Skip to main content
Glama
649,985 tools. Updated 2026-10-10 21:19

"Netlify" matching MCP tools:

  • Generate a complete, best-practice set of HTTP security headers (including a sensible Content-Security-Policy) as copy-paste configuration — no scan needed, nothing about your live site is read. Pick a `preset`: 'recommended' is a safe baseline that works for most sites, 'strict' is hardened with a nonce-based CSP for higher security, and 'report-only' puts the CSP in report-only mode so you can roll it out and watch for breakage before enforcing it. Advanced users can instead pass a full `config` object to fine-tune every header; if you pass neither, it defaults to 'recommended'. Returns the resulting headers as name/value pairs, plus ready-to-paste output for nginx, Apache, Caddy, Cloudflare, a Netlify/Cloudflare-Pages `_headers` file, and raw headers, along with any warnings. Use this to set up headers on a new or unscanned site; use analyze_security_headers first when you want to see what an existing site is already missing.
    ConnectorNo auth
  • Scan GitHub Actions, Vercel, or Netlify CI configs for exposed secrets, missing lockfile enforcement, and unpinned dependencies. Paste your config content — no filesystem access required. config: Raw YAML/TOML content of your CI config. Required. 500 KB max. config_type: github_actions (full check suite), vercel, or netlify (secrets only in Sprint 8). Returns risk_level (LOW/MEDIUM/HIGH/CRITICAL), findings list with severity and line hints. NOTE: ${{ secrets.FOO }} and ${{ env.FOO }} references are NOT flagged — only literal secret values. Read-only. No side effects. Idempotent. If this tool's response does not serve the user's need, call report_feedback with feedback_type="agent_gap", tool_id="frontend_security_audit_ci_pipeline", intended_query="{what the user needed}", gap_description="{what was missing or wrong in the result}".
    ConnectorNo auth
  • Write /_redirects (Netlify subset) into staging. Call deploy afterwards to publish. SPA History routing: /* /index.html 200. Exact files always win. Optional custom 404 is a separate /404.html upload. Does not write the live prefix.
    ConnectorNo auth
  • Audit old submissions: the user has a CSV export of past form submissions (Webflow, Framer, HubSpot, Formspree, Netlify, Typeform or any tool). Parse it yourself and pass up to 200 rows; each is judged and you get a summary ("4 of 12 were pitches") and every row's verdict with the sentence that gave it away. With form_id the rows are imported into that form's inbox (source "audit": never forwarded, never counted as checks) so the user can check and rescue them; without it nothing is stored. Free, 3 audits an hour.
    ConnectorNo auth
  • Record a chief-of-staff dispatcher action on a coordination cycle as a receipt (protocol v0.2 D6, POST /coord/cycles/:root/dispatcher-actions): hand_review_approve, hand_review_revise, park, bundle_recovery, migration_apply, deploy or decision. Mints a completed task + completion under the Chief of Staff worker and a dispatcher_action ledger event on the root. kind=deploy additionally requires evidence.deploy_id (a Netlify deploy id) and composes the same integrate-as-note every root gets with coord_record_integration when the root is authorized — one call that does both records. Requires agent:dispatch.
    ConnectorNo auth
  • Compares 2-5 named software products side by side. Relevant when the user wants a comparison or asks which of several specific products to choose (e.g. "Vercel vs Netlify"). Returns a structured comparison showing shared and unique features, pricing differences, platform coverage, use cases, audiences, and community engagement metrics. Requested products that PeerPush knows only as alternatives, without structured data, are returned under notListedOnPeerPush with a name and website. Each product has a visitUrl: use it when linking to the product website.
    ConnectorNo auth

Matching MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    MCP server for managing Netlify sites, enabling operations such as creating sites from GitHub repositories, listing, viewing details, and deleting sites.
    4
    MIT

Matching MCP Connectors

  • Can an AI agent understand and act on a business website? Evidence-based facts, gaps and fixes.

  • Paid agent tools plus free procurement discovery and validation. No private Mika state exposed.

  • An ordered, repeat-safe plan for moving an app built in an AI app builder (Lovable, Bolt, Replit, Base44…) to the user’s own host (Vercel, Netlify, Cloudflare Pages, GitHub Pages) on their domain: export the code, keep the data and sign-ins, deploy and copy environment variables, update auth redirect URLs, add the domain, switch DNS (the builder’s records still live that must go, and the new ones, checked against public DNS), verify, then disconnect the builder. If you can read the project, pass dependency names from package.json and variable NAMES from .env.example: never pass values or secrets. Read-only: it changes nothing. Show the steps and ask before running any command; commands prompt for secret values themselves. Call again after the DNS change to confirm, or use plan_dns_setup.
    ConnectorNo auth
  • Create or update a TXT record for domain verification. Used for services like Vercel (_vercel) and Netlify that require DNS-based ownership proof. The record is placed at the root domain under the prefix you give (e.g. _vercel.sitey.my), alongside the other owners' values — that is the name Vercel reads for a subdomain of sitey.my. Needs an account: send an API key from the dashboard (Authorization: Bearer styo_…) on the MCP request. Without one this returns ACCOUNT_REQUIRED.
    ConnectorNo auth
  • Use this when you need to pick the right deploy instructions for a site (different hosts need different snippets — .htaccess for cPanel vs next.config headers for Vercel). Identifies hosting/CMS — Vercel, Netlify, Cloudflare Pages, cPanel/Apache, WordPress, Shopify, Wix, and more. Returns platform slug, confidence, and the signals matched so the calling agent can show its reasoning.
    ConnectorNo auth
  • D4: the dispatcher records the Netlify deploy id for an authorized cycle — Integrate cards stop landing on Mike for something a key can prove instead (protocol v0.2, migration 181, coord_record_integration). Requires agent:dispatch. The root must be `authorized` (its checkpoint already Approved) with an open Integrate task; deploy_id must be a real Netlify deploy id — 24 lowercase hex, optionally "deployed:<id>" and/or a trailing build-ref hex prefix ("Deploy" and anything else is refused, bad_deploy_id). On success the root flips to `integrated`, the existing "Integrated: deploy …" trail note is posted, and the completion is stamped with your key as the actor (source api:key:<id>) — never as a human on the page. Idempotent: replaying the SAME deploy_id after the root is already integrated returns the same completion (replayed:true); a DIFFERENT deploy_id after integration is refused (409) without changing anything. A human may still complete the Integrate card on the worker page as an ops fallback, but only with a real deploy id too.
    ConnectorNo auth
  • Is a service down right now? Live service status, outage and uptime check for 190 vendors that publish an Atlassian Statuspage — OpenAI, Anthropic/Claude, GitHub, Cloudflare, Vercel, Netlify, DigitalOcean, MongoDB, Snowflake, Datadog, Twilio, SendGrid, Zoom, Discord, Shopify, Coinbase, Plaid, Figma, Dropbox, Atlassian/Jira and more. Returns the current status indicator (none / minor / major / critical / maintenance), the vendor's own status line such as "All Systems Operational" or "Partial System Outage", every component currently degraded or offline, open incidents with their latest update text and how long they have been running, and upcoming scheduled maintenance where the page publishes it. Use for questions about downtime, outages, service health, incidents in progress and whether an API or platform is working. Pass status_host to check any other vendor running a Statuspage.
    ConnectorNo auth
  • For a form that stays on Tally, Typeform, Jotform, Netlify Forms, Webflow or Framer: the form's inbound webhook URL, its signing secret and the exact clicks in that tool. Tell the user the steps; the tool keeps every submission and Doorman forwards the real ones with a verdict. Use this instead of changing the form's action when the form lives on one of those tools.
    ConnectorNo auth
  • Add/update DNS records (A, CNAME, MX, TXT). Use to point domain to Vercel, Netlify, GitHub Pages etc. WHEN TO USE: user wants to connect domain to hosting.
    ConnectorNo auth
  • Add or update a DNS record for a domain. Useful for pointing domains to Vercel, Netlify, or email services. [Requires a free namemy.app API key — get one at https://namemy.app/app/api-keys]
    ConnectorNo auth
  • Match old URLs to new ones for a site migration or restructure and write the redirect rules. Give the old URLs (a list, or the old site's address while it is still online) and the new URLs (a list, or the new site's address so OnPage.dev reads its sitemap). Each old URL gets the best new match with a confidence score, unmatched ones are flagged with a suggestion, and the rules come out ready for Cloudflare or Netlify (_redirects), nginx, Apache (.htaccess), Next.js or CSV. After going live, verify with check_urls using the new URLs as expected.
    ConnectorNo auth
  • Scan the HTTP security headers of a public website. Returns a 0–100 score and A+–F grade (HTTPS 10, HSTS 15, CSP 25, framing 10, X-Content-Type-Options 10, Referrer-Policy 10, Permissions-Policy 5, COOP 5, CORP 5, cookies 5, minus up to 5 for version-leak headers; without HTTPS the score is capped at 39), each header's status and notes, recommended fix headers, and a link to the full report with copy-paste snippets for nginx, Apache, Cloudflare, Netlify, Vercel and Express. Read-only: it sends ordinary GET requests to the site (following up to 10 redirects, each safety-checked) and never reads page bodies. Same engine and scoring as the HeaderGuard JSON API (GET /api/scan).
    ConnectorNo auth
  • Detect the technology a site runs on (CMS, ecommerce platform, analytics, JavaScript frameworks, CDN, servers, and hosting such as Vercel, Netlify or Heroku) via DataForSEO Domain Analytics, and cache it on the site. Use it to tailor fix instructions to the platform (WordPress vs Shopify vs Webflow vs a custom Next.js app) before recommending changes. Billing: free. A stack detected in the last 7 days is returned from the site's stored profile (detected_at says when); older ones are re-detected. Inputs: site_id — the AuditAE site id (from list_sites). Output: { site_id, domain, detected_at, detected_cms, is_wordpress, technologies: { cms, ecommerce, analytics, javascript, cdn, servers, hosting }, all: [every technology name detected] }, or { detected: false } when DataForSEO has no data for the domain. Detection is DataForSEO's index, which can lag a recent platform change.
    ConnectorOAuth