wraft-mcp
This server provides MCP tools to manage Wraft documents, templates, and approval flows via the Wraft REST API. Key capabilities:
Documents: Create from templates (preferred) or raw markdown, update, list/filter, retrieve, build PDFs, and transition approval states.
Templates & Content Types: Create data templates from markdown with placeholders, list/retrieve templates, list content types (e.g., NDA, Offer Letter) to inspect fields.
Approval Flows: List flows, get flow details, list flow states, and move documents through workflows.
Identity: Verify API key via
whoamito get user, email, organization, roles.Operational: Pagination on all list tools; field machine names are lowercased with spaces to underscores and stripped special chars. Write operations are not idempotent: check before retrying timed-out calls. Supports stdio and Streamable HTTP.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@wraft-mcpCreate a document from the 'Project Proposal' template."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
wraft-mcp
MCP server for Wraft — lets AI agents (Cursor, Claude Code, Claude Desktop) discover and run curated document-lifecycle tools over Wraft's /api/v1 REST API.
Two entrypoints, one shared tool set:
stdio (
wraft-mcp) — the client spawns the server locally; auth via env varsStreamable HTTP (
wraft-mcp-http) — a hosted, stateless service at/mcp; auth via per-requestx-api-keyheader
Tools
Tool | What it does |
| Content types (document variants) with their fields |
| Pre-authored templates with fillable fields |
| Author a template from markdown — |
| Documents in the organisation |
| Preferred create path: fills a template's placeholders from a field-values map and creates the document |
| Raw-payload create (escape hatch) |
| Update content (creates a version) |
| Generate the PDF (synchronous, up to ~2 min) |
| Move a document through its approval flow |
| Approval flows and their states |
| Verify the key: user, email, organisation, roles |
All list_* tools accept page and return page_number / total_pages / total_entries — paginate before concluding something doesn't exist.
Field machine names
create_document_from_template takes fields keyed by machine name: the field's
name lowercased, apostrophes stripped, spaces → _, other characters removed
("Client Name" → client_name). Get field names from get_data_template
(under content_type.fields).
Write tools are not idempotent
A timed-out create_* or build_document call may still have completed on the
server. List or fetch before retrying — a blind retry creates a duplicate
document or another build version.
Related MCP server: task-orchestrator
Cursor / Claude Code configuration
Local (stdio) — recommended for individuals:
{
"mcpServers": {
"wraft": {
"command": "npx",
"args": ["-y", "wraft-mcp@0"],
"env": {
"WRAFT_BASE_URL": "https://app.your-wraft.example",
"WRAFT_API_KEY": "wraft_..."
}
}
}
}During development (before npm publish): "command": "node", "args": ["/ABS/PATH/wraft-mcp/dist/index.cjs"].
Remote (hosted HTTP):
{
"mcpServers": {
"wraft": {
"url": "https://mcp.your-domain.example/mcp",
"headers": { "x-api-key": "wraft_..." }
}
}
}Client timeouts: build_document can run up to 120 s. Raise your MCP
client's tool-call timeout accordingly (Cursor: "timeout" per server entry)
or builds will appear to fail while still completing server-side.
API keys: what to know
Keys are unscoped. A Wraft API key carries its owner's full role permissions — this server's curated tool list limits what the agent can reach, not what the credential could do elsewhere. Create a dedicated least-privilege user for MCP keys.
IP-whitelisted keys don't work via the hosted server. Wraft sees the MCP server's IP, not yours, so whitelisted keys get
403 ip_not_whitelisted. Use a key without an IP whitelist for hosted access, or run stdio from an allowed machine. Do not whitelist the MCP server's egress IP — that nullifies the control for everyone behind the proxy.Keys are never logged by this server; redaction of
x-api-key/authorizationmust also be configured in any logging/APM middleware added around it.
Hosted deployment
docker build -t wraft-mcp .
docker run -p 8080:8080 \
-e WRAFT_BASE_URL=https://app.your-wraft.example \
-e ALLOWED_ORIGINS=https://your-web-agent.example \
wraft-mcpEnv | Meaning |
| Upstream Wraft instance. Must be |
| Listen port (default |
| Comma-separated browser origins. Fail-closed: unset = every request carrying an |
| Request body cap (default 2 MiB) |
Endpoints: POST /mcp (MCP, stateless — POST only), GET /healthz (probes).
The server is stateless (no MCP sessions): run any number of replicas with
no sticky routing; x-api-key is read on every request and forwarded only to
WRAFT_BASE_URL.
Hosting checklist
Build and push the image; deploy with the env above
DNS
mcp.<domain>+ TLS at the edgeEdge rate limit (required) and max request body size
Ingress read timeout ≥ 120 s (the
build_documentupstream timeout)Wire
GET /healthzinto liveness/readiness probesSmoke-test from Cursor with
whoami, then run onecreate_document_from_template→build_document→transition_document_statechain
Development
npm install
npm test # unit tests (template fill + authoring engines)
npm run typecheck
npm run build # dist/index.cjs (stdio) + dist/http.cjs (HTTP)
# live smoke against a running Wraft (runs whoami by default; exits non-zero on tool errors):
WRAFT_BASE_URL=http://localhost:4000 WRAFT_API_KEY=wraft_... npm run smoke
# or pass tool calls:
node scripts/smoke.mjs dist/index.cjs '{"name":"list_flows","arguments":{}}'
# optional pre-push gate (typecheck + tests + build before every push):
git config core.hooksPath .githooksPublishing (maintainers)
Publish only via CI with a scoped npm token, 2FA on the account, and
npm publish --provenance. Only the wraft-mcp stdio bin is meant for the
registry; wraft-mcp-http ships in the Docker image. After publishing, verify
the documented pinned npx config works on a clean machine.
License
AGPL-3.0-only — see LICENSE.md.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityBmaintenanceMCP server for MDMA (Markdown Document with Mounted Applications) — interactive Markdown with forms, approval gates, tables, and more. Exposes the MDMA spec, authoring prompts, package metadata, and live docs to AI assistants so agents can author and integrate MDMA correctly.Last updated721157MIT
- Alicense-qualityAmaintenanceServer-enforced workflow discipline for AI agents. An MCP server providing persistent work items, dependency graphs, quality gates, and actor attribution. Schemas define what agents must produce — the server blocks the call if they don't. Works with any MCP-compatible client.Last updated198MIT
- AlicenseAqualityDmaintenanceMCP server for Word document (.docx) creation and manipulation — the production-grade document automation tool for AI agents.Last updated926MIT
- Alicense-qualityCmaintenanceA sovereign, MIT-licensed MCP server for professional-service workflow tools that runs on your infrastructure with Ed25519 signing, enabling autonomous agents to discover and invoke tools securely.Last updatedMIT
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
Artifact store for AI agents. Hosted OAuth at mcp.artifacta.io/mcp; local stdio via npm/PyPI.
MCP server for generating rough-draft project plans from natural-language prompts.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/salsabeeljamal/wraft-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server