CodeWords
by CodeWords
Let your AI agent write, deploy and run automations on CodeWords from chat. 20 tools, OAuth sign-in, a paid-plan gate, one that executes code and four that manage your stored credentials.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Connect CodeWords via MCP
https://runtime.codewords.ai/run/devx_mcp/mcpWorks in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.
Use in Agentman
Connect CodeWords once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.
Open in Agentman StudioCodeWords Tools & Capabilities (20)
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
Limits
- The sandbox boundary is undocumented. CodeWords describes a secure sandbox with internet access and automatic software installation, and publishes no command allowlist, no network egress policy, no filesystem scope and no CPU or memory limit. The only published bounds are time: 30 minutes maximum sandbox lifetime, 120 seconds for a synchronous API run.
get_user_secret's return semantics are undocumented. CodeWords does not state whether it returns a credential value or a reference. Its "only the names of secrets are visible, never the values" line describes Cody's memory profile, a different subsystem.- Consent is coarse. The OAuth descriptor advertises two scopes,
api:readandapi:write. There is no way to grant deploy access while withholding credential access. - Paid plans only. Pro, Business or custom. CodeWords does not offer the connector on Free, and the same gate applies to its ChatGPT plugin and its REST API keys.
- Credits meter everything that runs. CodeWords charges credits by complexity, step count, data size and AI usage, and says building costs more than running. Credits are prepaid, non-refundable and not redeemable for cash.
- No rate limit is published for this endpoint. Our 401 responses carried no
x-ratelimit-*headers, and CodeWords' documentation states none for the MCP surface. Absent documentation is not absent limits. - Recovery is not in the tool list. Version history with Preview and Restore exists in the CodeWords web app. None of the 20 tool names performs a restore.
- We could not read tool schemas or annotations. The endpoint is OAuth-gated, so parameter detail and safety hints are unavailable to us. The read/write split on this page is inferred from names and documentation, not read from the protocol.
- SOC 2 is in progress, not complete. CodeWords' security page states it is "currently in the process of getting our SOC 2 Type II compliance". Treat it as underway rather than held.
- CodeWords may use some processed data to improve its systems. Its help centre says data processed through hosted or analytics services may be used to improve CodeWords systems and algorithms, while data from third-party integrations such as Google Workspace APIs is not used to train generalized models.
Frequently asked questions
Yes. CodeWords states the connector is a paid feature requiring an active Pro, Business or custom plan, and directs Free users to subscribe first. Pro is 39 dollars a month and Business is 100 dollars a month as documented in September 2026. Building in the Claude chat is free of CodeWords credits; credits are consumed when a workflow actually runs.
CodeWords does not document this, and we did not call the tool. The only related statement we found concerns Cody's memory, where CodeWords says only the names of secrets are visible and never the values. That sentence describes the memory profile, not this tool. Treat the return value as unknown and assume the agent can read what it fetches.
CodeWords does not publish a boundary. Its documentation describes a secure sandbox with internet access and automatic software installation, and states each run gets a fresh sandbox destroyed afterwards. Across the security page, the pricing page and the connector page there is no command allowlist, no network egress policy and no filesystem scope. Only time limits are published.
Thirty minutes at most. CodeWords documents a maximum sandbox lifetime of 30 minutes for complex workflows, with most runs finishing in seconds. Its API guide splits this by call type: synchronous runs must complete within 120 seconds, and asynchronous runs are designed for up to 30 minutes. The separate Web Agent browser tool carries its own 10-minute limit.
Through the CodeWords web app, not through the connector. CodeWords keeps a version history of automations built in chat, and documents Preview and Restore actions that make an older snapshot current again without deleting newer ones. No tool in this connector's 20 names performs a restore, so an agent cannot roll back its own change.
As environment variables under Settings then API Keys in the CodeWords web app. You add a variable name such as ASANA_API_KEY and paste the value, and CodeWords says keys are encrypted, stored in your environment, and not shared or exposed outside your workspace. Workflows then reference the variable by name rather than carrying the key itself.
No. The connector reaches your CodeWords account over an HTTPS endpoint, so it touches workflows, services, logs and secrets held in that account. CodeWords documents building, deploying and running as happening on its own cloud. Nothing in the tool set names a local path, and the transport gives the server no route to your filesystem.
OAuth for the connector. Our anonymous request returned HTTP 401 with an OAuth challenge pointing at codewords.agemo.ai, which advertises authorization code flow with PKCE and two scopes, api:read and api:write. CodeWords documents an Allow access screen during install. Its separate REST API uses bearer keys prefixed cwk- or cwotk-, which is a different surface.
Sources
- CodeWords Claude connector documentation (retrieved 2026-09-08, via the Markdown variant CodeWords publishes at the
.mdsuffix) · retrieved 2026-09-08 - CodeWords security page (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords plans and pricing (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords external API integration, the credential store (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords memory documentation, the secret-names statement (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords version history and restore (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords calling workflows via API, the run-duration figures (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords sharing workflows, the integrations-and-secrets switch (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords privacy and policies (retrieved 2026-09-08) · retrieved 2026-09-08
- CodeWords full documentation bundle, 268 KB covering every page (retrieved 2026-09-08) · retrieved 2026-09-08
docs.codewords.ai/robots.txtcarriesContent-Signal: ai-train=yes, search=yes, ai-input=yes— synthesis into AI-generated output is expressly permitted by the publisher (retrieved 2026-09-08).www.codewords.ai/robots.txtseparately allows ClaudeBot, GPTBot, PerplexityBot and others by name. · retrieved 2026-09-08- Anonymous
initializeagainsthttps://runtime.codewords.ai/run/devx_mcp/mcp— HTTP 401 with an RFC 9728WWW-Authenticatechallenge (2026-09-08). No tool was called and no credential was supplied. · retrieved 2026-09-08 - OAuth protected-resource descriptor — and authorization server metadata at (retrieved 2026-09-08) · retrieved 2026-09-08
- Anthropic Connectors Directory entry (retrieved 2026-09-08). Source of all 20 tool names, the endpoint, the transport and the partner tier. · retrieved 2026-09-08
- CodeWords support — <support@codewords.ai> · Privacy (retrieved 2026-09-08; the directory's
https://codewords.ai/privacy-policyredirects to thewwwhost, cited here as resolved) · retrieved 2026-09-08
Server Info
- Category
- Productivity
- Developer
- CodeWords
- Tools
- 20
- Domain
- runtime.codewords.ai
Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.
Similar MCP Servers for Productivity
Related Resources
Ready to connect CodeWords?
Connect CodeWords once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.