Use MaShop from another AI assistant
Authorize a compatible MCP client to work with your MaShop projects.
Understand the direction of access
The MaShop MCP server exposes MaShop tools to a compatible external assistant. This is different from connecting another service’s MCP server inside MaShop. The external client acts on the MaShop account you authorize and the permissions granted to it.
The server endpoint is https://mcp.mashop.app/mcp. Use a client that supports remote HTTP MCP connections and the offered OAuth authorization flow. Client setup and feature availability depend on the application you use.
Connect and verify
- Add the MaShop endpoint in your assistant’s MCP connection settings.
- Complete sign-in and inspect the application name and requested access on the consent screen.
- Ask the assistant to read your identity or list your projects before making changes.
- For a coding request, specify the project and inspect the returned task status and result.
- Review authorized applications in MaShop settings and revoke access when it is no longer needed.
Inspect the project first
Ask the external assistant to use get_me to confirm the authorized MaShop account, then list_projects to identify the intended project. Use its project_id in subsequent calls; the project name alone is not the identifier.
list_files reads the repository file list. read_file takes project_id and a repository-relative path. Both accept an optional git_ref, so the assistant can inspect a specific recorded revision before discussing a change.
Follow a longer coding request
send_message takes project_id and message. For a longer task, the external client can set wait to false, retain the returned message_id and call get_message with that same project_id and message_id. This retrieves the existing task instead of creating a duplicate request.
Read the returned status: in_progress means keep following the task; complete includes the recorded assistant response; error needs inspection before retrying. A finished response still needs the relevant files and preview checked before you rely on the application.
The current coding-message action requires a project owned by the authorized MaShop account. A collaborator invitation in the browser does not replace this ownership requirement. If access is refused, verify the account and project before sending another request.
Create from your own brief
create_project accepts a prompt describing the website or application, its users, features and design. The current route checks connected GitHub and Supabase accounts and the account’s project limit. It returns a project identifier and a workspace URL carrying the brief. Open that URL to continue; creating a record does not mean the application is ready.
Describe the pages, features, language, colors and typography your project needs. The optional include_backoffice choice is inferred from the brief when omitted. No selectable template identifier is accepted. remix_project copies a brief and saved project settings into a new project; it does not copy the source repository or assets.
Check publication separately
deploy_project uses the native Netlify connection and the project’s linked GitHub repository. Use it only for the intended project and connected hosting account. It does not select a different hosting provider. Other hosting workflows require the appropriate connection and tools.
A building response confirms that deployment has started, not that the new application is live. Read the build result in the workspace. get_project_status reports the last successful deployment URL when available; that URL may still belong to an older build.
Use the current catalog and saved context
Let the client discover the server’s tools rather than infer capabilities from another assistant. list_template_projects and list_library_projects currently return empty lists with feature_status set to not_available. They do not provide prefabricated applications or reusable project libraries. Start from a brief with create_project.
The workspace and project knowledge tools read or replace text saved through MCP. Read the existing text before replacing it; an empty string clears it. This storage is separate from an agent’s instructions, skills and memory. A successful save does not prove that a later execution applies the text automatically. Include the relevant instructions in the task and verify the result.
get_credits reads recorded balances. top_up_credits creates a checkout link for an amount you request; it does not charge your account or add credits by itself. Review the amount, complete payment in the browser and check the balance after confirmation.
Share only appropriate assets
get_file_upload_url prepares an upload for an allowed asset in an owned project. Supply the filename, declared size and an allowed MIME type, such as image/png; the current route rejects unsupported extensions and types. The maximum declared size is 10 MB.
The client completes the upload using the returned upload URL and checks whether it succeeded. The asset bucket is public. Use it for public images, fonts or other supported files, and keep private records and secrets out of it.
