Back to Browse

Rendley MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Create videos with prompts, and use Rendley’s video editor to adjust anything you need.

About

Create videos with prompts, and use Rendley’s video editor to adjust anything you need.

Remote endpoints: streamable-http: https://mcp.rendley.com/mcp

Security Report

4.2
Use Caution4.2High Risk

The Rendley MCP server is a well-structured video editing tool with generally sound authentication and authorization practices. It properly validates API keys, implements bearer token authentication, and uses appropriate input validation with Zod schemas. However, there are moderate concerns around missing SSRF protections for certain external URL operations, insufficient error handling in edge cases, and potential information disclosure through verbose error messages. Supply chain analysis found 10 known vulnerabilities in dependencies (0 critical, 6 high severity).

6 files analyzed · 17 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

https://api.rendley.com/v1Optional

Environment variable: API_BASE_URL

https://app.rendley.comOptional

Environment variable: APP_BASE_URL

noneOptional

Environment variable: MCP_PUBLIC_URL

localOptional

Environment variable: BROWSER_MODE

trueOptional

Environment variable: HEADLESS

trueOptional

Environment variable: USE_CHROME_CHANNEL

falseOptional

Environment variable: CPU_ONLY

120Optional

Environment variable: QUEUE_CONCURRENCY

noneOptional

Environment variable: CORS_ORIGINS

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Rendley MCP

The MCP server for Rendley. It gives an AI assistant a full video editor: connect it once, then create and edit video by describing what you want, in the same chat you already work in. Under the hood it drives the hosted Rendley editor in a browser and calls the hosted Rendley API on your behalf:

  • Editor: https://app.rendley.com
  • API: https://api.rendley.com/v1

The same agent is also reachable over plain HTTP (POST /v1/agent) for backends that don't speak MCP. See REST example.

There are two ways to use it:

  1. Use the hosted server at https://mcp.rendley.com/mcp. Nothing to run. See Connect a client.
  2. Self-host this server against the hosted Rendley API. See Self-host the server.

📖 Full documentation, with step-by-step setup guides and screenshots: docs.rendley.com/mcp


Connect a client

Any client that speaks remote MCP can connect. Point it at the endpoint and authenticate by signing in or with an API key:

https://mcp.rendley.com/mcp
  • Sign in with Rendley (recommended): the client opens a Rendley sign-in tab and you approve access. Nothing to copy, and you can revoke it later.
  • API key: the client sends an Authorization: Bearer YOUR_RENDLEY_API_KEY header. Create one at Settings → API Keys; see Get an API key.

Most clients accept a JSON config like this:

{
  "mcpServers": {
    "rendley": {
      "url": "https://mcp.rendley.com/mcp",
      "headers": { "Authorization": "Bearer YOUR_RENDLEY_API_KEY" }
    }
  }
}

For sign-in, drop the headers block and let the client run the browser flow.

The docs have illustrated, per-client walkthroughs:

  • Claude: desktop, web, and Claude Code.
  • Codex: the Codex desktop app and CLI.
  • Other clients: any other client that speaks remote MCP, plus the mcp-remote bridge for local-only clients.

For Claude Code specifically:

claude mcp add --transport http rendley https://mcp.rendley.com/mcp \
  --header "Authorization: Bearer YOUR_RENDLEY_API_KEY"

Try it

Ask the client what it can do, then try a simple request:

What can Rendley do here?

List my projects.

If it lists the Rendley tools and your projects, you're connected. From there, describe the video you want and the assistant creates a project, builds the edit, and returns a link.


Self-host the server

This repo is the MCP server only; it does not run the full Rendley stack locally. It talks to the hosted Rendley API and editor. When you self-host, point clients at your own https://<host>/mcp instead of https://mcp.rendley.com/mcp.

Requirements

  • Bun >= 1.1 (or Docker)
  • A Rendley account to connect with. Clients authenticate per request with their own API key (Settings → API Keys, guide) or OAuth sign-in. The server stores no key of its own.

Run locally

git clone https://github.com/rendleyhq/rendley-mcp.git
cd rendley-mcp

bun install
bun dev                       # http://localhost:8787

API_BASE_URL and APP_BASE_URL default to the hosted Rendley API and editor, so the server boots out of the box with no .env at all; copy .env.example only to point at a different stack. The server holds no credentials of its own: every request authenticates with the caller's own API key or OAuth token.

By default the server drives the editor with a local Chrome (BROWSER_MODE=local), so no extra infrastructure is needed. bun install downloads a bundled Chromium; with USE_CHROME_CHANNEL=true it prefers your installed Google Chrome and falls back to the bundled browser. Set HEADLESS=false to watch the editor in a visible window, and CPU_ONLY=true on machines without a usable GPU.

Verify it's up:

curl http://localhost:8787/health
# {"status":"ok","browser_mode":"local"}

Docker

docker compose up -d --build
curl http://localhost:8787/health

Connecting a client to your instance

Use the same client steps as the hosted server, but swap the endpoint for your host (e.g. http://localhost:8787/mcp) and authenticate with your API key as a bearer token:

{
  "mcpServers": {
    "rendley": {
      "url": "http://localhost:8787/mcp",
      "headers": { "Authorization": "Bearer YOUR_RENDLEY_API_KEY" }
    }
  }
}

OAuth. OAuth sign-in is always on. Clients that support it (Claude connectors, ChatGPT, codex mcp login rendley) can sign in via the hosted login flow instead of pasting a key; the server advertises the authorization server through RFC 9728 protected-resource metadata. Set MCP_PUBLIC_URL to this server's public URL so discovery points at the right host.

Remote browser mode

For hosted deployments, set BROWSER_MODE=remote and point the server at a deployed remote browser worker. The server mints a short-lived editor session token and posts it to the worker, so the caller's credential never leaves this process:

BROWSER_MODE=remote
BROWSER_WORKER_URL=https://<your-browser-worker-host>
BROWSER_WORKER_TOKEN=<must match the worker's secret>

Configuration

All configuration is via environment variables; start from .env.example, which documents every option. The essentials:

VariableDefaultPurpose
API_BASE_URLhttps://api.rendley.com/v1Rendley API root. Override for staging or a self-hosted stack.
APP_BASE_URLhttps://app.rendley.comRendley editor root. Override for staging or a self-hosted stack.
MCP_PUBLIC_URLnoneThis server's public URL, advertised for OAuth discovery.
BROWSER_MODElocallocal = in-process Playwright Chrome; remote = remote browser worker.
HEADLESStrueLocal mode only; false shows the browser window.
USE_CHROME_CHANNELtrueLocal mode only; prefer installed Chrome over bundled Chromium.
CPU_ONLYfalseForce software WebGL (SwiftShader) on hosts without a GPU.
QUEUE_CONCURRENCY120Max concurrent browser-backed jobs per container.
CORS_ORIGINSnoneCSV allowlist of browser origins. Empty disables CORS.

Endpoints

MethodPath
POST/mcpMCP Streamable HTTP transport
POST/v1/agentStart an async edit job
GET/v1/jobs/:idPoll a job
GET/healthLiveness

REST example

You don't need an MCP client to drive the agent. The same agent is available over plain HTTP. Start a job, get an id back, and poll until the video is ready. Full reference: docs.rendley.com/mcp/api-access.

# Start a job (swap in http://localhost:8787 for a self-hosted instance)
curl -X POST https://mcp.rendley.com/v1/agent \
  -H "Authorization: Bearer $RENDLEY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "prompt": "Create a 9:16 slideshow from these files",
    "files": [
      { "url": "https://cdn.example.com/photo1.jpg" },
      { "url": "https://cdn.example.com/photo2.jpg" }
    ]
  }'

# Poll it
curl -H "Authorization: Bearer $RENDLEY_API_KEY" \
  https://mcp.rendley.com/v1/jobs/<job_id>

Runtime notes

  • Single tenant per instance.
  • The browser launches lazily on the first browser-backed request; concurrent requests reuse it via separate tabs, which close on completion.
  • Media attachments are public URLs only. The editor imports them via the batch upload API (no local-file uploads through MCP).
  • REST jobs are asynchronous and must be polled. Job state is held in memory: completed records are retained for 1 hour, and a restart drops all job state (in-flight jobs are lost, finished results become unfetchable).
  • /health is healthy whenever the server can serve; browser launch failures surface on browser-backed requests.

Scripts

bun dev          # watch mode, pretty logs
bun start        # production start
bun run typecheck

License

Apache License 2.0. © 2026 Rendley.

Reviews

No reviews yet

Be the first to review this server!