Fine Structure
Build and host full-stack apps from a prompt, with agents that reach you on WhatsApp and email.
- 1.0.2
- Version
- remote
- Transport
- 93
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 93 tools scanned
- metadata: scanned
No findings.
Tools (93)
create_app
Create a new application from a natural language prompt. The AI generates a complete web app with pages, components, styling, and data models. Returns a job_id - poll get_job_status to track progress. When the job is done, the app is ready.
agency_create_client
Agency mode only. Create or update a client record for an account-level agent. This does not create a verified Fine Structure user account and does not transfer ownership.
agency_list_clients
Agency mode only. List client records and app handoff status for the authenticated agent.
agency_create_client_app
Agency mode only. Create a new app owned by the agent, start generation, and create a claim link for the client. Ownership transfers only when the invited client logs in with the same email and accepts the claim link.
agency_create_claim_link
Agency mode only. Create a client claim link for an existing app owned by the agent. The client must log in with the invited email before ownership transfers.
agency_get_claim_status
Agency mode only. Inspect one handoff status without exposing the raw claim token.
update_app
Update an existing application with a new prompt. The AI modifies the app based on your instructions. Creates a Saved Version before the update. Returns a job_id - poll get_job_status to track progress.
publish_app
Publish an app - freeze current state and make it live at a URL. Also configures whether the public URL is open, app-login gated, private, or inferred from the app.
get_platform_guide
Return a machine-readable Fine Structure / FSe2 guide for AI agents. Call this at the start of an MCP session to learn app files, entities, safe edit workflows, validation, publishing, A/B testing, secrets, and platform rules.
get_recommended_workflow
Return the recommended MCP tool sequence for a task type. Use this before creating apps, editing files, seeding data, publishing, setting up A/B tests, restoring versions, or configuring secrets/integrations.
get_job_status
Poll the status of an async generation job. Use this after create_app or update_app to know when the job is done. Returns status ('running' or 'done'), progress events, and result summary when complete.
get_app_status
Get app overview: files, published state, URL, active jobs.
get_app_links
Return editor, preview, published path, subdomain, and custom-domain links plus whether each works for anonymous visitors, app users, or Studio users based on publish and auth settings.
list_app_domains
List an app's platform path, subdomain, and configured custom domain with verification, SSL, primary-domain, redirect, publish, and login-gating status.
set_app_subdomain
Set or clear the app platform subdomain - the '<subdomain>.<base domain>' host Fine Structure already serves the app on. Runs the same ownership, format, reserved-name and uniqueness checks as the Studio subdomain field because it calls the same model function. Replacing a subdomain takes effect immediately and creates NO redirect: the previous name stops resolving to this app and is released for anyone to claim. Pass an empty subdomain to clear it. For a domain the user owns, use add_custom_domain instead.
check_subdomain_available
Check whether a platform subdomain can be claimed before calling set_app_subdomain. Returns available plus a status of available, invalid, reserved, taken, current, or empty, with the exact reason. Pass app_id (an app you own) to have that app's own current subdomain reported as 'current' instead of 'taken'.
add_custom_domain
Attach or replace the app custom domain through the same Fine Structure Studio custom-domain flow. Returns exact DNS verification and routing records for the user to configure at their DNS provider.
get_domain_verification
Return the exact DNS records and instructions required to verify and route the app custom domain.
check_domain_verification
Check Fine Structure custom-domain verification and SSL status for the configured custom domain, then save the latest status.
set_primary_domain
Set which app host should be treated as primary for generated links and custom-domain redirects.
remove_custom_domain
Remove the configured custom domain from the app and clean up the platform-side hostname registration when possible.
get_domain_ssl_status
Return SSL/certificate status and pending certificate validation DNS records for the app custom domain.
configure_domain_redirects
Configure custom-domain redirect policy: primary domain, optional www/root redirect, and HTTPS enforcement.
list_apps
List applications owned by the authenticated user, newest activity first. Returns up to `limit` apps per call plus the total count; page with `offset` when the account has more.
get_app_files
Get the file tree for an app with paths and byte sizes.
read_app_file
Read one source file from an app's virtual filesystem. Paths follow the Fine Structure app file API, documented at https://finestructure.ai/api/mcp/docs.
read_app_files
Read several source files from an app's virtual filesystem. Paths follow the Fine Structure app file API, documented at https://finestructure.ai/api/mcp/docs.
write_app_file
Create or replace one file in an app's virtual filesystem. Creates a Saved Version before changing content. Paths and file model follow the Fine Structure app file API, documented at https://finestructure.ai/api/mcp/docs.
patch_app_file
Patch one file by replacing exact text. Safer than full overwrite for targeted edits. Creates a Saved Version before changing content. Paths follow the Fine Structure app file API, documented at https://finestructure.ai/api/mcp/docs.
rename_app_file
Rename or move one app source file atomically. Internally stages an upsert at new_path and a delete at old_path, validates the resulting app state, and creates a Saved Version before applying.
get_app_detail
Deep introspection of an app: entities, pages, settings, integrations, environment variables, and file structure. Use this to understand what an app contains before updating it.
get_entities
Get all entity (data model) schemas for an app, with record counts. Each entity has fields, types, and relationships.
query_entity
Query app data records for one entity with optional exact-match filters.
seed_entity
Compatibility tool for starter-record creation. Inserts directly for the authenticated app owner; by default it only seeds an empty entity (skip_if_not_empty).
create_entity_records
Create/insert records in one app entity. Executes directly for the authenticated app owner and returns the created record ids.
update_entity_record
Compatibility tool that updates one record by ID. Executes directly for the authenticated app owner.
update_entity_records
Update exact records. Select explicit record_ids or exact-match filters and provide shared changes, or provide per-record updates. Executes directly for the authenticated app owner; expected_count aborts the write on a mismatch.
delete_entity_records
Delete exact records by ID or exact-match filters. Executes directly for the authenticated app owner; pass expected_count as a safety check to abort on a mismatch.
get_pages
Get all pages in an app with their file paths and sizes.
get_errors
Get recent runtime errors for an app (last 20). Useful for diagnosing issues before updating.
get_app_analytics
Traffic analytics for an app's published site over a chosen window: total views, unique visitors, daily series, top pages, top referrer domains and device split.
get_preview_url
Return editor preview and published/public URLs for an app.
list_saved_versions
List restorable Saved Versions for an app, including versions created by MCP writes.
create_change_set
Create a staged file change set. Add multiple file changes, validate them as one app state, then apply atomically.
add_file_change
Stage one file upsert or delete inside a change set. Does not modify the live app until apply_change_set. Paths follow the Fine Structure app file API, documented at https://finestructure.ai/api/mcp/docs.
validate_change_set
Validate current app files plus staged change set files before applying.
apply_change_set
Apply a staged change set to the app. Creates a Saved Version before applying. Blocks on validation errors unless force=true.
discard_change_set
Discard a pending staged change set without changing app files.
validate_app
Run deterministic app checks: syntax, imports, routes/pages, entity schemas, missing entities, and recorded runtime errors.
inspect_preview
Return server-side preview context: URLs, persisted runtime/network errors, static clickable candidates, pages, and explicit live-browser availability.
get_app_security_context
Return safe security context for one owned app: owner id/email, Studio collaborators, generated-app members, route policies, entity policies, function policies, and recent security audit entries. Does not return secrets and does not grant access to other apps.
set_route_policy
Create or update a server-owned route policy for a generated app route.
set_function_policy
Create or update the server-owned access policy of a backend function (functions/<name>.js). Without a policy a function answers only to the app owner's Studio token (401 for app visitors and webhooks). Recipes: anonymous checkout step or inbound webhook/IPN -> require_auth=false; signed-in members -> require_auth=true + allowed_roles (e.g. ['authenticated'] or ['admin','staff']); webhook with a shared secret -> require_secret=true + secret_name (an app secret) that the caller sends in secret_header. allowed_hosts fences the function's outbound network to those hosts plus the platform backend; omit it for open egress.
invoke_function
Run a backend function of an owned app exactly like the HTTP route and return its status and JSON. caller='owner' runs as the app owner; caller='anonymous' first evaluates the function policy as a public visitor and returns the 401/403 decision without running when access would be denied. Use it to verify a function (secrets, outbound calls, policy) before wiring it into the app.
create_platform_request
Open a request to the Fine Structure platform team: a bug, a feature request or a question about the platform itself (not about the user's app). Use it when something in the platform blocks you instead of working around it. Give a reproduction the team can run (invoke_function / curl / the exact tool call and result), what you expected, and how the team will know it is closed. Credential-looking values are redacted. Returns request_id and a Studio URL; the team's replies, status changes and deployments come back through get_platform_request / list_platform_requests. Limits: 20 per account per day, 32 KB.
get_platform_request
One platform request with its full history: team replies, status changes (open | triaged | in_progress | needs_info | deployed | wont_fix) and what was deployed (commit, time). Pass since=<ISO timestamp> to get only the events after it.
list_platform_requests
Your account's platform requests, newest activity first. Call it at the start of a session with since=<the updated_date you last saw> to learn what changed: replies, needs_info questions to answer, deployments with their commit. Filters: app_id, status.
reply_platform_request
Add a reply or a finding to one of your platform requests without opening a new one, e.g. to answer a needs_info question (that reopens it).
update_platform_request
Platform team only: set the status of a request (open | triaged | in_progress | needs_info | deployed | wont_fix), attach the deployed commit and/or reply. deployed and needs_info mail the requester.
set_entity_policy
Replace server-side entity access policy. Optional action rules override read/write roles and can allow public create without public read, update, or delete. Omitting rules replaces any existing action rules with read/write role behavior.
list_app_members
List generated-app runtime users/members for an app. This is separate from Studio project collaborators.
invite_app_member
Provision a generated-app runtime member with a role. This does not create a Studio collaborator, and the owner role cannot be assigned. password is required: ask the account owner which password the member should get. This tool never generates one, because a generated password would come back in the result and that is a live credential in the conversation transcript.
update_app_member_role
Update a generated-app runtime member role. This cannot assign owner and cannot change the Fine Structure account owner.
remove_app_member
Remove a generated-app runtime member.
get_app_security_audit
Read recent server-side security audit events for an app.
compare_saved_versions
Compare two Saved Versions and return per-file additions, removals, modifications, and compact diffs.
compare_current_to_version
Compare the current app files to a Saved Version and return compact per-file diffs.
restore_file_from_version
Restore one file from a Saved Version instead of restoring the entire app. Creates a Saved Version before changing the file. Paths follow the Fine Structure app file API, documented at https://finestructure.ai/api/mcp/docs.
create_entity_schema
Create an entity schema file in entities/<Entity>.json. Creates a Saved Version before writing.
update_entity_schema
Replace or shallow-merge an existing entity schema file. Creates a Saved Version before writing.
validate_entity_relationships
Validate entity relationship metadata and *_id references against existing entity schemas.
update_entity_metadata
Set relationship/index metadata on an entity schema. This stores metadata in the schema file; DB index creation is automatic where supported by the platform.
list_secret_keys
List secret key names for an app. Secret values are never returned.
set_secret
Create or update one encrypted app secret. The secret value is never returned.
delete_secret
Delete one app secret by key.
list_integrations
List supported integrations and safe connected integration metadata for an app. Tokens/secrets are never returned.
configure_integration
Store safe non-secret integration metadata for an app. Use set_secret for API keys/tokens.
list_ab_tests
List the platform A/B tests configured for an app.
create_ab_test
Create a native Fine Structure A/B test between existing app pages. Use update_app first if a variant page still needs to be generated. Creates a Saved Version before the change.
update_ab_test
Update a native A/B test, including active state, variants, traffic, and conversion goal. Creates a Saved Version before the change.
delete_ab_test
Delete a native A/B test from an app. Creates a Saved Version before the change.
get_ab_test_stats
Get views, unique visitors, conversions, and conversion rates for an A/B test.
get_app_metadata
Read the saved public HTML-shell identity: name, description, language and image URLs/dimensions. Same settings as Studio SEO/GEO.
set_app_metadata
Update public HTML-shell metadata immediately, without AI, code edits, publishing or Saved Versions. Upload social_image/icon as base64 PNG/JPEG/WebP (max 5 MB, 4096px); null clears an image. Language sets HTML lang/dir and OG locale. For per-page cards, write optional seo.json and publish it; dynamic entries may read only explicitly public entity records.
create_agent
Create an autonomous AI agent on the user's Fine Structure account: a standing worker, not a chat session. It gets the platform's default safe tool policy and its own email address, it can read and write the app database, and once the owner phone is verified (see get_agent_whatsapp) it can message its owner on WhatsApp and by email through the platform system channels. Pair it with schedule_agent_task for recurring work such as following up new leads on WhatsApp each morning, watching an app for runtime errors, or sending a weekly summary. Messaging anyone other than the verified owner requires a channel the owner connects in the Fine Structure Studio.
list_agents
List the AI agents on the user's account with id, name, role, status and FineMail address.
schedule_agent_task
Create a scheduled task for one of the user's agents. Supported schedule types: once (run_at ISO local time + timezone), interval (interval_minutes 5-1440), hourly, daily (time HH:MM + timezone), weekly (time + timezone + days_of_week 0=Sunday..6), cron (5-field expression + timezone), manual (only runs on demand). Returns the normalized schedule and the computed next_run_at so you can read the fire time back to the user in their timezone.
list_agent_tasks
List scheduled tasks for one agent (or the whole account), including schedule, status and next_run_at.
get_agent_whatsapp
Read the WhatsApp state of the connected account: whether the owner's phone is verified, which platform numbers they can connect, and which conversations already route to which agent. Call this first whenever the user asks to talk to an agent on WhatsApp, and repeat its next_step to them.
start_owner_phone_verification
Send a 6-digit code over WhatsApp to the ACCOUNT OWNER's own phone. This is the one-time ownership proof required before a platform number can be connected, and it also unlocks agents messaging the owner. Ask the user for their own WhatsApp number first and send only to that. No WhatsApp Business account is involved.
confirm_owner_phone_verification
Confirm the 6-digit code the owner received on WhatsApp from start_owner_phone_verification. On success the owner is verified: agents can message them, and platform numbers become connectable.
attach_agent_whatsapp
Connect a platform WhatsApp number to one of the account's agents, so the owner can message that number and reach that agent. Requires the owner to be verified first. Take phone_number_id from get_agent_whatsapp. A number already used by another account is still valid to connect: it answers only this owner's verified phone.
detach_agent_whatsapp
Disconnect the owner's WhatsApp route from a platform number. Removes only this account's route; other accounts sharing the number keep theirs.