Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

now.shiply/shiply

REMOTE · SHIPLY.NOW · SCANNED AUG 3

Publish any app in one call: SQL database, functions, email, and a custom domain. Flat price.

Available components

+8 this week 82 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security94
Transport & Reachability100
Schema Quality & AI Usability77
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 9168 tokens (~78/item across 117 items; 114 tools + 3 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 99% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · shiply.now

# add to Claude Code
claude mcp add --transport http now-shiply-shiply https://shiply.now/mcp
# ~/.codex/config.toml
[mcp_servers.now-shiply-shiply]
url = "https://shiply.now/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "now-shiply-shiply": {
      "type": "remote",
      "url": "https://shiply.now/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add now-shiply-shiply --url https://shiply.now/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  now-shiply-shiply:
    url: "https://shiply.now/mcp"
// mcp.json
{
  "mcpServers": {
    "now-shiply-shiply": {
      "type": "http",
      "url": "https://shiply.now/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +6
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 74

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://shiply.now/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=shiply.now CN=WE1,O=Google Trust Services,C=US 11 Jun 2026 9 Sept 2026 ECDSA 256 ECDSA-SHA256 c2577c70f60d0a4113fa4d399ec10b5a
SANs: shiply.now, *.shiply.now
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b
DNSSEC insecure

Validation of shiply.now. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
now. present 53572 8 Verified
shiply.now. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer error="invalid_token", error_description="No authorization provided", resource_metadata="https://shiply.now/.well-known/oauth-protected-resource"

Bearer error="invalid_token", error_description="No authorization provided", resource_metadata="https://shiply.now/.well-known/oauth-protected-resource"
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=(), payment=(), usb=()

Protected resource metadata

Document https://shiply.now/.well-known/oauth-protected-resource
Retrieved Yes
Resource https://shiply.now/mcp
Authorisation server https://shiply.now
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://shiply.now/mcp Verified 200
http (plaintext) http://shiply.now/mcp HTTPS enforced 301 https://shiply.now/mcp
MCP tools — 114 exposed · ~9,102 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
list_custom_domains ~32

List registered custom domains grouped with their subdomains, each subdomain's site and status, and the detected provider.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_databases ~85

List the SQL databases (D1 or Neon Postgres) on my account, including which owned site (if any) each is attached to. Call this BEFORE db_query/db_schema-style work to discover a databaseId — those live on a per-database MCP server reached via GET /api/v1/databases/{id} (see llms.txt), which this id feeds.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_domains ~15

List connected custom domains with status.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_drives ~42

List the user's private cloud Drives (id, name). Optional clientId filters to one client.

NameTypeReqDescription
clientIdstringonly drives filed under this client
NameTypeReqDescription
resultyes

No examples provided.

list_inbox ~75

List the user's email inbox threads (outbound demand-test sends + inbound replies / unsubscribes / complaints / bounces). Filter by tag.

NameTypeReqDescription
filterstringdefault all
limitintegermax threads to return, ≤200
offsetintegernumber of threads to skip (pagination)
NameTypeReqDescription
resultyes

No examples provided.

list_listings ~45

Return every marketplace listing the seller owns (any status: draft, live, paused, sold). Includes site slug and current price. Use to see what's for sale across the account.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_mailbox_contacts ~84

List captured contacts for a (site, collection) mailbox, optionally filtered by status (signed_up/confirmed/unsubscribed). Returns email, status, confirmedAt, createdAt, and captured fields.

NameTypeReqDescription
collectionstringyesmailbox collection name
slugstringyessite slug the mailbox belongs to
statusstringfilter contacts by status
NameTypeReqDescription
resultyes

No examples provided.

list_my_orders ~73

Return every marketplace order the user PURCHASED. Most recent first. Shows the acquired site, paid amount, and whether the order is still inside the 30-day refund window. Use to recap what the user owns by purchase.

NameTypeReqDescription
limitintegermax orders to return (default 100, max 500)
NameTypeReqDescription
resultyes

No examples provided.

list_my_sales ~77

Return every marketplace order for sites the user sold (incl. pending, paid, refunded, failed, disputed). Most recent first. Use to surface revenue + which orders are still inside the 30-day refund window (refundExpiresAt > now).

NameTypeReqDescription
limitintegermax orders to return (default 100, max 500)
NameTypeReqDescription
resultyes

No examples provided.

list_project_files ~64

Return the customer-uploaded files for one project (path, size, contentType, createdAt). Empty when no drive folder exists yet (no uploads). Use to inspect what intake assets the customer attached.

NameTypeReqDescription
idstringyesproject id whose uploaded files to list
NameTypeReqDescription
resultyes

No examples provided.

list_projects ~128

List the dev's customer-intake projects (newest first). Optional filters: status (draft|intake_open|brief_ready|brief_failed|archived), q (case-insensitive match on label or customer email), limit (default 100). Use to triage what's in flight before opening a specific project.

NameTypeReqDescription
clientIdstringonly projects filed under this client
limitintegermax projects to return (default 100)
qstringcase-insensitive match on label or customer email
statusstringfilter by project status
NameTypeReqDescription
resultyes

No examples provided.

list_secrets ~37

List secret names (values not returned) for a site's deployed function.

NameTypeReqDescription
slugstringyessite slug whose secret names to list
NameTypeReqDescription
resultyes

No examples provided.

list_sending_domains ~55

Return every BYO sending domain the user has added (id, domain, fromAddress, status: pending|verified|failed, DNS records). Use to inspect verification state or find the id of a domain to verify/remove.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_site_inbox ~55

Read the email threads (received, sent, web captures) for the agent's sites. Optionally scoped to one site by slug.

NameTypeReqDescription
slugstringlimit to one site by slug; omit for all sites
NameTypeReqDescription
resultyes

No examples provided.

list_site_variables ~36

Names of the variables attached to an owned site's Worker env (values never shown here).

NameTypeReqDescription
slugstringyesowned site slug
NameTypeReqDescription
resultyes

No examples provided.

list_sites ~39

List the sites owned by this API key. Optional clientId filters to one client.

NameTypeReqDescription
clientIdstringonly sites filed under this client
NameTypeReqDescription
resultyes

No examples provided.

list_suppressions ~49

Return the user's suppression list — addresses (and full domains) that shiply skips when sending. Bounces, complaints, manual user adds, and AI-detected unsubscribes all land here.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_test_inbox_addresses ~71

Return every active demand test's reply / inbound address (<slug>@<sitesDomain>). Use this when you need to TELL someone where to email — e.g. drafting a reply or sharing a test's contact address. Mail sent to these aliases lands in /dashboard/inbox tied to the test.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_tests ~19

List your demand tests with signups + confirmed counts.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultyes

No examples provided.

list_unsubscribes ~48

Shortcut for list_inbox with filter=unsubscribes — shows every thread tagged as an opt-out request.

NameTypeReqDescription
limitintegermax threads to return, ≤200
NameTypeReqDescription
resultyes

No examples provided.

list_variables ~33

List the encrypted variables. Values are masked unless reveal=true.

NameTypeReqDescription
revealbooleanreturn plaintext values instead of masked
NameTypeReqDescription
resultyes

No examples provided.

list_versions ~68

List a site's finalized deploys newest-first (id, createdAt, isLive, fileCount, bytes), capped at 20. Pair with rollback_site: pick a version id from here and re-point the site to it.

NameTypeReqDescription
slugstringyessite slug to list deploys for
NameTypeReqDescription
resultyes

No examples provided.

mark_thread_read ~68

Zero the unread counter for a thread. Useful after the agent has read but not acted. read_thread already calls this implicitly; use this explicitly when you want to clear unread without re-fetching the thread body.

NameTypeReqDescription
threadIdstringyesthread id from list_inbox to mark read
NameTypeReqDescription
resultyes

No examples provided.

promote_site ~75

Copy the EXACT live bytes of one owned site (srcSlug — your preview) into another owned site (destSlug — your production site / custom domain), no rebuild. Dest keeps its slug, domains, and access settings; only the served bytes change.

NameTypeReqDescription
destSlugstringyes
srcSlugstringyes
NameTypeReqDescription
resultyes

No examples provided.

publish_from_drive ~81

Snapshot a Drive (or a prefix of it) into a new live site at <slug>.shiply.now. Files copied server-side.

NameTypeReqDescription
driveIdstringyesdrive id (drv_…) or "default"
prefixstringonly snapshot files under this path prefix
titlestringdisplay title for the new site
NameTypeReqDescription
resultyes

No examples provided.

publish_site ~278

Publish files to the web → live URL at <slug>.shiply.now. UPDATING: never create a new site for changes — re-call with claimToken (anonymous sites) or slug (sites you own with a Bearer key) and the SAME URL gets the new version. Unchanged files are hash-skipped server-side, so re-publishing (including retrying a failed publish) is cheap — always update the same site rather than creating a new one. Works WITHOUT auth (anonymous: 24h lifetime, returns claimToken/claimUrl — SAVE THEM). With a Bearer shp_ key sites are permanent. ≤50 files / 2 MB inline; bigger: REST flow per https://shiply.now/llms.txt. index.html serves at /. spaMode for client-side routing.

NameTypeReqDescription
claimTokenstringUPDATE an existing anonymous site (from the original publish result)
clientobjectoptional: file this under a client (the publish/site is grouped in their customer view)
filesarrayyessite files; index.html required for a homepage
slugstringUPDATE an existing site you own (requires Bearer key)
spaModebooleanserve index.html for unknown paths (client-side routing)
titlestringdisplay title for the site
NameTypeReqDescription
resultyes

No examples provided.

pull_site ~80

Download the current files of a site you own (or created via a platform connection) so you can edit and republish to the same slug with publish_site. Static sites return editable source; framework/SSR sites return the built bundle (`.shiply/bundle/*`), not original source.

NameTypeReqDescription
slugstringyessite slug to pull files for
NameTypeReqDescription
resultyes

No examples provided.

read_thread ~44

Return the thread metadata + all messages in chronological order. Use list_inbox first to get a threadId.

NameTypeReqDescription
threadIdstringyesthread id from list_inbox
NameTypeReqDescription
resultyes

No examples provided.

refund_order ~98

Issue a full refund on a paid order the user sold. Must be inside the 30-day refund window (server enforces). Triggers a Stripe refund; the webhook flips the order to 'refunded' and reverts site ownership to the seller. Idempotent on already-refunded orders.

NameTypeReqDescription
orderIdstringyesid of the paid order to refund (from list_my_sales)
reasonstringoptional refund reason
NameTypeReqDescription
resultyes

No examples provided.

regenerate_brief ~77

Re-run the MiniMax/Anthropic brief generator from the project's current intake_responses and persist the result. Flips status to brief_ready on success or brief_failed on error. Use after the customer edits answers post-submit, or when the first AI attempt failed.

NameTypeReqDescription
idstringyesproject id to re-run the brief for
NameTypeReqDescription
resultyes

No examples provided.

remove_cron ~46

Remove a cron trigger from a site's deployed function.

NameTypeReqDescription
pathstringyesURL path of the cron to remove
slugstringyessite slug whose cron to remove
NameTypeReqDescription
resultyes

No examples provided.

remove_custom_domain ~43

Remove a registered custom domain and all its subdomains; they stop serving immediately.

NameTypeReqDescription
domainstringyesregistered custom domain to remove, e.g. example.com
NameTypeReqDescription
resultyes

No examples provided.

remove_domain ~34

Remove a connected domain (by id). It stops serving immediately.

NameTypeReqDescription
idstringyesconnected domain id from list_domains
NameTypeReqDescription
resultyes

No examples provided.

remove_function ~53

Remove the deployed Worker function from a site (and all its routes, secrets, and cron triggers). Site falls back to static-only serving. Irreversible.

NameTypeReqDescription
slugstringyessite slug whose function to remove
NameTypeReqDescription
resultyes

No examples provided.

remove_secret ~49

Remove a secret from a site's deployed function. The binding disappears on next request.

NameTypeReqDescription
namestringyessecret name to remove
slugstringyessite slug whose function holds the secret
NameTypeReqDescription
resultyes

No examples provided.

remove_sending_domain ~69

Delete a BYO sending domain. Any demand tests bound to it fall back to the managed shiply sender. Also GCs the underlying Resend domain. Irreversible — re-adding requires re-verifying DNS.

NameTypeReqDescription
idstringyessending domain id from list_sending_domains
NameTypeReqDescription
resultyes

No examples provided.

remove_suppression ~42

Delete one suppression by id. Use list_suppressions first to find the id.

NameTypeReqDescription
suppressionIdstringyessuppression id from list_suppressions
NameTypeReqDescription
resultyes

No examples provided.

reply_to_thread ~147

Send an email reply on an existing thread. Goes FROM the original recipient address (the <slug>@shiply.now alias the sender used) and TO the original sender. Threaded via RFC 5322 In-Reply-To so Gmail/Outlook group it with the original. Subject defaults to 'Re: <original>' when omitted. Cap at 20,000 chars. Use after read_thread to make sure you're replying to the right conversation.

NameTypeReqDescription
bodystringyesreply body, ≤20,000 chars
subjectstringsubject; defaults to 'Re: <original>'
threadIdstringyesthread id from list_inbox to reply on
NameTypeReqDescription
resultyes

No examples provided.

resend_confirmation ~55

Re-send the double-opt-in confirmation to a signup that has not confirmed yet.

NameTypeReqDescription
emailstringyesthe unconfirmed signup email to re-send to
testIdstringyesdemand test id the signup belongs to
NameTypeReqDescription
resultyes

No examples provided.

resend_intake_invite ~86

Re-fire the 'your developer sent you a project intake' email to the project's customer. Throws invalid_request if the project has no customerEmail (the dev needs to set one via the dashboard first — customer email isn't agent-patchable). Use when the customer says they didn't receive the link.

NameTypeReqDescription
idstringyesproject id to re-send the intake invite for
NameTypeReqDescription
resultyes

No examples provided.

restore_project ~63

Move an archived project back to status='draft' so it reappears in the active list. Idempotent on non-archived projects? No — server rejects the transition unless the project is currently archived.

NameTypeReqDescription
idstringyesarchived project id to restore
NameTypeReqDescription
resultyes

No examples provided.

rollback_site ~59

Re-point a site to any finalized version (rollback or roll-forward). Get version ids from get_site. Serving updates immediately.

NameTypeReqDescription
slugstringyessite slug to re-point
versionIdstringyesfinalized version id from get_site
NameTypeReqDescription
resultyes

No examples provided.

send_broadcast ~101

Send a campaign to this test's confirmed (double-opt-in) subscribers — the "we're live" email. An unsubscribe link is added automatically. Fails if there are no confirmed subscribers yet.

NameTypeReqDescription
htmlstringyesemail HTML body (unsubscribe link added automatically)
subjectstringyesemail subject line
testIdstringyesdemand test id whose confirmed subscribers to email
textstringplain-text fallback body
NameTypeReqDescription
resultyes

No examples provided.

send_email ~111

Send an email from <slug>.shiply.now's managed sender. The site can send transactional/notification email — no SMTP setup. Rate-limited and spam-checked; replies route back to the site inbox.

NameTypeReqDescription
htmlstringyesemail HTML body
slugstringyessite slug to send from (<slug>.shiply.now sender)
subjectstringyesemail subject line
textstringplain-text fallback body
tostringyesrecipient email address
NameTypeReqDescription
resultyes

No examples provided.

send_mailbox_broadcast ~115

Send a one-shot broadcast to the confirmed (double-opt-in) subscribers of a (site, collection) mailbox. Spam-checked; unsubscribe footer auto-added. Fails if no confirmed subscribers exist yet.

NameTypeReqDescription
collectionstringyesmailbox collection whose confirmed audience to email
htmlstringyesemail HTML body (unsubscribe footer added automatically)
slugstringyessite slug the mailbox belongs to
subjectstringyesemail subject line
textstringplain-text fallback body
NameTypeReqDescription
resultyes

No examples provided.

set_cron ~101

Set or update a cron trigger on a site's deployed function. Schedule is crontab syntax (UTC). Path is the URL the cron handler should fire on (for the worker's scheduled() handler context).

NameTypeReqDescription
pathstringyesURL path the cron handler fires on
schedulestringyescrontab schedule in UTC, e.g. "0 * * * *"
slugstringyessite slug whose function gets the cron
NameTypeReqDescription
resultyes

No examples provided.

set_handle ~109

Give ONE site a vanity URL: rename it to <handle>.shiply.now (3-30 chars, a-z 0-9 -). The old address 301-redirects for 30 days. (For a portfolio page listing all your sites, use set_profile instead — that lives at shiply.now/@<handle>.)

NameTypeReqDescription
handlestringyesnew vanity handle, 3-30 chars a-z 0-9 -
slugstringyescurrent site slug
NameTypeReqDescription
resultyes

No examples provided.

set_link ~139

Path-mounting: serve an owned target site at a path on an owned host site (host/docs -> target). location is a path like "docs", or "__root__" for the host root. Both sites must be owned by you. Pass remove=true to unmount.

NameTypeReqDescription
hostSlugstringyesslug of the owned host site
locationstringyespath to mount at, e.g. "docs", or "__root__" for the host root
removebooleanunmount instead of mounting
targetSlugstringslug of the owned site to serve there (required unless remove=true)
NameTypeReqDescription
resultyes

No examples provided.

set_mailbox ~149

Turn a Site Data collection into a mailbox: double opt-in, owner notifications, sending domain, branding. Call once per (site, collection) to configure how captured leads are handled.

NameTypeReqDescription
brandingobjectbranding applied to mailbox emails
collectionstringyesSite Data collection to turn into a mailbox
doubleOptInbooleanrequire email confirmation before a contact is active
notifyOwnerbooleanemail the owner on each new capture
notifyTostringaddress to send owner notifications to
sendingDomainIdstringBYO sending domain id to send from
slugstringyessite slug the collection belongs to
NameTypeReqDescription
resultyes

No examples provided.

set_primary_subdomain ~123

Mark a hostname as the primary (canonical) URL for its site. Sibling hostnames (apex + www both pointed at the same site) start 301-redirecting to it, preserving path + query. The host-side fix for the duplicate-content SEO problem. The first subdomain you add for a site is primary by default; call this only when you need to switch.

NameTypeReqDescription
domainstringyesregistered custom domain, e.g. example.com
hostnamestringyesfull hostname to make primary, e.g. www.example.com
NameTypeReqDescription
resultyes

No examples provided.