Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Create projects, trigger deploys and manage env vars on Netlify.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Netlify MCP server connects Netlify hosting to Claude, ChatGPT and any MCP-compatible agent. It exposes eight grouped dispatcher tools carrying 19 operations that create projects, trigger deploys, set environment variables and change who can view a site. Sign-in is OAuth against Netlify's own authorization server, verified live by an authentication challenge.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
netlify-coding-rules, netlify-user-services, netlify-deploy-services, netlify-team-services, netlify-project-services and netlify-extension-services. The server registers none of those strings. Five are the dispatcher names without the -reader or -updater suffix the source appends, so the directory collapses every domain's read and write tools into one name and hides that a write tool exists at all. netlify-coding-rules is thereadOnlyHint is the only annotation this server sets. A client cannot distinguish renaming a project from deleting a secret.read and write are advertised by the authorization server and sanitised at client registration, but we found no scope check in the tool-dispatch path at the commit we read. Granting read does not appear to prevent a write.claudeai scope is a workaround, not a permission. Netlify's source annotates it as temporary, pending a fix to an upstream Model Context Protocol issue it links by number.initialize-database does not initialise a database. It returns instructions telling the agent to install an npm package and restart the dev server. It takes no parameters and calls no API, yet is registered as a write tool.docs.netlify.com/build/build-with-ai/netlify-mcp-server/ returned 301 on 2026-08-22 to the agent setup overview. The MCP content is a section of that larger page, not a dedicated one.Yes, but not directly from the remote server. The remote deploy operation returns a shell command rather than deploying, because the upload has to happen where your files are. It mints a proxy token valid for thirty minutes, scoped in the source to one builds endpoint plus deploy reads. Running that command uploads your repo and starts a real Netlify build.
Its authorization server advertises read and write scopes, but no code path checks them. Netlify's repository contains no scope enforcement in the tool-dispatch path at the commit we read, and tools call the Netlify API with your full access token. The real read-write split is the tool names: reader tools carry readOnlyHint true, updater tools carry false.
Between nine and twenty, depending on your client and your URL. A non-Claude client sees nine tools, Claude.ai sees eleven because two design-import tools are gated on the user agent, and adding a verbose query parameter registers every operation separately for about twenty. Anthropic's directory lists six names, none of which the current server registers.
Yes, and nothing on the tool list says so. Deletion lives inside the environment-variable operation as a boolean flag, which issues a DELETE against Netlify's account environment endpoint. That operation is reached through the project updater dispatcher, whose only annotation is that it is not read-only. No tool carries a destructive hint anywhere on this server.
Yes, and it can happen without anyone asking for it. The visitor access-control operation builds a payload that resets the password to an empty string and disables SSO login by default, then applies whatever you enabled. Calling it to change one setting therefore clears the other. Netlify documents the operation as protection rather than as removal.
It can read environment variables, and secret values are the open question. The environment-variable operation fetches every variable for a site and returns them to the agent, and the same operation writes variables with a secret flag. Netlify's API treats secret values as write-only in some responses, but the connector code does not filter anything itself.
Netlify recommends splitting them by tool type. Its documentation for Claude Web suggests always allowing read-only tools, requiring approval for write and delete tools, and always allowing other tools. That maps cleanly onto the reader and updater tool names, which is the practical reason the server groups operations that way rather than exposing them individually.
Because two tools are gated on the client. Netlify's server inspects the user agent and client name, and registers a Claude Design import pair only when either matches Claude or Anthropic. Claude Code is deliberately excluded as a coding CLI. So claude.ai and Claude Desktop see eleven tools while Cursor, Windsurf and Claude Code see nine.
It can, through an action value rather than its own tool. The form-submission operation takes an action enum whose second value deletes a submission by id, issuing a DELETE against Netlify's submissions endpoint. The same operation otherwise reads submissions in pages. Form submissions are data your site visitors wrote, so deletion here removes visitor-supplied records permanently.
main. · retrieved 2026-08-22src/tools/project-tools/, src/tools/deploy-tools/, src/tools/extension-tools/, src/tools/team-tools/, src/tools/user-tools/ at the same commit (retrieved 2026-08-22) · retrieved 2026-08-22src/utils/client-detection.ts · src/tools/design-import/url-guard.ts (retrieved 2026-08-22) · retrieved 2026-08-22llms.txt (retrieved 2026-08-22). Markdown for any docs page is served by appending .md, which is how the pages above were read. · retrieved 2026-08-22robots.txt, carrying Content-Signal: search=yes, ai-input=yes, ai-train=yes (retrieved 2026-08-22). Netlify expressly permits AI synthesis of its content. · retrieved 2026-08-22WWW-Authenticate: Bearer realm="MCP Server" naming the RFC 9728 descriptor at https://netlify-mcp.netlify.app/.well-known/oauth-protected-resource/mcp, which advertises scopes_supported of offline_access, read, write and claudeai (2026-08-22) · retrieved 2026-08-22Connect Netlify once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.