@stringpush/setup-mcp
v0.8.0
Published
Local stdio MCP server for AI-assisted StringPush project setup
Downloads
1,036
Readme
@stringpush/setup-mcp
Local stdio MCP server for StringPush setup automation.
Intent
Run setup tools on the developer's machine so setup tokens and one-time runtime API keys do not pass through a hosted MCP service. Every setup MCP session must use a short-lived, user-bound token from admin Settings → AI setup.
Install from npm only — customers do not clone the StringPush monorepo.
Cursor
Add to ~/.cursor/mcp.json (or project .cursor/mcp.json):
{
"mcpServers": {
"stringpush-setup": {
"command": "npx",
"args": ["-y", "@stringpush/setup-mcp"],
"env": {
"STRINGPUSH_API_BASE": "https://api.platform.stringpush.com",
"STRINGPUSH_SETUP_TOKEN": "<paste short-lived setup token>"
}
}
}
}Claude Desktop / Claude Code
Add to your Claude MCP config (for example ~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"stringpush-setup": {
"command": "npx",
"args": ["-y", "@stringpush/setup-mcp"],
"env": {
"STRINGPUSH_API_BASE": "https://api.platform.stringpush.com",
"STRINGPUSH_SETUP_TOKEN": "<paste short-lived setup token>"
}
}
}
}Environment
| Variable | Required | Default | Purpose |
|----------|----------|---------|---------|
| STRINGPUSH_SETUP_TOKEN | yes | — | Scoped setup token from admin Settings → AI setup |
| STRINGPUSH_API_BASE | no | https://api.platform.stringpush.com | API host — use your staging API URL when the workspace is on staging |
Do not share one MCP config or token across teammates.
Tool policy
Allowed tools are setup-only:
- list/create project
- create application
- list environments/locales
- start/check domain verification
- create a translation key
- upsert a staging value
- publish staging
- validate runtime ping
Not exposed:
- deletes
- production publish or promotion
- sync token management
- members, billing, webhooks, platform ops
- generic API passthrough
Mutating tools require confirm: true. Staging write/publish tools resolve the provided environment ID and reject dev or production.
Secret handling
- Do not commit
.envfiles. - Runtime API keys are returned only when an application is created. Store them immediately.
- Tool errors redact common StringPush token shapes.
- The MCP does not log tokens or runtime keys.
Docs MCP (read-only, hosted)
Pair with the remote docs MCP — no npm install for docs:
"stringpush-docs": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.docs.platform.stringpush.com/mcp"]
}