Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Build and edit a WeWeb no-code app against your live project.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The WeWeb MCP server lets an external AI agent build inside a WeWeb project — the no-code platform's pages, elements, design system, database tables, auth users and workflows — from Claude, ChatGPT or any MCP client. Anthropic's directory lists 125 tools, the largest surface in this catalogue. Sign-in is OAuth, and it grants one scope.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
https://ai-api.weweb.io/.well-known/oauth-protected-resource and the authorization server metadata at https://api.weweb.io/.well-known/oauth-authorization-server both advertise exactly ["mcp:write"], checked 2026-08-23. The boundary does not fall between the routine write and the irreversible one — the same grant that lets an agent rename a page lets it drop a table. There is no read-only mode to hand a research agent.dropWeWebTable, dropWeWebTableColumn and dropWeWebTableConstraint destroy structure and the data inside it. Editor Backups restore an editor version, which we found no documentation extending to dropped backend tables.readOnlyHint is available to check our classification against.initialize completes, so its declared capabilities were never visible to us. Anthropic's directory lists zero prompt names.No. No tool among the 125 publishes or deploys anything to a live site. WeWeb documents publishing as an editor action: you click Publish in the top right, choose Publish your app, then Publish to production or Publish to staging. The one publish-named tool, publishComponent, publishes a reusable component into your project library, which is an editor asset rather than a live site.
It edits the editor version, not the published one. WeWeb states that publishing takes the latest version of your project and makes it available outside the editor, so tool calls change what your next publish will contain rather than what visitors see now. WeWeb's own beta warning says tool calls run against your real project and can create, edit, or delete resources.
Twenty of the 125, by name. Seventeen carry a delete verb and three carry drop: dropWeWebTable, dropWeWebTableColumn and dropWeWebTableConstraint. Dropping a table is a schema-level destruction of stored rows, and WeWeb documents no undo for it. Editor Backups roll back the editor version of a project, which is a different thing from restoring backend table data.
Yes, all four operations. listAllEnvVariables, createEnvVariable, editEnvVariable and deleteEnvVariable are in Anthropic's listing and in WeWeb's own documented tool table. WeWeb does not publish whether the list tool returns variable values or only their names, so assume any secret stored as a WeWeb environment variable is reachable by a connected agent.
Exactly one, and it is a wildcard. WeWeb's RFC 9728 resource descriptor and its authorization server both advertise scopes_supported of mcp:write, checked live on 2026-08-23. There is no read-only counterpart, so consent cannot separate listing your projects from dropping a table. Granting the connector grants everything the server implements, now and later.
Pro or Partner for ongoing use. WeWeb's pricing documentation states the MCP server is available on a 14-day trial on the Free and Essential seat plans, and that Pro and Partner seat plans include ongoing access. When the trial ends without an upgrade, WeWeb states your AI client can no longer call WeWeb tools through MCP.
Yes, through table views. WeWeb documents that a view of a table carries permissions set to Public, Authenticated, or specific Roles and Groups. createTableView and updateTableView are among the 125 tools, so an agent editing a view is editing the access boundary. Nothing in the tool names distinguishes a cosmetic view edit from a permission change.
WeWeb states the MCP does not expose ways for AI to build using plugin actions. Its documentation recommends switching Xano and Supabase to the newer Integrations, whose actions the MCP can reach. WeWeb also documents a makeshift workaround where you paste workflow JSON between the editor and your agent, and explicitly labels it not an official MCP feature.
docs.weweb.io/robots.txt is Allow: / with no Content-Signal directive. · retrieved 2026-08-23llms.txt (retrieved 2026-08-23). It indexes 300+ pages but names no MCP page, and llms-full.txt returns 404. · retrieved 2026-08-23initialize to https://ai-api.weweb.io/v1/mcp returned HTTP 401 with WWW-Authenticate: Bearer resource_metadata="https://ai-api.weweb.io/.well-known/oauth-protected-resource"; that descriptor and https://api.weweb.io/.well-known/oauth-authorization-server both returned scopes_supported: ["mcp:write"] · retrieved 2026-08-23Connect WeWeb once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.