Back to Browse

Branderux MCP Server

Developer ToolsModerate6.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Turns any agent into a full agentic application — branded, interactive screens generated at runtime.

About

Turns any agent into a full agentic application — branded, interactive screens generated at runtime.

Remote endpoints: streamable-http: https://mcp.branderux.com/mcp

Security Report

6.8
Moderate6.8Moderate Risk

BranderUX MCP is a well-architected OAuth-based server with strong authentication practices and appropriate permission scoping. The codebase demonstrates good security hygiene with pre-flight validation for user-submitted code, safe dependency management, and proper confirmation gates on destructive operations. Minor code quality observations exist but do not materially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

7 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

BranderUX MCP

The official BranderUX MCP server. It gives an AI agent real control over BranderUX projects — brand, custom elements, screens, API keys — plus the verified reference docs it needs to integrate the SDK correctly.

Connect: https://mcp.branderux.com/mcp · Docs: https://branderux.com/mcp

claude mcp add --transport http branderux https://mcp.branderux.com/mcp

No API keys: the first tool call opens your browser for a one-click BranderUX sign-in (OAuth 2.1 + PKCE, scoped and revocable). Access is currently limited to design partners — everyone else lands on the waiting list.

Tools

Knowledge (no scopes needed — signing in is still required to reach the server): get_started · read_doc · search_docs · get_integration_snippet

Projects (projects:*): whoami · list_projects · get_project · create_project · update_brand_settings · update_project_settings · delete_project

Screens (projects:write): list_screens · get_screen · put_screen · delete_screen — custom screens live on the project aggregate; these tools do the read-modify-write for you.

Custom elements (elements:*): list_elements · get_element · create_element · publish_element_version · preview_element · delete_element — your agent writes the TSX; the server pre-flight validates it (compile + sandbox import allowlist + export contract) before publishing. In clients that support MCP Apps, create_element, publish_element_version and preview_element render the element LIVE in the panel — demo props applied, clicks showing the exact query they would send.

API keys (keys:manage): create_api_key · list_api_keys · set_key_origins · revoke_api_key

Playground (no project needed): generate_screen — renders a real branded, interactive screen in the panel with demo data, powered by the same published @brander/mcp-tools package customers install. Ask for a storefront, analytics or order-flow screen to see actual BranderUX output before building anything.

Every destructive tool requires an explicit confirm: true.

Local development

npm install
BRANDER_API_BASE=http://localhost:8080/api/v1 npm run dev   # http://localhost:3010/mcp
EnvDefaultPurpose
BRANDER_API_BASEhttp://localhost:8080/api/v1BranderUX API base
MCP_RESOURCE_URLhttp://localhost:3010Public URL of this server (OAuth resource id)
OAUTH_ISSUER_URL= BRANDER_API_BASEAuthorization server issuer

The server is stateless: one MCP server instance per request, bound to the caller's bearer. Deploy target is Vercel (api/mcp.ts + api/oauth-protected-resource.ts).

License

MIT

Reviews

No reviews yet

Be the first to review this server!