A

app.buildy.so

Buildy hosts interactive web apps that agents can create, update, and render inline, publishing each app at a Buildy URL. The service supports building and operating those apps through either MCP tools or its HTTP API.

3 integrations · MCP · REST

Buildy exposes two developer surfaces on app.buildy.so: a bearer-authenticated HTTP API and an OAuth-protected streamable-HTTP MCP server.

discovered 2mo ago
MCP servers1
REST · OpenAPI2
Credentials
Buildy user token (`bld_user_*`)bearerGet token ↗

Easiest path: run Buildy's device-pairing flow described in Buildy auth. Start with POST https://app.buildy.so/api/pair/start to get a device_code, user_code, and verification_url; show the user_code to the human, send them to https://app.buildy.so/pair, then poll POST https://app.buildy.so/api/pair/poll until the response returns a plaintext bld_user_* token. As a browser-based alternative, sign in at Buildy login and mint a token with POST https://app.buildy.so/api/token as documented in Buildy auth.

Buildy app token (`bld_app_*`)bearerGet token ↗

Create an anonymous app with POST https://app.buildy.so/app and no Authorization header; the create response returns a one-time plaintext bld_app_* token for that app only. Buildy documents this in Buildy auth and in the OpenAPI spec. The token expires if the anonymous app is not claimed.

OAuth 2.0oauth2
OAuth 2.0 — self-onboarding

Point your MCP client at the server URL and approve access in the browser. The server supports OAuth Dynamic Client Registration (RFC 7591), so the client registers itself automatically — no developer-portal app, client_id, or client_secret to create.

Buildy user token (bld_user_*)bearer

Two ways to obtain a bld_user_* token (see https://buildy.so/auth.md):

1. Device-pairing (RFC 8628-shaped): POST /api/pair/start returns { device_code, user_code, verification_url, polling_interval, expires_in }. Show the user_code to the human, direct them to verification_url (https://app.buildy.so/pair), then poll POST /api/pair/poll with { device_code }. On approval the next poll returns { status: "approved", token: "bld_user_..." } exactly once.

2. Browser-mint: sign in at https://app.buildy.so/auth/login, then POST /api/token with an optional label; the plaintext is returned once.

Anonymous app creation does not need a token — POST /app with the source and no Authorization header mints a one-app bld_app_* token (7-day TTL if unclaimed).

conventions · 7/8 published

Publish these signals → /publishing