Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Supero

REMOTE · API.SUPERO.DEV · SCANNED SEP 30

Build multi-tenant apps over MCP. Schemas, CRUD, deploys — access control enforced server-side.

Available components

+3 this week 85 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security89
Transport & Reachability100
Schema Quality & AI Usability85
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 7502 tokens (~115/item across 65 items; 64 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management67
  • Stability observed for 20 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage96
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 87% of tool parameters carry a description.Partial
Tool Safety95
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 4 of 5 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "build_deploy_status" implies "deploy" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
  • An AI judge read all 66 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities40
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the Supero MCP server?

Supero is a hosted endpoint at https://api.supero.dev/mcp/v1/messages, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · api.supero.dev

# add to Claude Code
claude mcp add --transport http supero-platform-supero 'https://api.supero.dev/mcp/v1/messages'
// .cursor/mcp.json
{
  "mcpServers": {
    "supero-platform-supero": {
      "url": "https://api.supero.dev/mcp/v1/messages"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "supero-platform-supero": {
      "type": "http",
      "url": "https://api.supero.dev/mcp/v1/messages"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.supero-platform-supero]
url = "https://api.supero.dev/mcp/v1/messages"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "supero-platform-supero": {
      "type": "remote",
      "url": "https://api.supero.dev/mcp/v1/messages",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add supero-platform-supero --url 'https://api.supero.dev/mcp/v1/messages' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  supero-platform-supero:
    url: "https://api.supero.dev/mcp/v1/messages"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "supero-platform-supero": {
      "Transport": "http",
      "Url": "https://api.supero.dev/mcp/v1/messages"
    }
  }
}
# add to Vellum
assistant mcp add supero-platform-supero -t streamable-http -u 'https://api.supero.dev/mcp/v1/messages'
// mcp.json
{
  "mcpServers": {
    "supero-platform-supero": {
      "type": "http",
      "url": "https://api.supero.dev/mcp/v1/messages"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 23 Sept 26 +5
    • HTTPS: unverified → pass ▲ security
  • 22 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 30 Sept 2026 · Probed https://api.supero.dev/mcp/v1/messages

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=supero.dev CN=WE1,O=Google Trust Services,C=US 25 Aug 2026 23 Nov 2026 ECDSA 256 ECDSA-SHA256 71652014602d07d113add22c16ee272c
SANs: supero.dev, *.supero.dev
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of api.supero.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
supero.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Challenged, unverified

The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.

Result Challenged, unverified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer realm="Supero MCP"

Bearer realm="Supero MCP"
Header Value
strict-transport-security max-age=31536000; includeSubDomains

Protected resource metadata

Retrieved No
Problem no_resource_metadata

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.supero.dev/mcp/v1/messages Verified 200
http (plaintext) http://api.supero.dev/mcp/v1/messages HTTPS enforced 301 https://api.supero.dev/mcp/v1/messages
MCP tools · 64 exposed · ~7,379 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
apikey_get_scope ~21

Get the scope and permissions of the current API key.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

build_bind_data_source ~128

Bind source streams to the app's schemas. mode='live_read' (default: read-only BYODB / warehouse), 'live_readwrite' (BYODB read+write — DOMAIN-ADMIN only), or 'sync' (copy into SuperoDB). For live modes, discovery must have run and each binding's `source` must match a discovered stream; the bind VERIFIES the live mapping materialized. Bound live schemas are read/written via ORDINARY app CRUD — nothing goes in the bundle.

NameTypeReqDescription
bindingsarrayyes–
connector_idstringyes–

No output schema declared.

No examples provided.

build_configure_services ~201

Configure a service's keys for the project so an integration works at deploy (e.g. wire SendGrid for email, a Stripe TEST key for checkout). TEST/SANDBOX keys ONLY. Keys with a clear live marker (Stripe sk_live_… / Razorpay rzp_live_…) are auto-refused, but most providers give NO test-vs-live signal — so for EVERY provider send test/sandbox keys only and use the admin panel for production secrets (a deep link is returned). Never put a real secret through this tool/chat. Reacts to the live permission result; secret values are never echoed.

NameTypeReqDescription
configobjectyesTest/sandbox config key→value (e.g. {"sendgrid_api_key":"SG.test…"}). Live-marked keys refused; send test keys only.
project_uuidstringyes–
service_idstringyesCatalog id (e.g. 'stripe_checkout', 'email').

No output schema declared.

No examples provided.

build_connect_data_source ~306

Create a data connector to an EXTERNAL source the app owner controls (their own database, a REST API, or a warehouse). Returns a connector_id. Does NOT bind schemas yet — run build_discover_source then build_bind_data_source. Credentials are sent to the platform and NEVER echoed back; prefer read-only DB creds / the Key Store for production. Requires a domain- or project-admin API key.

NameTypeReqDescription
authobject–api kind: {type: none|api_key|bearer|basic|oauth2, ...}.
base_urlstring–api kind: API base URL.
configobject–Extra source config (e.g. warehouse account).
databasestring––
db_typestring–database/warehouse: postgresql|mysql|mssql|oracle|mongodb|snowflake|bigquery|redshift|databricks|clickhouse|fabric.
endpointstring–api kind: endpoint path.
hoststring––
kindstringyesSource kind.
namestringyesConnector name (unique within the project).
passwordstring–DB password — sent to the platform, never echoed.
portinteger––
schema_namespacestring–Namespace for schemas from this source.
ssl_modestring––
test_firstboolean–Probe connectivity before creating (default true).
usernamestring––

No output schema declared.

No examples provided.

build_create_project ~136

Create a NEW project (domain-admin keys only; plan-gated). Mints the project's schema_namespace + an API key (returned ONCE). Use for a fresh app.

NameTypeReqDescription
descriptionstring–Optional: what the app is for — persisted on the project so future sessions build to it.
display_namestring––
namestringyesProject name/slug.
requirementsarray–Optional: the confirmed requirements/plan bullets — persisted on the project record (future sessions read them via build_get_project).
schema_namespacestring–Optional; server normalizes/derives if omitted.

No output schema declared.

No examples provided.

build_deploy ~131

Deploy a published version. target='cloud_ephemeral' (managed Cloud Run, ~30m throwaway preview; requires platform enablement; the default when cloud deploy is enabled) or 'local' (hand the user the bundle to run with the project's own key). For a PERMANENT public URL, use build_go_live instead.

NameTypeReqDescription
app_typestring–Default 'web'.
project_uuidstringyes–
targetstring–Default 'cloud_ephemeral' when cloud deploy is enabled (else 'local').
version_uuidstring–Default: latest published version.

No output schema declared.

No examples provided.

build_deploy_status ~91

Poll a cloud deploy started by build_deploy or build_go_live. Pass the poll_url it returned. Reports elapsed_s since launch; a launch still pending after ~5 minutes should be treated as failed.

NameTypeReqDescription
permanentboolean–Set true when polling a build_go_live (permanent) deploy so the expiry guidance is correct. Default: auto-detected.
poll_urlstringyes–

No output schema declared.

No examples provided.

build_discover_source ~164

Discover a connector's schema: trigger discovery, wait, and return the source streams (names, columns, primary keys), AI-inferred Supero schemas, field mappings, and a suggested namespace. Run AFTER build_connect_data_source and BEFORE build_bind_data_source (a live bind's `source` MUST equal a discovered stream name).

NameTypeReqDescription
connector_idstringyes–
execution_idstring–RESUME polling an in-flight discovery (from a previous timeout error) instead of starting a new job.
timeoutinteger–Max seconds to wait IN THIS CALL (default 60, cap 90 — an MCP call must finish under the ~100s edge limit). On timeout, resume with the returned execution_id; the job keeps running server-side.

No output schema declared.

No examples provided.

build_doctor ~214

PREFLIGHT a bundle BEFORE publish/deploy — catches the silent deploy-killers build_validate does NOT: missing #supero-preloader removal (app stuck on a spinner forever), heavy startup seed (Cloud Run port-bind timeout → 'container failed to start'), reserved field names like status/state (silently dropped), namespace collisions (ambiguous reads), and services needing elevated import permission. Run it after build_validate and before build_publish.

NameTypeReqDescription
filesobjectyesMap of {relative_path: file_content}.
files_b64gzstring–Alt to files: base64(gzip(JSON {path:content})).
files_refstring–For a LARGE bundle that exceeds the model output-token cap: a file_id from build_stage_bundle (upload the gzip(json {path:content}) blob out-of-band, then pass its file_id here). Preferred over files…
project_uuidstring–Target project (enables namespace + collision checks).

No output schema declared.

No examples provided.

build_e2e_test ~300

Run the FULL behavioural test suite against a PUBLISHED bundle in the project's OWN already-deployed app (no throwaway project is created) — auth/RBAC/multi-tenant, CRUD round-trips, workflows + event emission, services, aggregates, real-browser UI. WRITE-SAFE: on a DEV project the write suites create + delete only their OWN test records (your real data stays read-only); a LIVE project is auto-restricted to read-only suites so production data is never mutated. This is the deep complement to build_smoke_test ('loads + reads one row'); it proves the app actually WORKS. COSTS A FULL RUN (~2-4 min of real compute) — a PRE-DELIVERY gate, NOT a per-edit check; run it after build_validate + build_doctor pass, on a deployed + seeded project. ASYNC: returns a run_id; poll build_e2e_test_status. Findings are layer-attributed so you know which are yours to fix (app/config) vs. report (platform/sdk). Requires platform enablement.

NameTypeReqDescription
live_emailboolean–Actually send a test email (default false → audit-only).
project_uuidstringyesThe project the published bundle belongs to.
suitesarray–Subset to run (default ['all']). Skipping a core suite caps the verdict.
version_uuidstring–Published version to test. Default: latest.

No output schema declared.

No examples provided.

build_e2e_test_status ~118

Poll an e2e run started by build_e2e_test. While running, returns status only. When complete, returns a compact report: verdict (honest — never 'healthy' if a core suite couldn't run), per-suite pass/fail/warn/skip, findings with layer + fix hint, what was/wasn't covered, and next_steps that say which findings to fix vs. report. On failure it carries a cause.

NameTypeReqDescription
run_idstringyesThe run_id from build_e2e_test.

No output schema declared.

No examples provided.

build_get_bundle ~134

Fetch the CURRENT (or a given) PUBLISHED bundle: the file list + a signed download_url, or ONE file's content inline via file=. For ANY change request on an existing app, START from this bundle and modify it — re-authoring from scratch silently drops the hand-authored ui/app.js and every prior fix.

NameTypeReqDescription
filestring–Optional app-root-relative path (e.g. 'ui/app.js') to return that single file's content inline (~120KB cap, truncated with a note).
project_uuidstringyes–
version_uuidstring–Default: latest published version.

No output schema declared.

No examples provided.

build_get_examples ~276

Fetch a COMPLETE, production-quality reference app (schemas.py + config.py + setup.py + ui/app.js) to copy patterns from — the single biggest lever for app quality. archetype='index' (default) lists the available archetypes with per-file byte sizes; pick the one closest to your app ('commerce-marketplace' | 'service-booking' | 'ops-dashboard' | 'multitenant-portal' | 'saas-billing') and fetch it BEFORE authoring your UI. These are real 'stunning' apps; mirror how they compose the SDK components, art-direct the landing page, and structure schemas. Optional file= to fetch just one file ('schemas.py' | 'config.py' | 'setup.py' | 'ui/app.js'). Responses are PAGED (~32KB/section): when the header says more:true, fetch the next section with offset=<next_offset> — never re-fetch from 0.

NameTypeReqDescription
archetypestring–Which reference app (default 'index' to list them).
filestring–Optional: return only this one file instead of the whole bundle.
max_bytesinteger–Max bytes to return per section (default ~32000).
offsetinteger–Byte offset to start from (for paging; default 0).

No output schema declared.

No examples provided.

build_get_project ~115

Get one project's details: schema_namespace (use this EXACT value as the `namespace` literal on every schema dict), last published version, AND the captured `project_intent` — the brief (project_description/summary), the discovered data model (entities/central_entity/relationships/status_workflows), and the landing intent (public_landing_view). BUILD TO THIS — it's the authoritative app spec the user already gave; don't re-ask or ignore it.

NameTypeReqDescription
project_uuidstringyesProject UUID (from build_list_projects).

No output schema declared.

No examples provided.

build_get_service_contract ~241

Fetch the AUTHORITATIVE contract for a transactional/stateful platform service (cart, order, payment, booking, appointment, membership, approval, document_signature, recurring_plan, inventory, task, ticket, loyalty_points, rental, comment, attachment, feedback, notification, product, service, customer, workflows). Returns the service's state machine (initial_state + transitions), its operations (op ids + input fields + resulting state), the base schemas + mandatory fields you must supply, AND the platform's DEFAULT UI SCHEMAS for that service — the bulletproof reference for building a correct, sophisticated transactional UI. ALWAYS call this for any service your app `extends` BEFORE authoring its UI — do not guess op names, states, or mandatory fields from prose. service_id='index' (default) lists all services.

NameTypeReqDescription
partsstring–What to return (default 'both'): 'contract' = state machine/ops/schemas; 'ui_schemas' = default UI only.
service_idstring–The service id (e.g. 'cart', 'booking', 'payment'); 'index' (default) lists all.

No output schema declared.

No examples provided.

build_get_skills ~277

Fetch a Supero build reference. doc='skills' (default, the spec you MUST follow) | 'components' (the real pre-built SDK component/global catalog — read so you don't reinvent UI) | 'rubric' (the rich-app quality checklist — what 'stunning' means) | 'landing' (compact landing-page derivation + quality bar — MANDATORY read for public-facing apps) | 'integrations' (the EXACT services.* wrapper→service_id→args map for email/sms/stripe/ai/etc.) | 'web' / 'transactional' / 'workflows' / 'mobile' / 'services' (deep companion docs) | 'e2e_testing'. Returns the doc + a content version + the SDK floor to pin. Read 'skills' FIRST, then 'components' + a matching build_get_examples before you author UI. Docs are PAGED (~32KB/section): when the header says more:true, fetch the next section with offset=<next_offset> — never re-fetch from 0.

NameTypeReqDescription
docstring–Which doc (default 'skills').
max_bytesinteger–Max bytes to return per section (default ~32000).
offsetinteger–Byte offset to start from (for paging large docs; default 0).

No output schema declared.

No examples provided.

build_go_live ~162

PERMANENT deploy: promote a published version to a PERMANENT public URL at <service>.supero.live (managed Cloud Run) — unlike build_deploy(target='cloud_ephemeral'), which is a ~30-min throwaway. If version_uuid/file_id are omitted, the latest published version for the project is used. Returns public_url + poll_url; poll with build_deploy_status until live, then build_smoke_test the public_url. build_teardown removes it. Requires a domain- or project-admin API key + platform cloud-deploy enablement.

NameTypeReqDescription
file_idstring–Default: the resolved version's web artifact file_id.
project_uuidstringyes–
version_uuidstring–Default: latest published version.

No output schema declared.

No examples provided.

build_list_bound_schemas ~86

Classify this project's schemas: which are connector-backed vs app-authored, and each one's access mode (sync | live-ro | live-rw | warehouse). Use it so you DON'T render create/edit UI for read-only live sources (live-ro/warehouse) or regenerate/overwrite connector-discovered schemas.

NameTypeReqDescription
project_uuidstring–Defaults to the key's project.

No output schema declared.

No examples provided.

build_list_capabilities ~176

List the platform's available services/integrations from the LIVE catalog (email, sms, slack, ai, stripe_checkout, google_oauth, push_notification, …) — so the intake's 'which connections/integrations?' question is accurate and you never guess a service id. Returns each service's exact catalog `service_id` (use it verbatim in config.py `services` — e.g. 'stripe_checkout', NOT 'stripe'), category, whether it needs a key, and YOUR connection's service permissions (can_import / can_configure). Descriptive — what EXISTS, never what to use. Pass service_id for one service's config fields.

NameTypeReqDescription
categorystring–Optional filter ('integration' or 'service').
service_idstring–Optional: one service's detail incl. config fields.

No output schema declared.

No examples provided.

build_list_data_sources ~110

List the external DATA SOURCE types an app can connect to — its own Postgres/MySQL/MSSQL/Oracle/MongoDB, any REST API, or a Snowflake/BigQuery/Redshift/Databricks/ClickHouse/Fabric warehouse — plus the curated public-API catalog. Read this to offer a 'connect your own data' option. Flow: build_connect_data_source → build_discover_source → build_bind_data_source. See build_get_skills(doc='connectors').

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

build_list_projects ~39

List projects you can build into (uuid, name, schema_namespace, live_url).

NameTypeReqDescription
limitinteger–Max results (default 50).

No output schema declared.

No examples provided.

build_logs ~101

Fetch recent Cloud Run logs for a project's deployed app — THE tool for diagnosing a failed/stalled cloud deploy or a crashing app (startup-probe timeouts, tracebacks, 'container failed to start on PORT'). Read-only; rate-limited per domain.

NameTypeReqDescription
linesinteger–Max log lines to return (default 200).
project_uuidstringyes–
sinceinteger–How many minutes back to fetch (default 60).

No output schema declared.

No examples provided.

build_plan ~264

PLAN FIRST — turn a one-line app idea into an explicit BUILD CHECKLIST before you author anything, so a thin prompt doesn't silently skip what expert builders add (this is exactly why first-draft apps miss detail pages, tenant pickers, seed data). Deterministic, no LLM: it detects the app's VERTICAL and returns the authentic page structure + terminology for that domain, which entities need a full DETAIL PAGE, the multi-tenant login pattern (picker + tenant=''), seed guidance, and which build_get_examples to copy. Call it right after build_get_skills and BEFORE authoring.

NameTypeReqDescription
descriptionstringyesThe app idea in a sentence or two (e.g. 'portal for Karnataka polytechnic colleges with admin + student portals').
entitiesarray–Optional: the main entity/noun names (e.g. ['college','course','student']). Sharpens the per-entity detail-page + seed guidance.
is_multi_tenantboolean–Optional: true if each customer/org (college/clinic/branch) is a separate tenant. Inferred from the description if omitted.
public_facingboolean–Optional: true if end-users/the public browse it (vs an internal-only tool). Inferred if omitted.

No output schema declared.

No examples provided.

build_publish ~212

Package + upload your authored bundle and record a version under the project. Returns version_uuid + file_id + download_url. Runs build_validate first unless force=true. Provide files as {relative_path: content}.

NameTypeReqDescription
app_typestring–Default 'web'.
filesobjectyesMap of {relative_path: file_content}.
files_b64gzstring–Alt to files: base64(gzip(JSON {path:content})). Use if a CDN/WAF blocks raw code in the body.
files_refstring–For a LARGE bundle that exceeds the model output-token cap: a file_id from build_stage_bundle (upload the gzip(json {path:content}) blob out-of-band, then pass its file_id here). Preferred over files…
forceboolean–Publish even if validation has errors (default false).
project_uuidstringyes–
validateboolean–Validate before publish (default true).

No output schema declared.

No examples provided.

build_recommend_integrations ~236

RECOMMEND which concrete provider integrations this app needs, and WHY — the deterministic Step-2 intelligence the web wizard uses, now over MCP. Pass the app `description` + the platform `service_ids` it will use (e.g. ['cart','order']); returns GROUPED, TIERED suggestions (required/recommended/optional) with the default option flagged — e.g. cart/checkout → a payment gateway (REQUIRED; stripe_checkout default, paypal/razorpay offered), customer-facing apps → transactional email, appointments+reminders → sms. Options are drawn ONLY from the LIVE installed manifests, so it can't suggest a provider you don't have. PRESCRIPTIVE complement to build_list_capabilities (which is descriptive): call this so you don't OMIT a needed integration; use build_list_capabilities for a service's exact id + config fields.

NameTypeReqDescription
descriptionstring–The app description / intent (drives email/sms/oauth/ai/payment triggers).
service_idsarray–Platform service ids the app will use (e.g. ['cart','order','appointment']). Drives most recommendations.

No output schema declared.

No examples provided.

build_replace_project ~243

DESTRUCTIVE (DOMAIN-admin keys only): completely replace a DEV-mode project's app — wipes its data (retains credentials, API keys, namespace, tenant). Refused if mode='live'. Requires confirm_project_name to match. If you pass files, they are VALIDATED before any wipe (a bad bundle is a no-op) and published after; otherwise wipe-only, then call build_publish.

NameTypeReqDescription
app_typestring––
confirm_project_namestringyesMust equal the project's name — a safety confirmation.
filesobject–Optional new bundle {path: content} to publish after the wipe.
files_b64gzstring–Alt to files: base64(gzip(JSON {path:content})). Use if a CDN/WAF blocks raw code in the body.
files_refstring–For a LARGE bundle that exceeds the model output-token cap: a file_id from build_stage_bundle (upload the gzip(json {path:content}) blob out-of-band, then pass its file_id here). Preferred over files…
project_uuidstringyes–

No output schema declared.

No examples provided.

build_run_data_source ~97

Trigger a SYNC RUN on a data connector and return the run id. MCP-created connectors are trigger:manual, so a mode='sync' binding copies NO rows until a run executes — call this after build_bind_data_source (and again whenever the source data changes). Live-read/warehouse bindings don't need runs (they read the source directly).

NameTypeReqDescription
connector_idstringyesThe connector to run (from build_connect_data_source).

No output schema declared.

No examples provided.

build_set_project_mode ~67

Set a project's build mode. 'dev' (default) allows COMPLETE REPLACE (wipe data, keep credentials); 'live' protects it. Switch to dev before replacing, to live when it's in production.

NameTypeReqDescription
modestringyes–
project_uuidstringyes–

No output schema declared.

No examples provided.

build_smoke_test ~348

VERIFY a DEPLOYED app actually works (not just 'running'). HTTP-checks the live URL: root loads with a title, app.js is your bundle (not a stub) and dismisses the boot splash, config.js namespace matches the project; optionally logs in and reads an entity to confirm data + no namespace ambiguity. Pass url= (from build_deploy_status) or poll_url=. THE post-deploy gate — run it after every deploy.

NameTypeReqDescription
emailstring–Optional — a user to log in and verify data reads.
entitystring–Optional bare schema slug (e.g. 'participant') to read for the authed data check.
expected_app_js_sha1string–Optional — the first 12 lowercase hex chars of `sha1sum ui/app.js` (sha1 of your local bundle FILE). If given, smoke_test reports whether the DEPLOYED app.js matches, so you can confirm the deploy ac…
passwordstring–Optional — password for that user.
poll_urlstring–Alt to url: the build_deploy poll_url; the URL is resolved from it.
project_uuidstringyesThe deployed project (for namespace + live_url).
tenantstring–Optional tenant for the login. Default '' so the server resolves the user's OWN tenant (required for a multi-tenant app whose test user lives in a named tenant).
urlstring–The deployed app URL (from build_deploy_status).

No output schema declared.

No examples provided.

build_stage_bundle ~112

PUB-1a: get the out-of-band UPLOAD endpoint for a LARGE app bundle that won't fit inline (the model's max OUTPUT tokens cap `files`/`files_b64gz`, so big apps otherwise have to be truncated/minified). Upload a gzip(json {path:content}) blob to the returned URL with your OWN key, then pass the returned file_id as `files_ref` to build_validate / build_publish / build_doctor. Bundle size then no longer depends on any token cap.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

build_teardown ~132

Tear down a project's live deployment — BOTH the permanent (build_go_live) app and the ephemeral preview — DELETEing the managed Cloud Run services and freeing their URLs. Idempotent: a project with nothing deployed returns stopped=true. ONLY manages Supero-hosted apps — a project deployed to your own AWS/GCP is refused, not silently reported stopped. Check `stopped`: false means the teardown was INCOMPLETE and the app may still be serving (and billing) — re-run it, do not report success. Requires a domain- or project-admin API key.

NameTypeReqDescription
project_uuidstringyes–

No output schema declared.

No examples provided.

build_update_project ~43

Update a project's metadata (display_name, description, show_public, live_url).

NameTypeReqDescription
patchobjectyesFields to update.
project_uuidstringyes–

No output schema declared.

No examples provided.

build_validate ~186

Validate a locally-authored bundle against the live platform BEFORE publishing. AST-only (your code is never executed). Checks manifest, syntax, import-safety, config exports, schema validity, and namespace==project schema_namespace.

NameTypeReqDescription
filesobjectyesMap of {relative_path: file_content} for the bundle.
files_b64gzstring–Alt to files: base64(gzip(JSON {path:content})). Use if a CDN/WAF blocks raw code in the body.
files_refstring–For a LARGE bundle that exceeds the model output-token cap: a file_id from build_stage_bundle (upload the gzip(json {path:content}) blob out-of-band, then pass its file_id here). Preferred over files…
project_uuidstring–Target project (for namespace/schema checks).

No output schema declared.

No examples provided.

build_whoami ~43

Resolve your API key's scope: role (domain_admin/project_admin), domain, whether you can create projects, and your plan. Call this to decide the flow.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

connector_cancel ~40

Cancel a running connector execution.

NameTypeReqDescription
connector_idstringyesUUID of the connector.
execution_idstringyesUUID of the execution to cancel.

No output schema declared.

No examples provided.

connector_disable ~24

Disable a connector.

NameTypeReqDescription
connector_idstringyesUUID of the connector.

No output schema declared.

No examples provided.

connector_discover ~40

Trigger schema/metadata discovery for a connector.

NameTypeReqDescription
connector_idstringyesUUID of the connector.
paramsobject–Optional discovery parameters.

No output schema declared.

No examples provided.

connector_discover_results ~39

Get discovery results.

NameTypeReqDescription
connector_idstringyesUUID of the connector.
execution_idstringyesUUID of the discovery execution.

No output schema declared.

No examples provided.

connector_discover_status ~40

Get discovery execution status.

NameTypeReqDescription
connector_idstringyesUUID of the connector.
execution_idstringyesUUID of the discovery execution.

No output schema declared.

No examples provided.

connector_enable ~26

Enable a connector for scheduling.

NameTypeReqDescription
connector_idstringyesUUID of the connector.

No output schema declared.

No examples provided.

connector_plugins ~13

List available connector plugins.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

connector_run ~37

Trigger a manual connector sync execution.

NameTypeReqDescription
connector_idstringyesUUID of the connector.
paramsobject–Optional execution parameters.

No output schema declared.

No examples provided.

connector_status ~27

Get connector status and recent executions.

NameTypeReqDescription
connector_idstringyesUUID of the connector.

No output schema declared.

No examples provided.

connector_test ~27

Test an existing connector's connectivity.

NameTypeReqDescription
connector_idstringyesUUID of the connector.

No output schema declared.

No examples provided.

connector_test_config ~25

Test a connector configuration.

NameTypeReqDescription
configobjectyesConnector config to test.

No output schema declared.

No examples provided.

crud_create ~178

Create a new object in the current domain. Use schema_list to see available types and their fields.

NameTypeReqDescription
dataobject–Object fields as key-value pairs
namestringyesObject name (required for most types)
object_typestringyesThe object type to create (e.g. 'customer', 'appointment', 'project')
parent_fq_namearray–Parent FQ name path (e.g. ['cine-corp', 'car-service'])
parent_typestring–Parent type if applicable (e.g. 'project' for tenant, 'domain' for project)
tenantstring–Optional tenant name to create the object under (multi-tenant apps: seed a specific named tenant's data). Omit for single-tenant apps — the session/API-key tenant is used.

No output schema declared.

No examples provided.

crud_delete ~80

Delete an object from the current domain.

NameTypeReqDescription
object_typestringyesThe object type
tenantstring–Optional tenant name context for this delete (multi-tenant apps). Omit for single-tenant apps — the session/API-key tenant is used. Deletes address the record by UUID.
uuidstringyesObject UUID to delete

No output schema declared.

No examples provided.

crud_get ~51

Get a specific object by UUID from the current domain.

NameTypeReqDescription
object_typestringyesThe object type (e.g. 'customer', 'project', 'tenant')
uuidstringyesObject UUID

No output schema declared.

No examples provided.

crud_search ~211

Search/list objects of any type in the current domain. Use schema_list first to discover available object types. System types: project, tenant, user_account, api_key, connector, audit_log, schema_registry, client_sdk, connector_execution, connector_plugin. Domain types vary per domain (e.g. customer, invoice, appointment, vehicle).

NameTypeReqDescription
detailboolean–Include full object data (default: true)
filtersobject–Filter criteria as key-value pairs (e.g. {"status": "active"})
limitinteger–Max results (default: 100)
object_typestringyesThe object type to search (e.g. 'customer', 'project', 'tenant', 'connector')
offsetinteger–Skip N results for pagination
tenantstring–Optional tenant name to scope the search to (multi-tenant apps: verify a specific named tenant's data). Omit for single-tenant apps — the session/API-key tenant is used.

No output schema declared.

No examples provided.

crud_update ~91

Update an existing object in the current domain.

NameTypeReqDescription
dataobjectyesFields to update
object_typestringyesThe object type
tenantstring–Optional tenant name context for this update (multi-tenant apps). Omit for single-tenant apps — the session/API-key tenant is used. Updates address the record by UUID.
uuidstringyesObject UUID to update

No output schema declared.

No examples provided.

Common questions

What is the Supero MCP server?

Supero is an MCP server listed in the public MCP registry as io.github.supero-platform/supero. Build multi-tenant apps over MCP. Schemas, CRUD, deploys, access control enforced server-side. This page covers its hosted endpoint (https://api.supero.dev/mcp/v1/messages).

Is the Supero MCP server safe to use?

Supero scores 85 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Supero MCP server expose?

Supero exposes 64 tools: crud_search, crud_get, crud_create, crud_update, crud_delete, and 59 more. Their descriptions and schemas cost roughly 7,379 tokens of context every time the server is loaded.

Does the Supero MCP server require authentication?

Yes. Supero asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the Supero MCP server still maintained?

Supero is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.