Homespun by homespun.dev

MCP server · Databases & files · indexed, not reviewed

HostedLocalvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Deploy a multi-user web app from your agent: hosting, auth, database, and permissions.

What the official MCP registry says

Facts

MCP registry
dev.homespun/homespun · 1.6.91
Endpoint
https://homespun.dev/mcp
Packages
npm @homespunapps/mcp stdio
npm / week
644
GitHub stars
1
Registry entry
updated 27 Sep 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under homespun.dev, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 27 · about 21,339 tokens of context · checked 11 minutes ago

ToolWhat it doesHint
document_uploadUpload App DocumentCreate a short-lived, byte-scoped upload session for an HTML document authored in a native editor or shell. The caller supplies the exact UTF-8 byte length and SHA-256 hex digest as { size, sha256, app_id? }. The…writes
deploy_appDeploy AppDeploy a v2 app: an HTML document plus a capability manifest, hosted at its own URL. For sandbox-authored files in hosted chat, native file editing and shell tools can create and validate the document. Its UTF-8 byte…writes
list_rowsList RowsList rows in a v2 app's mutable collection. This is also how a collection's current state is polled, since MCP has no streaming: pass the prior next_cursor as `since` to fetch only rows that are new or changed. Returns…read-only
count_rowsCount RowsThe live row count of a v2 app's collection (spec B4, issue #1056), a whole-scope total with no filter and no paging. Gated by the collection's countRead opt-in, independent of its read list: a collection that opted in…read-only
get_rowGet RowFetch a single row by its key from a v2 app collection, through a dedicated relay route rather than a client-side scan. Returns { row }, or an isError row_not_found.read-only
upsert_rowUpsert RowCreate a row in a v2 app's collection, or return the existing row when `key` is already present (deduped:true). Row creation goes through this tool; there is no separate strict-create verb. Omit `key` to add a new row…writes
update_rowUpdate RowUpdate an existing row in a v2 app's collection, replacing its data. Gated by the collection's `update` role list when it declares one, and by its `write` list otherwise, so a collection that scopes updates to the row's…writes
delete_rowDelete RowSoft-delete a row from a v2 app's collection. Recoverable: the row is tombstoned, not destroyed, and restore_row brings it back for 30 days (see list_deleted_rows). A watcher sees the deletion live as op:delete on the…writes
list_deleted_rowsList Deleted RowsList a collection's recently deleted rows: the recovery bin. Deleting a row is a soft delete, so it can be restored with restore_row until recoverable_until passes (30 days after deletion by default). Owner or agent…read-only
restore_rowRestore RowRestore a soft-deleted row, undoing delete_row. The row comes back with its original data and creator, its version bumped. Find restorable keys with list_deleted_rows. Owner or agent only. Fails with restore_expired if…writes
get_feed_eventsGet App Feed EventsPoll a v2 app's change feed for what has happened: row creates, updates and deletes, from any writer, agent or human. It is the long-poll analogue of `homespun apps watch`, since MCP has no streaming. The loop is: call…read-only
appsManage AppsThe v2 app lifecycle apart from creation and redeploy, which deploy_app covers. Actions: list returns the owning human's apps; show returns full detail including manifest, timezone and has_share_token; audit is a…writes
membersManage App MembersA v2 app's membership (auth spec section 6): who besides the owner can sign in to a private app and write to member-scoped collections. Actions: add invites or attaches a member by email, attaching immediately when the…writes
grantsManage App Grant LinksA v2 app's grant links (M5). A grant link is a capability URL that confers a declared custom role (x-homespun-manifest.roles) on a stable per-holder anonymous identity, so a holder's own rows are isolated by author/:own…writes
transferManage App Ownership TransferA v2 app's ownership transfer (issue #1847): handing the app, and the quota and billing responsibility that come with it, to a different human. This is two steps, and `start` completing is only the first one. start…writes
credentialsManage App Service CredentialsA v2 app's scoped service credentials (#1354, #1355): the bearer token an app owner points a backend they host themselves at, so their own server can read and write the app's data without holding the owner's full…writes
connectionsManage App ConnectionsA v2 app's Connections: the stored credential (a static header token, or a full generic OAuth2 client) a manifest webhook rule authenticates its delivery target with, bound to a host so the credential can never be…writes
ingestManage App Inbound HooksA v2 app's inbound catch-hooks (inbound-webhooks). A catch-hook lets an external system such as Stripe, Zapier, Make, Home Assistant or an email router POST JSON to a secret URL that writes into a declared collection,…writes
attachmentsManage AttachmentsBinary attachments (images, PDFs, audio, video) referenced from event payloads and input_data via `format: homespun-attachment-id`. Actions: upload, fetch, presign, finalize, download, show, list, delete, mint_token,…writes
tasteManage UI Taste NotesThe agent's UI taste notes: a short freeform markdown document of presentation preferences gathered from human feedback, such as 'denser layout' or 'no rounded corners'. Reading it before generating or revising an app…writes
keyManage API KeyThe calling agent's API key. Actions: list returns key info (agent_id, key_prefix, timestamps); mint creates a sibling API key for the caller's own agent identity with the same scope and ownership and returns its raw…writes
feedbackManage FeedbackReports a problem with homespun itself to the relay operator, and lists what this agent has already reported. A report is the operator's only visibility into a failure that happened inside an agent's session, so an…writes
agentManage Agent IdentityAgent identity and binding. Actions: whoami returns the resolved relay URL, the active profile and whether a key is configured, with no network call and no secrets; claim binds this agent to a human using a one-shot…writes
communityCommunity TemplatesPublishing an app as a community template, taking your own listing back down, installing a template, and, for relay operators, reviewing submissions. Actions: publish, unpublish, get_config_contract, install,…writes
publisherPublisher ProfileThe caller's community publisher identity: the @-handle and public profile shown in the template gallery. Actions: get returns the profile, including the handle, whether it has been claimed, tenure, and the rating and…writes
reviewCommunity ReviewsRatings and reviews of community templates, responses from a template's own publisher, and, for relay operators, moderation. Actions: create leaves a 1-to-5 star rating and an optional written body on a template the…writes
get_skillGet Skill GuideThe relay's SKILL.md, a generated guide to the Homespun workflow covering events versus records, the schema grammars and the poll loop. Needs no API key. Useful when working out how the other tools fit together, or to…read-only

What https://homespun.dev/mcp answered to tools/list, asked without credentials over MCP 2025-11-25. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 11 warnings · 1 note

  • warnTC07appsthe description is about 632 tokens
  • warnTC07attachmentsthe description is about 529 tokens
  • warnTC07communitythe description is about 579 tokens
  • warnTC07deploy_appthe description is about 1,127 tokens
  • warnTC07feedbackthe description is about 532 tokens
  • warnTC12grantsno type for pin_where[]
  • warnTC14communityallowed values are in the description, not an enum: setup_steps[].key
  • warnTC22attachmentsthe definition is about 1,745 tokens
  • warnTC22communitythe definition is about 3,400 tokens
  • warnTC22deploy_appthe definition is about 2,942 tokens
  • warnTC23server27 tools, about 21,142 tokens of definitions
  • noteTC24server27 of 27 tools have no outputSchema

The checks from /check and anchor check, run each day on the list above: about 21,339 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.