MCP Server

reachpad-mcp

io.github.Reachpad/reachpad-mcp
Cloud & Infrastructure Developer Tools Public & reachable MCP 2025-11-25

What this MCP does

Publishes and manages full-stack applications in persistent workspaces, including versions, files, databases, secrets, sharing, access, and logs.

create_app
Publish a new app
Publish new files as an app and get its URL back. Version 1 goes live at once, so show the person the content and the destination before calling this. Access defaults to org_link, which lets anyone signed in to the same organization open the link.
Input schema
{'type': 'object', 'required': ['name', 'files'], 'properties': {'name': {'type': 'string', 'description': 'What the app is called. Shown in listings.'}, 'slug': {'type': 'string', 'description': 'The readable part of the subdomain to publish at, 3 to 34 characters of a-z, 0-9 and single hyphens. Derived from the name when omitted. A random 5-character tag is always appended, so a name is never taken and two apps may share one.'}, 'type': {'enum': ['app', 'page', 'doc', 'file'], 'type': 'string', 'description': 'The badge on the row. Defaults to app.'}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'content'], 'properties': {'path': {'type': 'string', 'description': 'Path inside the app, relative and at most 100 bytes, for example index.html.'}, 'content': {'type': 'string', 'description': "The file's text."}}}, 'description': 'Files to publish as plain text, not base64: HTML, Markdown or JavaScript exporting default { fetch }. A page serves index.html at its URL. Functions declaring db include schema changes as migrations/NNNN_name.sql, run in order when the version goes live.'}, 'access': {'type': 'object', 'required': ['level'], 'properties': {'level': {'enum': ['restricted', 'org_link', 'public_link'], 'type': 'string'}}, 'description': 'Who may open the link. Defaults to org_link.'}, 'message': {'type': 'string', 'description': 'What version 1 contains.'}, 'manifest': {'type': 'object', 'required': [], 'properties': {'env': {'type': 'object', 'description': 'Plain strings bound as env.NAME, visible to anyone who can read the version. Put keys in secrets instead. Names shared with secrets fail publication.'}, 'kind': {'enum': ['page', 'function'], 'type': 'string', 'description': 'page serves files unchanged; function runs a JavaScript module for every request.'}, 'entry': {'type': 'string', 'description': 'Root file for a page, usually index.html; module exporting default { fetch } for a function. Must exist in the resulting files, including files retained by merge.'}, 'secrets': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Organization secret names bound as env.NAME for functions. Set values first at reachpad.dev/apps/settings/secrets or with reachpad secrets set NAME. An unset name fails publication with NAME is not set.'}, 'services': {'type': 'array', 'items': {'enum': ['db', 'files'], 'type': 'string'}, 'description': "Function services: db binds the app's SQLite database at env.reachpad.db.query(sql, params) and env.reachpad.db.batch(statements); files binds its file store at env.reachpad.files.put/get/head/delete. Other names are refused. db permits migrations/NNNN_name.sql, run when the version goes live."}}, 'description': "Omit on create_app for a static page; omit on update_app to keep the previous version's manifest. If supplied, replaces the entire manifest: include every field still needed. services, secrets and env apply only to functions. Runtime details and limits: https://reachpad.dev/SKILL.md"}, 'validate': {'type': 'boolean', 'description': 'Check without writing. Validates and returns the resulting file set, total bytes, entry and kind. create_app also validates the slug and returns it with the URL; <tag> stands for five random characters assigned on publish. Does not check the org app limit; publishing can still fail for that.'}}}
get_app_logs
Read app logs
Read recent log lines from the live version of a function app. An app that serves files has no process and answers that it has no logs. Function logs are not captured yet either, and the answer says so: until they are, have the function catch its own errors and return them in the response.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['app_id'], 'properties': {'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'How many rows to return. Defaults to 50.'}, 'since': {'type': 'string', 'description': 'RFC 3339 timestamp to read from.'}, 'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}}}
list_app_shares
List shares
List the people an app is shared with, their roles, and whether the grant has attached to an account yet. The owner and editors can read this list.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['app_id'], 'properties': {'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}}}
list_app_versions
List versions
List an app's versions, newest first. Versions are immutable and numbered from 1. Earlier versions open for the app's editors; the live link follows the app's access setting. Pass the next_cursor from a previous call to get the next page.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['app_id'], 'properties': {'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'How many rows to return. Defaults to 50.'}, 'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'cursor': {'type': 'string', 'description': 'next_cursor from a previous call.'}}}
list_secrets
List secrets
List the organization's secrets: each name, who set it, when, and the apps whose versions bind it. Names only. No tool anywhere returns a secret value.
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {}}
ls
List a folder
List what is directly inside one folder: its subfolders and the apps filed in it. Omit folder_id for the top level. Each folder carries the updated_at that mv needs.
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'How many rows to return. Defaults to 50.'}, 'folder_id': {'type': 'string', 'description': 'The folder to look inside. Omit for the top level.'}}}
mkdir
Create a folder
Create a folder, at the top level or inside another one.
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'The folder name.'}, 'parent_id': {'type': 'string', 'description': 'The folder to create it inside. Omit for the top level.'}}}
mv
Move an app or folder
Move an app into a folder, or move a folder under another folder. Name exactly one of app_id or folder_id as the thing being moved, and to_folder_id as the destination, or null for the top level. Moving a folder also needs base_updated_at, the value read from ls or tree, so a move made against a stale reading is refused instead of undoing someone else's.
Idempotent
Input schema
{'type': 'object', 'required': ['to_folder_id'], 'properties': {'app_id': {'type': 'string', 'description': 'The app to move. Name this or folder_id, not both.'}, 'folder_id': {'type': 'string', 'description': 'The folder to move. Name this or app_id, not both.'}, 'to_folder_id': {'type': ['string', 'null'], 'description': 'The destination folder id, or null to move to the top level.'}, 'base_updated_at': {'type': 'string', 'description': "The moved folder's updated_at, from ls or tree. Required when folder_id is given."}}, 'dependentRequired': {'folder_id': ['base_updated_at']}}
publish_app_version
Make a version live
Make one version of an app live by its number. This is how a version staged with publish false goes on the link, and how an app is rolled back: name an older number and that version is what the link serves again. Nothing is rebuilt, the pointer moves.
Idempotent
Input schema
{'type': 'object', 'required': ['app_id', 'number'], 'properties': {'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'number': {'type': 'integer', 'minimum': 1, 'description': 'The version number to make live.'}}}
query_app_db
Run one SQL statement
Run one SQL statement against a function app's own database, to read rows and to fix data. Not for schema: a table or a column belongs in the version's migrations/NNNN_name.sql, and a statement that changes the schema is refused. Owners and editors only. Answers rows and rowCount for a select, and changes with lastInsertRowid for a write.
Input schema
{'type': 'object', 'required': ['app_id', 'sql'], 'properties': {'sql': {'type': 'string', 'description': 'One statement, with ? placeholders for every value that comes from somewhere else. A second statement in the same string is refused.'}, 'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'params': {'type': 'array', 'items': {'type': ['string', 'number', 'boolean', 'null']}, 'description': 'The values for the ? placeholders, in order. Strings, numbers, booleans and null.'}}}
read_app
Read an app
Read one app before update_app: its name, type, access level and publishing mode, plus base_version_id and its files, which both describe the version the next edit builds on. Each text file carries its content, so this is how you see what an app already contains before changing it. A file marked content_omitted answer budget did not fit in this answer and read_app_file fetches it; one marked too large is past what any tool answer carries. Pass that base_version_id to update_app. version is what the link serves now, and head_version is the version base_version_id names on the apps where that is not the live one, which is every app with a version staged by publish false. pending_version is the number of that staged version, and publish_app_version is what makes it live.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['app_id'], 'properties': {'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}}}
read_app_file
Read one file
Read one file out of an app as text, at most 256 KB. Use it for a file that read_app left out with content_omitted: "answer budget", or to fetch a single file without the rest of the app. A file that is not text, and a text file over that size, are refused rather than truncated. Reads the newest version unless you name one, which is the same version read_app lists.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['app_id', 'path'], 'properties': {'path': {'type': 'string', 'description': "The path inside the app, as it appears in read_app's files, for example index.html."}, 'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'number': {'type': 'integer', 'minimum': 1, 'description': 'The version number to read from. Defaults to the newest version.'}}}
read_app_preview
See an app
Look at the picture of what an app's link serves right now, as an image. Use it for an app whose files you cannot read: a function app's module stays with the people who develop it, so this is how you see what the app actually shows. It is the live version only, and an app published before its picture was taken, or one whose capture has not run yet, answers that there is no picture rather than an error.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['app_id'], 'properties': {'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}}}
read_app_version
Read a version
Read one version by its number, with its files and each text file's content. Use it to see what an earlier publish contained, and to copy a file back out of a version you want to return to. Earlier versions open for the app's editors; the live link follows the app's access setting.
Read only Idempotent
Input schema
{'type': 'object', 'required': ['app_id', 'number'], 'properties': {'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'number': {'type': 'integer', 'minimum': 1, 'description': 'The version number.'}}}
remove_secret
Remove a secret
Remove one organization secret and delete it from every published version that binds it. A version the deletion did not reach keeps the name in the list with that version in failed, and running this again retries exactly those.
Destructive Idempotent
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'The secret name, from list_secrets.'}}}
revoke_app_share
Remove a share
Remove one share by its id, from list_app_shares. The app itself is untouched. The owner or an editor may use this when editor-managed sharing is enabled.
Destructive Idempotent
Input schema
{'type': 'object', 'required': ['app_id', 'share_id'], 'properties': {'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'share_id': {'type': 'string', 'description': 'The share id. Starts with shr_.'}}}
rmdir
Delete an empty folder
Delete an empty folder. This refuses while the folder still holds apps or subfolders, and it never deletes an app. Move the contents out first.
Destructive Idempotent
Input schema
{'type': 'object', 'required': ['folder_id'], 'properties': {'folder_id': {'type': 'string', 'description': 'The folder to delete.'}}}
search_apps
Search apps
Find apps in the caller's organization by text. This matches substrings of the name and the slug, and whole words on the live version's page, not meaning: search for a word that appears in the title or on the page rather than describing the app. Returns ids and live URLs.
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {'q': {'type': 'string', 'description': 'Text to match against the name, the slug and the words on the live page.'}, 'type': {'enum': ['app', 'page', 'doc', 'file'], 'type': 'string', 'description': 'Keep only apps carrying this badge.'}, 'limit': {'type': 'integer', 'maximum': 200, 'minimum': 1, 'description': 'How many rows to return. Defaults to 50.'}, 'created_by': {'type': 'string', 'description': 'Keep only apps owned by this user id or email address.'}, 'updated_by': {'type': 'string', 'description': 'Keep only apps owned by this user id or email address. Version authors are not indexed in v1, so this filters on the owner.'}}}
set_app_access
Set who can open an app
Change who can open an app: restricted (only the owner and named people), org_link (anyone signed in to the organization), or public_link (anyone with the URL). A password and an expiry apply to a public link only. Owner only.
Idempotent
Input schema
{'type': 'object', 'required': ['app_id', 'level'], 'properties': {'level': {'enum': ['restricted', 'org_link', 'public_link'], 'type': 'string'}, 'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'password': {'type': 'string', 'description': 'Set a password on a public link.'}, 'expires_at': {'type': 'string', 'description': 'RFC 3339 timestamp after which a public link stops working.'}, 'clear_expiry': {'type': 'boolean', 'description': 'Remove the expiry.'}, 'clear_password': {'type': 'boolean', 'description': 'Remove the password.'}}}
set_secret
Set a secret
Set one organization secret, so a function can bind it by name in its manifest secrets list. Any member of the organization. Setting a name that already exists replaces the value and rotates it onto every published version that binds it. Answers the name, how many versions took the new value, and the ids of any that did not.
Destructive Idempotent
Input schema
{'type': 'object', 'required': ['name', 'value'], 'properties': {'name': {'type': 'string', 'description': 'The environment variable name the function reads, for example STRIPE_SECRET_KEY. Letters, digits and underscores.'}, 'value': {'type': 'string', 'description': "The value. It is sealed on write: no tool returns it, this one included, and it is never written to a log or to this app's database. Ask the person to paste it themselves rather than repeating a key from earlier in the conversation."}}}
share_app
Share an app
Give one email address access to an app as a viewer or an editor. An address without an account gets a grant that starts working the first time they sign in. The owner or an editor may use this when the owner has enabled editor-managed sharing.
Idempotent
Input schema
{'type': 'object', 'required': ['app_id', 'email', 'role'], 'properties': {'role': {'enum': ['viewer', 'editor'], 'type': 'string', 'description': 'viewer can open it, editor can also publish versions.'}, 'email': {'type': 'string', 'description': 'The address to share with.'}, 'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}}}
trash_app
Move an app to the trash
Move an app to the trash. Its link stops opening at once. Owner only. The app and its versions are kept and can be restored from Trash at reachpad.dev/apps/trash, which is also the only place an app is deleted for good.
Destructive Idempotent
Input schema
{'type': 'object', 'required': ['app_id'], 'properties': {'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}}}
tree
Read the folder tree
The whole folder tree for the organization, nested, with the number of apps filed in each folder and the count sitting at the top level. Each node carries the updated_at that mv needs.
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {}}
update_app
Publish a new version
Publish a new version of an existing app. Read the app first and pass the base_version_id read_app returns: it names the version this edit builds on, and a base that has moved is refused rather than overwritten. By default the new version replaces the whole file set and goes live immediately unless the app is set to review before publishing. Send mode merge to publish only the files that changed and keep the rest of that version's files, with remove for paths to drop. Two merges in a row build on each other, staged versions included. Send validate true to check the call without publishing, or publish false to stage the version and make it live later with publish_app_version.
Input schema
{'type': 'object', 'required': ['app_id', 'files', 'base_version_id'], 'properties': {'mode': {'enum': ['replace', 'merge'], 'type': 'string', 'description': 'replace, the default, publishes files as the whole file set: anything left out is gone. merge sends only the files that changed and carries every other file of the base version into the new version.'}, 'files': {'type': 'array', 'items': {'type': 'object', 'required': ['path', 'content'], 'properties': {'path': {'type': 'string', 'description': 'Path inside the app, relative and at most 100 bytes, for example index.html.'}, 'content': {'type': 'string', 'description': "The file's text."}}}, 'description': 'Files to publish as plain text, not base64: HTML, Markdown or JavaScript exporting default { fetch }. A page serves index.html at its URL. Functions declaring db include schema changes as migrations/NNNN_name.sql, run in order when the version goes live.'}, 'app_id': {'type': 'string', 'description': 'The app id, as returned by search_apps or create_app. Starts with app_.'}, 'remove': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Paths from the base version to leave out of the new one. Merge only, and a path that is not in the base version is refused rather than ignored. A call that only removes files sends an empty files array.'}, 'message': {'type': 'string', 'description': 'What changed in this version.'}, 'publish': {'type': 'boolean', 'description': 'false stages the version instead of putting it on the link. It is built and readable at its own version URL, and publish_app_version makes it live. Defaults to true.'}, 'manifest': {'type': 'object', 'required': [], 'properties': {'env': {'type': 'object', 'description': 'Plain strings bound as env.NAME, visible to anyone who can read the version. Put keys in secrets instead. Names shared with secrets fail publication.'}, 'kind': {'enum': ['page', 'function'], 'type': 'string', 'description': 'page serves files unchanged; function runs a JavaScript module for every request.'}, 'entry': {'type': 'string', 'description': 'Root file for a page, usually index.html; module exporting default { fetch } for a function. Must exist in the resulting files, including files retained by merge.'}, 'secrets': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Organization secret names bound as env.NAME for functions. Set values first at reachpad.dev/apps/settings/secrets or with reachpad secrets set NAME. An unset name fails publication with NAME is not set.'}, 'services': {'type': 'array', 'items': {'enum': ['db', 'files'], 'type': 'string'}, 'description': "Function services: db binds the app's SQLite database at env.reachpad.db.query(sql, params) and env.reachpad.db.batch(statements); files binds its file store at env.reachpad.files.put/get/head/delete. Other names are refused. db permits migrations/NNNN_name.sql, run when the version goes live."}}, 'description': "Omit on create_app for a static page; omit on update_app to keep the previous version's manifest. If supplied, replaces the entire manifest: include every field still needed. services, secrets and env apply only to functions. Runtime details and limits: https://reachpad.dev/SKILL.md"}, 'validate': {'type': 'boolean', 'description': 'Check without writing. Validates and returns the resulting file set, total bytes, entry and kind. create_app also validates the slug and returns it with the URL; <tag> stands for five random characters assigned on publish. Does not check the org app limit; publishing can still fail for that.'}, 'base_version_id': {'type': 'string', 'description': 'The base_version_id read_app returned, which is the version this edit was made against. Starts with ver_.'}}}
whoami
Who am I
Report the account and the organization this connection is signed in as: user id, email and name, plus org id and name, and `orgs`, every organization the account is in with the current one marked. Takes no arguments. Every app is created in the current organization and nowhere else, so call this before publishing when the person named an organization to publish into, and stop if the org id is not the one they named: switching is done at reachpad.dev/apps, from the organization name at the top of the sidebar, and this connection follows it.
Read only Idempotent
Input schema
{'type': 'object', 'required': [], 'properties': {}}
Added
get_app_logs
Sept. 17, 2026, 12:49 p.m.
Added
rmdir
Sept. 17, 2026, 12:49 p.m.
Added
mv
Sept. 17, 2026, 12:49 p.m.
Added
mkdir
Sept. 17, 2026, 12:49 p.m.
Added
tree
Sept. 17, 2026, 12:49 p.m.
Added
ls
Sept. 17, 2026, 12:49 p.m.
Added
revoke_app_share
Sept. 17, 2026, 12:49 p.m.
Added
list_app_shares
Sept. 17, 2026, 12:49 p.m.
Added
share_app
Sept. 17, 2026, 12:49 p.m.
Added
set_app_access
Sept. 17, 2026, 12:49 p.m.
Added
publish_app_version
Sept. 17, 2026, 12:49 p.m.
Added
update_app
Sept. 17, 2026, 12:49 p.m.
Added
create_app
Sept. 17, 2026, 12:49 p.m.
Added
trash_app
Sept. 17, 2026, 12:49 p.m.
Added
remove_secret
Sept. 17, 2026, 12:49 p.m.
Added
set_secret
Sept. 17, 2026, 12:49 p.m.
Added
list_secrets
Sept. 17, 2026, 12:49 p.m.
Added
query_app_db
Sept. 17, 2026, 12:49 p.m.
Added
read_app_file
Sept. 17, 2026, 12:49 p.m.
Added
read_app_version
Sept. 17, 2026, 12:49 p.m.
Added
list_app_versions
Sept. 17, 2026, 12:49 p.m.
Added
read_app_preview
Sept. 17, 2026, 12:49 p.m.
Added
read_app
Sept. 17, 2026, 12:49 p.m.
Added
search_apps
Sept. 17, 2026, 12:49 p.m.
Added
whoami
Sept. 17, 2026, 12:49 p.m.