Back to Browse

Krexel MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Ship and edit static sites from any MCP-compatible AI. The AI is the brain; Krexel is the hands.

About

Ship and edit static sites from any MCP-compatible AI. The AI is the brain; Krexel is the hands.

Security Report

4.2
Use Caution4.2High Risk

krexel-mcp is a well-structured MCP server for deploying and editing static sites via the Krexel API. Authentication is properly implemented with Bearer token forwarding, and permissions are appropriate for its purpose. However, there are several moderate-severity concerns: credentials are accepted via environment variables without validation of their format/length, file path validation uses a simple regex pattern that could be bypassed, the API client does not validate HTTP responses against documented schemas, and error messages may leak sensitive deployment details. Code quality is generally good with comprehensive tests, but some error handling is overly broad. Supply chain analysis found 6 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.

5 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-syfer-web-krexel-mcp": {
      "args": [
        "-y",
        "krexel-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

krexel-mcp

Ship AND edit static sites from any AI assistant that speaks the Model Context Protocol.

krexel-mcp is the official MCP server for Krexel — a "your AI ships and edits your live site" API. Point any MCP-compatible client (Claude Desktop, Cursor, Windsurf, VS Code) at this server and your assistant can deploy, list, edit, rollback, and inspect sites just by talking.

Quickstart

Add krexel-mcp to your MCP client configuration:

{
  "mcpServers": {
    "krexel": {
      "command": "npx",
      "args": ["-y", "krexel-mcp"],
      "env": {
        "KREXEL_API_URL": "https://api.krexel.com",
        "KREXEL_API_KEY": "krx_live_••••••••••••••••",
        "KREXEL_MASTER_KEY": "<your-32-byte-hex-key>"
      }
    }
  }
}

Restart your client. The assistant now sees nine Krexel tools.

Tools

ToolWhat it does
ship_siteUpload a built site folder. Returns a deploy_id and preview URL.
edit_filePatch a deployed site (create / replace / replace_all / delete). 0.1 deploy.
list_filesList the files in a deployed site (path + size + sha256).
read_fileRead one file's content from a deployed site.
list_deploysList recent deploys from local state. Optional domain filter.
get_logsFetch build logs for a deploy.
rollbackMark a previous deploy as the current good version.
set_envEncrypt and persist an env var for a domain (AES-256-GCM).
get_statusReturn account, deploy count, plan, and state directory.

The conversational-edit flow

  1. AI calls list_files(deploy_id) to see what files exist on the site.
  2. AI calls read_file(deploy_id, path) to read the file it wants to change.
  3. AI generates the new content itself, then calls edit_file(deploy_id, op: "replace", file, find, value, message).
  4. Krexel ships the patch as a new deploy — live in ~8 seconds, 0.1 deploy against the customer's quota. The new deploy_id and parent_deploy_id are returned so the AI can chain further edits on top.

The AI is the brain. Krexel is the hands.

All tools take plain JSON arguments and return JSON. Tool schemas are discoverable via the standard MCP tools/list request.

Configuration

Env varRequiredDefaultNotes
KREXEL_API_URLnohttps://api.krexel.comBase URL of the Krexel orchestrator API.
KREXEL_API_KEYno*~/.krexel/auth.jsonAccount API key. Forwarded as Authorization: Bearer *** to every API call. *Required unless saved by krexel login.
KREXEL_MASTER_KEYyes*32-byte hex string for env-var encryption. *Required for set_env.

State files are written under $KREXEL_HOME (default ~/.krexel/).

License

MIT © Syfer

Reviews

No reviews yet

Be the first to review this server!