file) so the user's changes go live. Pro/paid accounts only. CONFIRM BEFORE CALLING — tell the user the project will be rebuilt and redeployed, and call only with confirm=true after they agree. ASYNCHRONOUS: kick-off returns immediately; check dreamagent_get_project_status until the project reports 'ready'.

NameTypeReqDescription
confirmboolean––
project_idintegeryes–
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_cancel_chat ~130

DESTRUCTIVE — stops an AI edit that is currently running. Use ONLY when the user explicitly asks to stop/cancel the active edit. After cancellation, do NOT claim the requested change was completed — report that it was stopped. Returns 'Cancellation requested: <backend message>' — e.g. 'Query cancelled', 'Cancellation requested' (durable run), or 'No active query found'. Afterwards poll dreamagent_get_chat_status / dreamagent_get_edit_progress until run_status reports 'cancelled'.

NameTypeReqDescription
session_keystringyesthe session key of the running edit.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_chat ~492

WRITE ACTION — builds, modifies, or fixes an EXISTING project with a natural-language instruction. Use ONLY when the user clearly asks for a change ("add X", "fix Y", "change the theme"). If the user is only asking for advice, analysis, review, or suggestions ("what could be improved?", "review my bot"), do NOT call this — answer from the project's info instead; a review request is not an edit. Describe ONLY the desired change — DreamAgent's AI automatically handles code, tests, rebuild, and redeployment. Completed changes are saved and committed automatically. ASYNCHRONOUS: returns immediately with the session_key; monitor with dreamagent_get_edit_progress (or dreamagent_get_chat_status with the returned session key) until a terminal state. Report success only after run_status reaches 'completed'. Edits consume the user's AI credits. ERRORS (actual returns): failures come back as text starting with 'ERROR:'. If the edit was rejected before starting, the text says 'the edit was NOT started' plus the reason — HTTP 402 insufficient credits, 409 another edit already active, 423 session lock held by another session, 404 wrong project id, 401 no account connected. Treat the edit as failed/cancelled only when a status tool says so. ONE EDIT AT A TIME: never start another modification on the same project while one is running — check progress first and wait. SUPERPOWERS: projects can use the account's enabled AI tools (song/video/image generation, voiceover, lip sync, voice clone, transcription, media processing, PDF tools). If the user asks to add or use one ("add song generation", "generate an image feature"), simply include that in the message — DreamAgent's agent knows the enabled tools and wires the integration, UI and job handling automatically. Check the catalog with dreamagent_list_superpowers; if a tool is disabled, direct the user to dreamagent.cloud -> Superpowers to enable it first.

NameTypeReqDescription
messagestringyesthe desired change (what + any behavioral constraints).
new_sessionboolean–optional — start a fresh session for a new topic.
project_idintegeryesthe project to modify.
session_key––optional — continue a specific development session.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_create_project ~990

WRITE ACTION — creates a new DreamAgent project (website, Telegram bot, Discord bot, or AI agent). Use ONLY when the user clearly asks to create/build a new project; not for questions about what to build. CONFIRM BEFORE CALLING — never create on the first mention. In ONE message, present and get the user's explicit go-ahead for: 1. The credential: run dreamagent_list_global_integrations first. If several telegram/discord credentials are saved, list them (id + title) and ask which to use. If exactly one is saved, state which one you will use. Never pick silently. 2. The plan: name, type, and the final description exactly as you will submit it (this is the Prompt Assistant's recommendation summary). Call this tool only after the user confirms. CREATION IS ASYNCHRONOUS: after calling, check dreamagent_get_project_status repeatedly until the project is 'ready' or 'failed' (bots ~2-5 min, websites longer). CREDENTIALS: raw bot tokens are never accepted in chat or as inputs. For Telegram/Discord bots you MUST pass bot_token_integration_id — the ID of a saved credential from dreamagent_list_global_integrations. If none is saved, direct the user to dreamagent.cloud → Settings → Global Integrations. Other saved keys can be imported via global_integration_ids. Credentials are stored as project secrets and are never exposed back. DESCRIPTION = the refined creation brief. Act as a Creative Director / Product Manager, not an architect. Create a concise but complete description of WHAT should be built: - product vision and target audience - user experience and core functionality - design/tone direction - important features and behavior - final expected result Do not include implementation details such as: - technology stack - architecture - database/API implementation - authentication implementation - deployment - CI/CD - testing commands Infer reasonable defaults when missing details are non-critical. Ask for clarification only when missing information mat…

NameTypeReqDescription
bot_token_integration_id––REQUIRED for telegrambot & discordbot — saved-credential ID (see dreamagent_list_global_integrations).
description––the build request (what + for whom + features/tone).
env_vars––optional non-secret environment variables.
global_integration_ids––optional saved-key IDs to import as env vars.
namestringyesproject name (max 30 chars; a public subdomain is auto-generated).
project_typestringyeswebsite / telegrambot / discordbot / agent.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_create_session ~82

Create a new development session for a project — a separate conversation with its own context. Use when the user wants to start a distinct development topic. A new session does NOT replace or affect the existing project — earlier sessions remain available.

NameTypeReqDescription
labelstring–optional name for the session.
project_idintegeryesthe project.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_delete_file ~95

WRITE ACTION — delete one source file from a DreamAgent project. Hidden/credential files (.env, .git, keys) are rejected. Recoverable via the project's git history. CONFIRM BEFORE CALLING — tell the user which file will be deleted and call only with confirm=true after they agree.

NameTypeReqDescription
confirmboolean––
file_pathstringyes–
project_idintegeryes–
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_design_mode ~204

WRITE ACTION — redesign a website project's UI to match a design image. Website projects only. The user provides an image (screenshot, mockup, AI-generated design) and instructions. You generate the image (e.g. DALL-E), encode it as base64, and send it here. DreamAgent's AI will read the image and redesign the project's frontend to match. CONFIRM BEFORE CALLING — show the user: 1. The project being redesigned 2. The design instructions Then call only with confirm=true after they agree.

NameTypeReqDescription
confirmboolean–must be true to execute.
image_base64stringyesbase64-encoded design reference image (PNG/JPG).
instructionsstringyeswhat to change (e.g. "match this dark theme with purple accents", "make the hero section look like this", "use this layout").
project_idintegeryesthe website project to redesign.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_get_chat_status ~256

Check the progress and final status of a specific AI development session using its session key. Use this to monitor an asynchronous edit until it completes, fails, or is cancelled — keep checking until a terminal state. The session key comes from dreamagent_chat or dreamagent_list_sessions and is an identifier, not a secret. Returns (actual fields): 'active=', 'run_status=', 'next_after=' (cursor for the next check), optional 'new_output:' (text produced since the last check), then either "Still working — poll again" or a terminal 'done=true' line: finished (with the final output tail), 'the edit was NOT started: <reason>' (rejected early, e.g. HTTP 402 insufficient credits), or 'stream error' (the connection to the run broke — the server-side run may still have finished; verify with dreamagent_get_edit_progress). run_status values: queued | running | cancel_requested | completed | failed | cancelled | interrupted | unknown.

NameTypeReqDescription
afterinteger–cursor from the previous check (0 on the first check).
session_keystringyesthe session key returned by dreamagent_chat.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_get_edit_progress ~276

Check the latest AI edit progress for a project using its project identifier — no session key needed: the project id retrieves the session holding the latest edit. Use when the user asks whether their edit is finished, when the session key isn't available (e.g. a new conversation), and BEFORE starting any new edit. Returns (actual fields): 'session_key=' (the identifier of the session this progress comes from), 'edit_active=', 'run_status=', 'chunks=' (output size so far), optional 'recent_output (tail):', and a terminal 'result:' line: finished (with the final output tail), 'the edit was NOT started: <reason>' (rejected early, e.g. HTTP 402 insufficient credits), 'stream error', or 'no run is currently active'. run_status values: queued | running | cancel_requested | completed | failed | cancelled | interrupted | unknown. Distinct from dreamagent_get_project_status: project status = creation/deployment state (creating/ready/failed); edit progress = current AI modification state; chat status (dreamagent_get_chat_status) monitors one specific session by its session key. If edit_active is true, do NOT launch another edit for the same project.

NameTypeReqDescription
project_idintegeryesthe project being edited.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_get_file_diff ~66

Git diff of one project file against the last commit — shows the pending (not yet live) changes. Free, read-only. Use after edits to review exactly what changed before rebuilding.

NameTypeReqDescription
file_pathstringyes–
project_idintegeryes–
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_get_project_status ~144

Check a project's creation/deployment state. Terminal states are 'ready' (built and live) and 'failed'; while a project is being created it reports progressive phases such as 'creating', 'building', 'deploying', or 'ai_provisioning' — treat any non-terminal status as still building. Use after dreamagent_create_project (poll until ready or failed) and whenever the user asks whether a project is ready or live. NOTE: this reports the PROJECT's build/deploy state — NOT AI edit progress. For edits use dreamagent_get_edit_progress.

NameTypeReqDescription
project_idintegeryesthe project to check.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_list_files ~54

List the file tree of a DreamAgent project (source files only — hidden files like .env are excluded). Use before reading or editing a file to find the correct path.

NameTypeReqDescription
project_idintegeryes–
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_list_global_integrations ~132

List the user's saved credentials (Global Integrations). ALWAYS call this before creating any bot project or asking the user for a token/API key. Saved credentials are referenced BY ID when creating projects: bot_token_integration_id for bot tokens, global_integration_ids for other keys. Secret values are never returned — only IDs and metadata (type, key name, verified, title). If nothing suitable is saved: direct the user to dreamagent.cloud → Settings → Global Integrations to add it (one-time, verified, reusable). Never ask the user to paste tokens in chat.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_list_project_env ~118

List a project's environment variables with their details. Shows each key's name, title, description, docs URL, and category — values are masked (secrets are never returned). Use to see which integrations a project already has before adding more, or to answer "what keys does my project have?". These are PROJECT-SPECIFIC variables — distinct from the user's Global Integrations — API-key credentials and connected OAuth services (dreamagent_list_global_integrations).

NameTypeReqDescription
project_idintegeryesthe project to inspect.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_list_projects ~125

List the user's DreamAgent projects. Returns each project's name, ID, type, status, and live domain (when available). Use when the user asks to see, find, select, or check their projects — and ALWAYS before modifying a project when its ID is not already known (resolve names to IDs here first).

NameTypeReqDescription
status––optional exact-match filter (e.g. 'ready', 'failed'). During creation, projects report intermediate phases (creating/building/deploying/…), so filtering by 'creating' does not match every in-progress…
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_list_sessions ~103

List a project's development sessions (conversation threads). Returns each session's identifier (session key) and context so you can select, continue, or monitor a specific development session — pass the session key to dreamagent_chat to continue that thread or to dreamagent_get_chat_status to monitor it. The session key is a reference used to address a session; it is not an authentication credential or a secret.

NameTypeReqDescription
project_idintegeryesthe project.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_list_superpowers ~121

List DreamAgent Superpowers — the account's ready-made AI tools (song/video/image generation, voiceover, lip sync, voice clone, transcription, media processing, PDF tools) with their enabled state and beta pricing. Read-only; no credits consumed. Use when the user asks what AI tools/superpowers are available, whether a specific tool is enabled, or what they can add to a project. Tools shown as enabled can be used from ANY of the user's projects through dreamagent_chat (just ask in the message).

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_read_file ~80

Read a source file from a DreamAgent project. file_path is the project-relative path (from dreamagent_list_files), e.g. "src/pages/Home.tsx" or "telegram/main.py". Hidden files (.env) and binaries are not readable.

NameTypeReqDescription
file_pathstringyes–
project_idintegeryes–
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_release_project_lock ~124

RECOVERY-ONLY — releases a project's editing lock when a stale or abandoned session blocks new modifications. NOT a normal editing step, and NEVER a way to bypass an actively running edit. The lock state is not machine-readable from here: to judge staleness, check dreamagent_get_edit_progress — if no edit is active but dreamagent_chat still fails with a lock error, the lock is stale. Confirm with the user before releasing if they may have the project open elsewhere.

NameTypeReqDescription
project_idintegeryesthe project to unlock.
NameTypeReqDescription
resultstringyes–

No examples provided.

dreamagent_write_file ~206

WRITE ACTION — overwrite or create one source file in a DreamAgent project with the exact content given. Changes go live after the project is rebuilt (dreamagent_build_publish). CONFIRM BEFORE CALLING — in ONE message show the user: the target path and a summary of the change, then call only after they agree. Never write on the first mention. GUARDS (enforced server-side, the same as the in-app code editor): path stays inside the project, hidden/credential files (.env, .git, keys) are rejected, content is scanned for malware/shell signatures and blocked, 2MB size cap. Failed scans return the reason. The user can undo damage by editing in the DreamAgent editor, so a wrong write is recoverable — still, prefer precise minimal diffs.

NameTypeReqDescription
confirmboolean––
contentstringyes–
file_pathstringyes–
project_idintegeryes–
NameTypeReqDescription
resultstringyes–

No examples provided.

Common questions

What is the DreamAgent MCP server?

DreamAgent is an MCP server listed in the public MCP registry as io.github.nivethaug/dreamagent. Build and deploy websites, Telegram and Discord bots from chat via the DreamAgent platform. This page covers its hosted endpoint (https://mcp.dreamagent.cloud/mcp).

Is the DreamAgent MCP server safe to use?

DreamAgent scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the DreamAgent MCP server expose?

DreamAgent exposes 20 tools: dreamagent_list_projects, dreamagent_list_global_integrations, dreamagent_list_project_env, dreamagent_list_superpowers, dreamagent_list_files, and 15 more. Their descriptions and schemas cost roughly 3,930 tokens of context every time the server is loaded.

Does the DreamAgent MCP server require authentication?

No. We connected to DreamAgent without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the DreamAgent MCP server still maintained?

DreamAgent is still listed as active in the MCP registry. We last reached this channel on 7 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.