Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Build, run and publish full-stack apps: write code, provision Postgres, run SQL, deploy live.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Floot MCP server lets Claude, ChatGPT or any MCP-compatible agent build and publish full-stack web apps on Floot's infrastructure. Its 46 tools write React and TypeScript code, provision a Postgres database, run SQL, read logs, capture previews and deploy to a live URL. Sign-in is OAuth, and your assistant's own subscription pays for the thinking rather than Floot credits.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
scopes_supported: [] and the protected-resource descriptor omits the key. There is no read-only grant to choose — verified live, 2026-08-20.search and fetch by ChatGPT's own contract. Those two only search and read.ptoken query parameter granting read and interaction rights for seven days with no login, so anyone the link is forwarded to can open it until it expires.readOnlyHint, destructiveHint and idempotentHint are all unavailable. The read/write split above is our classification of published tool names, not the vendor's assertion.has_mcp_app: true, but the 401 blocked prompts/list and resources/list, so we make no claim about either surface.Yes. Floot's troubleshooting page states that adding connectors requires a paid Claude plan and that on Claude Free the option is not there to find. Any paid tier works. On Claude Team or Enterprise there is a second gate: an organization Owner must enable Floot once for the whole organization before individual members can click Connect for themselves.
Because standard ChatGPT mode calls only two tools. Floot documents that standard ChatGPT can use only tools named search and fetch, which is ChatGPT's own contract rather than a Floot restriction — Floot states it registers the same full tool set for every client and holds nothing back. Those two tools only search and read projects. For writes, use a client that calls the full set.
No. Floot documents OAuth as the only accepted method and tells you to leave bearer-token, API-key and custom-header fields empty, adding that a value typed into a token field is not a credential Floot accepts. Sign-in opens a Floot page in your browser. Floot also requires PKCE with S256, so a client offering only plain or no PKCE cannot connect at all.
No. Floot documents that nothing an assistant can call buys anything — there is no checkout tool, no plan-change tool, and no way for an agent to add a payment method. Floot calls this deliberate rather than an oversight. The one exception consumes credits you already hold: generate_image bills the project owner's balance, not the account driving the chat.
Three things, per Floot's capability matrix. Turning on native mobile app builds has no tool and no publish parameter at all. Finishing a custom domain needs you to complete a DNS wizard, and the link Floot hands you stays open for one hour. Downloading the code export zip is assembled in your browser rather than on Floot's servers.
In build actions — one per tool call your assistant makes, reads counted the same as writes. Floot's free plan allows 100 per UTC day plus 400 across a rolling seven-day window; Pro allows 1,000 a day and Power 5,000, neither with a weekly cap. Failed and cancelled calls never count, and six housekeeping tools are permanently exempt.
Yes, and Floot says so plainly. Its security page states that query_database, execute_sql and pull_database_schema read rows from your app's database, and that if the database holds real user data, that data reaches your assistant's context whenever a question requires it. Resource secrets are the documented exception — those are never part of the payload an assistant sees.
No. The 2026-08-16 snapshot record carries no permissions field at all, on a connector whose 46 tool names include delete_file, execute_sql, publish_app and unpublish_app. Absence is not a read-only claim and it is not a write claim either — it means the reach of these tools was never summarised for the reader. Floot's own capability matrix fills that gap instead.
.md suffix form of this URL returns 404 · retrieved 2026-08-20com.floot/floot, and the stack description). No licence or citation grant appears in the file · retrieved 2026-08-20streamable-http transport and oauth2 auth type, and names both one-click install routes) · retrieved 2026-08-20application/json; resource is the real endpoint string, one authorization server, bearer_methods_supported: ["header"], and no scopes_supported key). This is the form the www-authenticate header names · retrieved 2026-08-204ee3fbac8aae084042dce7606098a425d0a37d4a on both) · retrieved 2026-08-20text/plain) · retrieved 2026-08-20https://floot.com/mcp-authorize consent screen, code_challenge_methods_supported: ["S256"], a registration endpoint, token_endpoint_auth_methods_supported: ["none"], and scopes_supported: [], present but empty). The openid-configuration form returns 404 · retrieved 2026-08-20initialize POST to https://mcp.floot.com/mcp returns HTTP 401 with {"error":{"code":-32001,"message":"Unauthorized"}} and www-authenticate: Bearer resource_metadata="https://mcp.floot.com/.well-known/oauth-protected-resource", naming no scope. No tool was called · retrieved 2026-08-20Allow: / for the wildcard agent and for fourteen individually named AI crawlers including ClaudeBot, GPTBot and PerplexityBot; no Content-Signal line on any axis; the preamble itself advertises llms.txt, llms-full.txt and the .well-known/mcp.json manifest). Nothing on any axis restricts the use made of this page · retrieved 2026-08-20has_mcp_app: true, streamable HTTP, the mcp.floot.com/mcp endpoint, the developer-tools category, partner tier, and auth_posture: auth_required). The live directory page returns HTTP 403 Cloudflare interstitials to both curl and WebFetch, so the permissions-label check was made against the committed snapshot rather than the rendered page · retrieved 2026-08-16Connect Floot once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.