Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Open the real production session recording — events, screenshots, DOM, console, network — to find root cause.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Subtext MCP server lets Claude or any MCP-compatible agent open a real production session recording and investigate it — event map, screenshots, DOM tree, console and network traffic — instead of a human scrubbing a replay video. A second tool family lets the agent govern which page elements, URLs and network bodies get captured at all.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
privacy-url-create and privacy-network-create take effect for all sessions immediately, with no preview scope and no MCP delete.privacy-promote is one-way through the agent tools. A promoted rule cannot be demoted or deleted via MCP.permissions label at all, over a tool set with five write-shaped verbs.comment-* tools on the same core server are absent from Anthropic's snapshot.review-list-sessions, review-summary and privacy-propose at 1 credit each.Partly, and the split matters. Element masking rules land in a preview scope and only reach production when a human promotes them, and the agent cannot delete a live rule at all. But URL and network rules created through the connector apply to all sessions immediately, with no preview step and no promotion gate. Those two tools are the ones to watch.
Not for live element rules. Subtext states the agent can only delete preview-scoped rules, and rejects a live rule ID outright, because removing production masking could expose personal data in future recordings. Removing a live rule requires the Fullstory settings interface. Unmask rules cannot be created through the connector either, and baseline form-input masking cannot be switched off by these tools.
Yes, directly and in detail. The review tools open a real production session and return the event map, a prose digest, screenshots of what the user saw, the component tree, and console and network activity down to headers and bodies. Sessions can be looked up by a user's email address, and responses carry the identified user's name, email and custom properties.
Four, and they separate reading from writing. We verified them live on 2026-08-19 in the authentication challenge and the protected-resource descriptor alike: sessions:read, settings.privacy:read, settings.privacy.element_block:write and settings.privacy.url:write. Session data is read-only at the scope layer, and the two write scopes are confined to privacy settings. No scope grants writes to session content.
No. Subtext is a separate, self-serve product built by Fullstory on Fullstory capture infrastructure, with its own signup, billing and free tier. Fullstory states you do not need a Fullstory account, and that existing Fullstory customers get agentic session review through a different offering instead. The shared api.fullstory.com host reflects shared infrastructure, not a shared subscription.
Anthropic's directory snapshot lists 15, and Subtext's documentation describes more than that. Four comment tools are documented as part of the same core server but absent from the snapshot, and a separate closed-beta browser toolset is documented on top. The 15 listed names are all real and all documented; the listing is a subset rather than a full inventory.
No. Subtext publishes a free tier with no credit card, covering 10,000 captured sessions and 100 agent credits a month, and paid plans at 50 and 250 dollars a month. No administrator role is documented as a prerequisite for connecting. Two meters apply: captured sessions and agent credits, where a full session review costs 10 credits.
.md variant; documents every parameter and return for the six review tools) · retrieved 2026-08-19subtext.fullstory.com/robots.txt allows all agents with no disallows and publishes no Content-Signal axes; www.fullstory.com/robots.txt allows all with one unrelated disallow and likewise publishes no Content-Signal axes. A documentation index is also published at https://subtext.fullstory.com/docs/llms.txt · retrieved 2026-08-19initialize POST to https://api.fullstory.com/mcp/subtext returns HTTP 401 with www-authenticate: Bearer realm="Fullstory API", resource_metadata="...", scope="sessions:read settings.privacy:read settings.privacy.element_block:write settings.privacy.url:write", plus an x-fullstory-data-realm response header. No tool was called and no authentication was attempted · retrieved 2026-08-19authorization_servers: ["https://auth.fullstory.com"]; root returns a 301 redirect; path-insert returns a 52-byte typed JSON 404 · retrieved 2026-08-19S256 only, authorization_code and refresh_token grants, no client_credentials, public clients, dynamic registration and revocation endpoints, no scopes_supported). All three well-known forms on api.fullstory.com return 404 · retrieved 2026-08-19permissions field, no prompts listed, author recorded as Fullstory) · retrieved 2026-08-16Connect Subtext once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.