app.buildy.so
Buildy hosts interactive web apps that agents can create, update, and render inline, publishing each app at a Buildy URL. The service supports building and operating those apps through either MCP tools or its HTTP API.
Buildy exposes two developer surfaces on app.buildy.so: a bearer-authenticated HTTP API and an OAuth-protected streamable-HTTP MCP server.
- Buildy MCP serverdetected
- Buildy HTTP APIdiscovered
- Buildy HTTP APIdeclared
Easiest path: run Buildy's device-pairing flow described in Buildy auth. Start with POST https://app.buildy.so/api/pair/start to get a device_code, user_code, and verification_url; show the user_code to the human, send them to https://app.buildy.so/pair, then poll POST https://app.buildy.so/api/pair/poll until the response returns a plaintext bld_user_* token. As a browser-based alternative, sign in at Buildy login and mint a token with POST https://app.buildy.so/api/token as documented in Buildy auth.
Create an anonymous app with POST https://app.buildy.so/app and no Authorization header; the create response returns a one-time plaintext bld_app_* token for that app only. Buildy documents this in Buildy auth and in the OpenAPI spec. The token expires if the anonymous app is not claimed.
Point your MCP client at the server URL and approve access in the browser. The server supports OAuth Dynamic Client Registration (RFC 7591), so the client registers itself automatically — no developer-portal app, client_id, or client_secret to create.
Two ways to obtain a bld_user_* token (see https://buildy.so/auth.md):
1. Device-pairing (RFC 8628-shaped): POST /api/pair/start returns { device_code, user_code, verification_url, polling_interval, expires_in }. Show the user_code to the human, direct them to verification_url (https://app.buildy.so/pair), then poll POST /api/pair/poll with { device_code }. On approval the next poll returns { status: "approved", token: "bld_user_..." } exactly once.
2. Browser-mint: sign in at https://app.buildy.so/auth/login, then POST /api/token with an optional label; the plaintext is returned once.
Anonymous app creation does not need a token — POST /app with the source and no Authorization header mints a one-app bld_app_* token (7-day TTL if unclaimed).
conventions · 7/8 published
- integrations.json✓https://app.buildy.so/.well-known/integrations.json
- llms.txt✓https://app.buildy.so/llms.txt
- API catalog✓https://app.buildy.so/.well-known/api-catalog
- OpenAPI document✓https://app.buildy.so/openapi.json
- MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✓https://app.buildy.so/.well-known/oauth-protected-resource
- Agent card✓https://app.buildy.so/mcp
- Agent skills✓https://app.buildy.so/.well-known/agent-skills/index.json
Publish these signals → /publishing