CodeWords MCP server icon

CodeWords

by CodeWords

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity20 tools

Let your AI agent write, deploy and run automations on CodeWords from chat. 20 tools, OAuth sign-in, a paid-plan gate, one that executes code and four that manage your stored credentials.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect CodeWords via MCP

https://runtime.codewords.ai/run/devx_mcp/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Use in Agentman

Connect CodeWords once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

CodeWords Tools & Capabilities (20)

consult_docs
search_templates
edit_service
deploy_service
validate_service
run_code
get_workflow_requests
get_workflow_logs
get_workflow_output
cancel_workflow
list_user_secrets
get_user_secret
set_user_secret
delete_user_secret
run_workflow
view_service_code
list_service_implementations
set_active_implementation
list_user_services
todo_write

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • The sandbox boundary is undocumented. CodeWords describes a secure sandbox with internet access and automatic software installation, and publishes no command allowlist, no network egress policy, no filesystem scope and no CPU or memory limit. The only published bounds are time: 30 minutes maximum sandbox lifetime, 120 seconds for a synchronous API run.
  • get_user_secret's return semantics are undocumented. CodeWords does not state whether it returns a credential value or a reference. Its "only the names of secrets are visible, never the values" line describes Cody's memory profile, a different subsystem.
  • Consent is coarse. The OAuth descriptor advertises two scopes, api:read and api:write. There is no way to grant deploy access while withholding credential access.
  • Paid plans only. Pro, Business or custom. CodeWords does not offer the connector on Free, and the same gate applies to its ChatGPT plugin and its REST API keys.
  • Credits meter everything that runs. CodeWords charges credits by complexity, step count, data size and AI usage, and says building costs more than running. Credits are prepaid, non-refundable and not redeemable for cash.
  • No rate limit is published for this endpoint. Our 401 responses carried no x-ratelimit-* headers, and CodeWords' documentation states none for the MCP surface. Absent documentation is not absent limits.
  • Recovery is not in the tool list. Version history with Preview and Restore exists in the CodeWords web app. None of the 20 tool names performs a restore.
  • We could not read tool schemas or annotations. The endpoint is OAuth-gated, so parameter detail and safety hints are unavailable to us. The read/write split on this page is inferred from names and documentation, not read from the protocol.
  • SOC 2 is in progress, not complete. CodeWords' security page states it is "currently in the process of getting our SOC 2 Type II compliance". Treat it as underway rather than held.
  • CodeWords may use some processed data to improve its systems. Its help centre says data processed through hosted or analytics services may be used to improve CodeWords systems and algorithms, while data from third-party integrations such as Google Workspace APIs is not used to train generalized models.

Frequently asked questions

Yes. CodeWords states the connector is a paid feature requiring an active Pro, Business or custom plan, and directs Free users to subscribe first. Pro is 39 dollars a month and Business is 100 dollars a month as documented in September 2026. Building in the Claude chat is free of CodeWords credits; credits are consumed when a workflow actually runs.

CodeWords does not document this, and we did not call the tool. The only related statement we found concerns Cody's memory, where CodeWords says only the names of secrets are visible and never the values. That sentence describes the memory profile, not this tool. Treat the return value as unknown and assume the agent can read what it fetches.

CodeWords does not publish a boundary. Its documentation describes a secure sandbox with internet access and automatic software installation, and states each run gets a fresh sandbox destroyed afterwards. Across the security page, the pricing page and the connector page there is no command allowlist, no network egress policy and no filesystem scope. Only time limits are published.

Thirty minutes at most. CodeWords documents a maximum sandbox lifetime of 30 minutes for complex workflows, with most runs finishing in seconds. Its API guide splits this by call type: synchronous runs must complete within 120 seconds, and asynchronous runs are designed for up to 30 minutes. The separate Web Agent browser tool carries its own 10-minute limit.

Through the CodeWords web app, not through the connector. CodeWords keeps a version history of automations built in chat, and documents Preview and Restore actions that make an older snapshot current again without deleting newer ones. No tool in this connector's 20 names performs a restore, so an agent cannot roll back its own change.

As environment variables under Settings then API Keys in the CodeWords web app. You add a variable name such as ASANA_API_KEY and paste the value, and CodeWords says keys are encrypted, stored in your environment, and not shared or exposed outside your workspace. Workflows then reference the variable by name rather than carrying the key itself.

No. The connector reaches your CodeWords account over an HTTPS endpoint, so it touches workflows, services, logs and secrets held in that account. CodeWords documents building, deploying and running as happening on its own cloud. Nothing in the tool set names a local path, and the transport gives the server no route to your filesystem.

OAuth for the connector. Our anonymous request returned HTTP 401 with an OAuth challenge pointing at codewords.agemo.ai, which advertises authorization code flow with PKCE and two scopes, api:read and api:write. CodeWords documents an Allow access screen during install. Its separate REST API uses bearer keys prefixed cwk- or cwotk-, which is a different surface.

Sources

Server Info

Category
Productivity
Developer
CodeWords
Tools
20
Domain
runtime.codewords.ai

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.

Ready to connect CodeWords?

Connect CodeWords once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.