Skip to content
shiplet / docs

DEVELOPER TOOLS / MCP

Your agent.
Your Shiplet workspace.

Let an MCP-compatible client inspect a repository and guide it through deployment. You control the credentials and the changes it makes.

1. Create an agent key

Sign in, open Profile → Agents, and create a named key for your client. Copy it immediately; Shiplet only shows a new key once. The key acts as your user and uses workspace permissions.

Manage agent keys →

2. Connect the endpoint

In a client that supports remote HTTP MCP servers with custom headers, use your Shiplet site address followed by /mcp. The profile page shows the endpoint for your current environment.

Transport
HTTP JSON-RPC
Endpoint path
/mcp
Authentication
Authorization: Bearer YOUR_AGENT_KEY
Alternative header
X-API-Key: YOUR_AGENT_KEY

Use HTTPS for a hosted workspace. A localhost URL only works for a client that can reach that computer. Configuration syntax varies between clients; this is a connection reference, not a universal client configuration file.

Keep the key private

Store it in your client’s secret configuration. Don’t commit it to a repository or paste it into a shared conversation. Revoke unused keys from your profile.

3. Start with an inspection

Check my repository with Shiplet. Explain any blockers, required variables, and review findings. Wait for my approval before importing, deploying, or creating a share link.

The usual sequence is check → import → secrets (if needed) → deploy → status → logs (if needed) → share. Pass the inspection receipt from check to import. Show review findings before accepting them, and stop on blocked findings.

Deployment is asynchronous. Poll status until the app is live before requesting a share link. If a deploy fails, call logs for the selected environment’s bounded, redacted output and Shiplet’s diagnosis. Creating a share link grants access according to its policy and duration.

Available tools

check

Inspect a GitHub repository for deploy blockers, secrets, data needs, and unsafe capabilities. Returns an inspectionReceipt for import. Does not deploy.

import

Create or update a Shiplet application from an inspectionReceipt. Requires safetyAccepted=true when the review status is review.

secrets

Store encrypted environment variables for an application. Call after check/import when missingVariables are listed.

deploy

Queue a production deploy. Returns immediately; poll status until live.

status

Latest deploy state, protected gateway URL, missing setup, and any existing share link.

logs

Read the latest deployment logs for one environment. Returns redacted, size-bounded output and Shiplet's diagnosis; defaults to Production.

share

Mint a week-long app-only share URL. Teammates open the app, not GitHub or the Shiplet console. Requires a live protected deploy.

When a connection fails

401: missing or invalid key

Check that the header contains an active key from the same Shiplet environment. Create a replacement only if needed, and revoke keys you no longer use.

Tools list works, but an action fails

Tool discovery is available without authentication. Tool calls need a valid key, workspace access, and any required GitHub installation or app configuration.

The client asks for browser OAuth

This endpoint uses API-key headers. Choose a client configuration that supports them; a connector that only accepts an OAuth flow will need a compatible adapter.

Import or deploy reports a blocker

Read the tool error. Resolve missing values, repository access, or capability review requirements before retrying. Retrying alone does not fix a blocked inspection.

Connect your agent →