Spala Public MCP

by Unknown

Not rated yet

About

Discovery, OAuth handoff, and project MCP routing for Spala backend projects.

Explore

1. Read the MCP OAuth metadata again. 2. Start the client OAuth/browser approval flow if no token is available. 3. Retry the same tool after the MCP client reports authentication complete. 4. If the token is expired, refresh or repeat OAuth according to the authorization server metadata. 5. If the user lacks project access, ask the user to grant access in the Spala dashboard instead of guessing another project URL.

Auth errors are not a reason to call](https://api.spala.ai/%7Bproject%7D/mcp)[https://api.spala.ai/{{project}}/mcpor any guessed project MCP URL.

Missing, invalid, or expired bearer tokens should return 401 with a WWW-Authenticate header pointing to the MCP OAuth protected-resource metadata. Clients should use that challenge to restart or refresh the Spala platform OAuth flow.

This transcript is for MCP client implementers. Most users should let Codex, Claude Code, Cursor, VS Code, or another MCP client handle these protocol calls.

GET https://mcp.spala.ai/.well-known/oauth-protected-resource GET https://mcp.spala.ai/.well-known/oauth-authorization-server
{ "jsonrpc": "2.0", "id": 1, "method": "initialize", "params": { "protocolVersion": "2025-06-18", "capabilities": {}, "clientInfo": { "name": "example-client", "version": "1.0.0" } } }
{ "jsonrpc": "2.0", "id": 2, "method": "tools/list", "params": {} }
{ "jsonrpc": "2.0", "id": 3, "method": "tools/call", "params": { "name": "spala_get_onboarding", "arguments": {} } }
{ "jsonrpc": "2.0", "id": 4, "method": "tools/call", "params": { "name": "spala_get_tool_map", "arguments": {} } }
{ "jsonrpc": "2.0", "id": 5, "method": "tools/call", "params": { "name": "project_list", "arguments": {} } }
{ "jsonrpc": "2.0", "id": 6, "method": "tools/call", "params": { "name": "project_connect", "arguments": { "projectId": "PROJECT_ID_FROM_PROJECT_LIST" } } }
1. Read the MCP OAuth metadata again. 2. Start the client OAuth/browser approval flow if no token is available. 3. Retry the same tool after the MCP client reports authentication complete. 4. If the token is expired, refresh or repeat OAuth according to the authorization server metadata. 5. If the user lacks project access, ask the user to grant access in the Spala dashboard instead of guessing another project URL.

Auth errors are not a reason to call](https://api.spala.ai/%7Bproject%7D/mcp)https://api.spala.ai/{{project}}/mcpor any guessed project MCP URL.

Missing, invalid, or expired bearer tokens should return 401 with a WWW-Authenticate header pointing to the MCP OAuth protected-resource metadata. Clients should use that challenge to restart or refresh the Spala platform OAuth flow.

This transcript is for MCP client implementers. Most users should let Codex, Claude Code, Cursor, VS Code, or another MCP client handle these protocol calls.

GET https://mcp.spala.ai/.well-known/oauth-protected-resource GET https://mcp.spala.ai/.well-known/oauth-authorization-server
{ "jsonrpc": "2.0", "id": 1, "method": "initialize", "params": { "protocolVersion": "2025-06-18", "capabilities": {}, "clientInfo": { "name": "example-client", "version": "1.0.0" } } }
{ "jsonrpc": "2.0", "id": 2, "method": "tools/list", "params": {} }
{ "jsonrpc": "2.0", "id": 3, "method": "tools/call", "params": { "name": "spala_get_onboarding", "arguments": {} } }
{ "jsonrpc": "2.0", "id": 4, "method": "tools/call", "params": { "name": "spala_get_tool_map", "arguments": {} } }
{ "jsonrpc": "2.0", "id": 5, "method": "tools/call", "params": { "name": "project_list", "arguments": {} } }
{ "jsonrpc": "2.0", "id": 6, "method": "tools/call", "params": { "name": "project_connect", "arguments": { "projectId": "PROJECT_ID_FROM_PROJECT_LIST" } } }
| Category | Purpose | | --- | --- | | Context | Read builder contract, auth rules, project state, graph, resources, and environment requirements | | Preview | Preview generated or edited models, endpoints, functions, tasks, triggers, agents, and channels | | Apply | Save scoped backend resource changes after preview and validation | | Validate | Check project consistency, auth safety, references, missing configuration, and publish readiness | | Publish | Promote the project draft to the live API when appropriate | | Review | Inspect publish/test results, warnings, repair feedback, logs, and generated docs | | Recovery | Use snapshots, pull requests, version history, rollback, or revert-to-published when a change needs to be undone |

The public docs describe the contract and workflow, not private project data. The exact project tool names and schemas are discovered from the selected project MCP at runtime.

https://mcp.spala.ai/mcp/install-manifest

Use it for current commands, transport, OAuth notes, and the project MCP resolution rule. The rule is always to use the explicit mcpUrl returned by Spala.

Codex Setup /agents/codex Add Spala MCP to Codex Claude Setup /agents/claude Add Spala MCP to Claude Code Cursor Setup /agents/cursor Configure Cursor with Spala MCP Public Agent Skills /agents/skills Public skill files for evaluation and safe workflow Quick Start /getting-started/quickstart Build a backend from the dashboard

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Personal wealth & portfolio tracker — 23 OAuth-scoped tools for holdings, performance, FIRE status, crypto P&L, and confirm-gated transaction writes across 20+ markets.

Deploy and manage apps on your cloud from coding agents. Create environments, choose regions, configure infrastructure, and monitor jobs. Supports OAuth 2.0 with Dynamic Client Registration, RBAC permissions, and approval workflows for production environments.

Privacy-first analytics MCP server for ezStats with site discovery, SEO, goals, billing, and OAuth connectors.

Extentos is a multi-vendor development platform for adding smart-glasses capabilities to existing iOS and Android apps. The simplest analogy is Stripe for smart glasses

An MCP server tailored for React Native–first development using Gluestack UI

Create and read feature flags, review experiments, generate flag types, search docs, and interact with GrowthBook's feature flagging and experimentation platform.

Gives AI agents public URLs (tunnels) for localhost, live HTTP traffic inspection, snapshot publishing, and access control.

Understand, develop, and debug authorization policies in Oso Cloud.

Up-to-date documentation for your coding agent. Covers 1000s of public repos and sites. Built by ref.tools

Model Context Protocol server for Skycloak managed Keycloak. Manage clusters, realms, applications, SSO and users from any MCP client.

Use this endpoint first when an AI coding agent needs to understand or work with Spala, including from a completely empty app folder. Do not wait for frontend files or ask the user to create a dashboard project. It is not the project backend itself. It helps the agent discover Spala, authenticate, complete missing account setup, choose or create a project, and connect the correct project MCP.

Run this from the user's app workspace, replacing <client> with codex, claude-code, gemini, or another supported client:

pnpm dlx @spala-ai/mcp-install init --client <client> --yes --json

The agent must execute the setup commands returned by the installer, then verify the installation:

pnpm dlx @spala-ai/mcp-install status --json

If the active client cannot hot-load the newly installed Public MCP, ask the user to restart or resume the same agent session once. Do not ask the user to create or select a project in the dashboard. After restart, continue with account_status and the project handoff below.

Browser sign-in or signup is the only expected browser action. After authentication, the agent calls account_status. For a new account, it asks one concise terminal question for exactly the reported missing profile/company fields and calls account_setup; that call creates the missing account workspace. Project name is a separate next step: the agent asks for or confidently derives it, reuses or creates the project, calls project_connect exactly once, and executes the workspace-only bind plan. Do not send the user to dashboard onboarding, use placeholder names, wait for application files, or build a separate local-only backend.

Do not guess project MCP URLs. Do not use[https://api.spala.ai/{{project}}/mcp. Do not configure the OAuth authorization server as the MCP server URL. Do not make backend mutations on public MCP. Public MCP discovers and hands off; project MCP builds.

| Surface | URL | Purpose | Can mutate backend? | | --- | --- | --- | --- | | Public MCP | https://mcp.spala.ai/mcp | Discover Spala, read onboarding, search docs, expose OAuth metadata, list/select projects after auth | No | | Project MCP | Connected by project_connect after auth and project choice | Inspect one project, preview changes, validate, apply, publish when requested, review behavior | Yes, after project auth and validation |

The project MCP URL is resolved at runtime from authenticated Spala project data. It is not derived from a fixed path pattern.

1. Run the installer init command and execute its returned setup steps. 2. Run installer status. 3. Complete browser sign-in or signup when requested. 4. Call spala_get_onboarding, spala_get_tool_map, then account_status. 5. If setup is required, ask once for exactly missingFields and call account_setup with real values. 6. Ask for or derive the real project name; reuse .spala/project.json, list projects, or call project_create only when needed. 7. Call project_connect exactly once and execute its returned workspace-only bind plan. 8. Continue on the connected project MCP.
| Tool | Purpose | | --- | --- | | spala_help | Explain what Spala is and how agents should start | | spala_get_onboarding | First call for agents connected to the public MCP | | spala_get_tool_map | Machine-readable routing between public MCP and project MCP | | docs_search | Search agent-facing Spala docs when the agent needs more context | | template_list | Optional starter-pattern lookup for agents | | addon_list | Optional integration lookup for agents |

Good docs_search queries are short and focused:

oauth project handoff create project and connect workspace MCP codex setup cursor project mcp
| Tool | Purpose | | --- | --- | | account_status | Verify the authenticated Spala account before project work | | account_setup | Fill missing profile data and create the first company/workspace after one concise user question | | project_list | List projects available to the authenticated Spala user | | project_connect | Prepare the chosen project's MCP and return a one-time workspace bind plan | | project_get_mcp_manifest | Return the selected project's MCP install manifest shape | | project_get_public_context | Return safe project context for the selected project | | project_create | Create a project when no suitable existing project or local binding should be reused |

Public discovery tools can be called before account authentication. Project tools require the MCP client's Spala OAuth session. The installer and MCP client manage these credentials; users and agents should not copy tokens into project files.

https://mcp.spala.ai/.well-known/oauth-protected-resource https://mcp.spala.ai/.well-known/oauth-authorization-server

The authorization server is discovered from the OAuth metadata. Do not manually configure the authorization server as the MCP server URL.

| Endpoint | URL | | --- | --- | | Authorization | Discovered from /.well-known/oauth-authorization-server | | Token | Discovered from /.well-known/oauth-authorization-server | | Dynamic registration | Discovered from /.well-known/oauth-authorization-server | | Device authorization | Discovered from /.well-known/oauth-authorization-server |

Supported grants include authorization code and device code. PKCE uses S256. Public MCP scopes include api, builder, ai, project, and data. The token endpoint uses public-client auth (none) for the MCP OAuth flow.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.