Every workspace has a Model Context Protocol (MCP) endpoint. Connect it to any MCP client that supports streamable HTTP, then ask your AI assistant things like "Which of my apps are running?" or "Restart my shop backend."
1. Create a token
In your workspace, open MCP tokens in the sidebar and create a token. Copy it right away; it is shown only once.
| Scope | Can do |
|---|---|
| Read only | List templates and services, and read service status. |
| Manage services | Everything above, plus start, stop, restart, and retry failed deployments while hosting is paid. |
Tokens expire after 30 days and can be revoked at any time.
2. Add the endpoint
Use the HTTP transport with your token as a Bearer header. Most clients accept a configuration like this:
{
"mcpServers": {
"kilat": {
"type": "http",
"url": "https://kilat.host/mcp",
"headers": { "Authorization": "Bearer kilat_mcp_YOUR_TOKEN" }
}
}
}
Treat the token like a password: keep it out of shared files and repositories, and use your client's secret or environment-variable support where it has one.
3. Tools
| Tool | What it does | Scope |
|---|---|---|
list_templates | Apps you can launch and their plan sizes | Read |
list_apps | Your services with status and URL | Read |
get_app | Status of one service | Read |
start_app | Start a stopped service | Manage |
stop_app | Stop a running service | Manage |
restart_app | Restart a running service | Manage |
deploy_app | Retry a failed deployment of a service you already paid for | Manage |
New purchases, payments, and deletion stay in the dashboard, so an assistant can never spend your wallet balance or remove data.
Security
A token only sees the workspace it was created in. Every action is checked against the same rules as the dashboard, and start, stop, and restart requests made over MCP show up in your workspace notifications. If a token leaks, revoke it from MCP tokens; it stops working immediately.
