# drobek > drobek is an open-source cloud workspace for agent-built web apps. Connect the drobek MCP server from your agent (Claude Code, Codex, Cursor) and it works directly in your drobek workspace: create an app, write its files, get the compile result back on every write, and hand the user a live preview URL — every change is an immutable version. ## Docs - [Full contract](https://drobek.app/llms-full.txt): the MCP connect/OAuth flow, every tool with its inputs, result shape and an example, the app briefing (stack, files, import map, rules), limits, and the error catalogue. - [Build with your agent](https://drobek.app/build-with-your-agent): install the drobek plugin, or connect the MCP server + install the drobek skill. - [Agent guide](https://www.drobek.app/docs/agent.md): how an agent connects, every tool with its scope, the briefing, the skills and llms.txt. - [Platform modules](https://www.drobek.app/docs/modules.md): the backends an app uses through the SDK (sign-in, data, forms, e-mail, files, external APIs) and how a module is written. - [Self-hosting](https://www.drobek.app/docs/self-hosting.md): running a drobek server — configuration, TLS, custom domains, limits. - [Security](https://www.drobek.app/docs/security.md): the threat model and what the platform enforces. ## Plugin (Claude Code, Codex, Cursor) - Claude Code: `claude plugin marketplace add freema/drobek-plugin` then `claude plugin install drobek@drobek`; build with `/drobek:build-app `, move a Claude artifact with `/drobek:port-artifact`. The plugin connects https://drobek.app/mcp. - Codex and Cursor: install instructions in https://github.com/freema/drobek-plugin ## Connect (MCP) - MCP endpoint: https://drobek.app/mcp (OAuth 2.1, PKCE S256; discovery at https://drobek.app/.well-known/oauth-protected-resource/mcp) - Authorization server: https://drobek.app ## Tools - list_apps — List apps (read (any role in the workspace)) - create_app — Create an app (write (editor+ role in the workspace)) - duplicate_app — Duplicate a gallery app (write (editor+ role in the target workspace)) - get_app — Get an app (read (any role in the workspace)) - read_file — Read a file (read (any role in the workspace)) - write_files — Write files (new version) (write (editor+ role in the workspace)) - restore_version — Restore a version (write (editor+ role in the workspace)) - publish — Publish a version (publish (editor+ role in the workspace)) - set_gallery_listing — List an app in the public gallery (publish (editor+ role in the workspace)) - skill_info — Read a skill (read (any signed-in user)) - configure_module — Configure a platform module (write (editor+ role in the workspace)) - query_data — Query an app's data (read (viewer+ role in the workspace)) - get_logs — Read an app's logs (read (viewer+ role in the workspace)) - create_asset_upload — Get an upload URL for a big file (write (editor+ role in the workspace)) - list_assets — List an app's uploaded files (read (viewer+ role in the workspace)) - delete_asset — Delete an uploaded file (write (editor+ role in the workspace)) - list_domains — List an app's custom domains (read (viewer+ role in the workspace)) - add_domain — Add a custom domain (write (editor+ role in the workspace)) - verify_domain — Verify a custom domain (write (editor+ role in the workspace)) - set_primary_domain — Set the primary custom domain (publish (editor+ role in the workspace)) - remove_domain — Remove a custom domain (write (editor+ role in the workspace)) - list_upstreams — List a workspace's proxy upstreams (read (workspace-admin role in the workspace)) - register_upstream — Register a proxy upstream (write (workspace-admin role in the workspace)) - remove_upstream — Remove a proxy upstream (write (workspace-admin role in the workspace)) - set_workspace_publishing — Set a workspace's publishing (publish (super-admins of this server only))