CircleCI
Diagnose failed builds, read job logs, inspect test results and rerun or roll back deployments from your AI assistant.
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Base44 MCP server lets Claude, ChatGPT or any MCP-compatible agent build and modify apps on Base44, the AI app builder Wix acquired in 2025. An agent can create a project from a description, edit an existing one, read its entity schemas and query the records its users submitted. Sign-in is OAuth, and a Builder plan is required.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
prompts/list, so we cannot say whether the server serves any.edit_base44_app is a natural-language dispatcher. Its effective surface is whatever the Base44 builder can do, and the documentation does not bound that. The sandbox tools are the reviewable alternative.query_entities is undocumented. Base44 documents row-level and field-level security for an app's own users, but neither the MCP page nor the security page says whether a builder-side query is subject to them. Silence, not a guarantee.PREMIUM_REQUIRED.RATE_LIMITED.sandbox:write — you must reconnect.Base44 documents sixteen; Anthropic's directory snapshot lists five. The five in the directory are real and still documented, but the docs add seven sandbox tools, two internal build-polling tools, and two connector tools. The gap matters because the eleven unlisted tools include a shell command, a file writer and a file editor — the highest-privilege part of the surface.
No, not to the public site. Base44 documents that a sandbox write commits to the app's active branch as part of the same request, so it appears in the app editor and its live preview straight away. Reaching the app's public site still takes the same separate publish step a change made in the editor would. Editing is not publishing.
Yes, through checkpoints. Base44 documents `create_checkpoint` as saving a named restore point anchored to a specific commit, which you restore from the app editor if a later change goes wrong. Pending changes are flushed and committed first so the checkpoint captures the latest code. Base44 also states every sandbox change lands in git rather than in the compute process.
Records from your app's entities — the tables holding whatever your app's end users submitted. Base44 documents entities as its MongoDB-compatible data model and names form submissions and survey answers among the records stored there. Base44's own deletion guidance treats those tables as a place personal data lives, and states the app owner is responsible for handling it lawfully.
Base44's documentation does not say. Its security page defines row-level and field-level rules governing what an app's users can access, but the MCP page describes the assistant's reach in terms of your own workspace role instead. Whether builder-side reads through `query_entities` are subject to those rules is not stated on either page. Treat the surface as unbounded until Base44 documents otherwise.
Yes. Base44's MCP documentation states a Builder plan or higher is required to connect an AI assistant through the server. The same requirement gates the sandbox tools from outside the app editor, where calls without it fail with `PREMIUM_REQUIRED`. Base44 also notes a workspace viewer or guest cannot create projects, whatever plan the workspace is on.
Exactly one, chosen at the OAuth consent step. Base44 documents that every action runs in the workspace you pick, that the connection cannot reach any other, and that the choice is fixed for the life of the connection. Targeting a different workspace means connecting again. Base44 re-checks your membership on every request and every token refresh.
.md suffix; this is the URL Anthropic's directory publishes) · retrieved 2026-08-19docs.base44.com/robots.txt allows the docs paths and carries Content-Signal: ai-train=yes, search=yes, ai-input=yes — synthesis is expressly permitted on all three axes (fetched 2026-08-19). app.base44.com/robots.txt is a bare Disallow: with no path, which permits everything · retrieved 2026-08-19POST to the endpoint returns HTTP 307 to /mcp/, which returns HTTP 401 with www-authenticate: Bearer error="invalid_token", resource_metadata="https://app.base44.com/.well-known/oauth-protected-resource/mcp" · retrieved 2026-08-19Connect Base44 once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.