Skip to content
Official MCP RegistryListed

Valet

Part ofValetlisted on 2 directories

Get share links, publish and manage websites, artifacts and agents. No account needed.

First seen 2 Oct 2026. Evidence as of 7 Oct 2026.

29
Tools
From an anonymous probe
1
Source listings
Each with its own history
28
Recorded changes
Since first seen

Tools

ToolDescriptionBehaviour
attach_connectorAttach an organization connector to a website, app, or agent so it can call the connector's tools with the credential Valet holds. It is attach_site_connector for every kind. Attaching is a grant, and it is wider than it looks: for a website, every person who can open the page can call every tool; for an agent, the agent can. Attach only what the thing needs. A website can hold only an HTTP MCP server, which list_attachable_connectors reports; an app cannot hold a connector yet and the call says so. Attaching a connector that is already attached changes nothing and is safe to repeat. Requires connecting a Valet account.Changes data
attach_resourceAttach a resource to an app: a named set of environment variables, such as a database's connection string, that the app reads as secrets. Name the resource. When the organization has none by that name, pass a provider from list_resource_catalog and the first call creates it, returning at once with state provisioning. Call again with the same arguments, env_prefix included, until the state is attached: the call that finds the resource ready attaches it and sets its variables, restarting the app if it is running. An existing resource attaches by name alone, including one another app holds. The call is safe to repeat: one name is one resource however many times it is called, and an app can hold several under different names. Pass env_prefix when two resources would set the same variables. Read the names an attachment sets from list_resource_catalog before writing the app's code. A new database is empty, so the app creates its own tables, and its URL carries the TLS settings it needs. The app must exist, so publish it first. After the attach restarts it, get_service shows whether it is running again. Provisioning takes about a minute; call again every ten seconds. Values are never returned here. Requires connecting a Valet account.Changes data
attach_site_connectorAttach an organization connector to a website so pages served from that site can call the connector's tools. Attaching is a grant, and it is wider than it looks: every person who can open the page can call every tool the connector exposes, using the credential Valet holds for it. On a private site that is every member of the organization; on a password-protected or shared one it is everyone holding the password or the link. Valet does not narrow the connector's reach for a page, so attach only what the page needs and check the site's access mode before you do. Only an organization connector that is an HTTP MCP server — transport sse or streamable-http — can be attached; list_attachable_connectors reports exactly that set. A connector that belongs to a single agent cannot back a page. A page calls the connector by its own name, which is what list_site_connectors reports and what the page's request path carries. Attaching a connector that is already attached changes nothing and is safe to repeat. Requires connecting a Valet account.Changes data
call_site_connectorRun one tool on a connector attached to a website and return what the connector answered. It is the sampling step of building a page that calls live data: discover, attach, read the schemas, then call one tool for real before you write any page code. Call it because a schema is not a shape. list_site_connectors gives you each tool's name and argument schema, which is what your call has to satisfy; this tells you what comes back, which is what the page has to parse. Results are text to read, not JSON to assume: many servers answer in markdown tables or prose, some expose a single meta-tool taking a whole command as one string, and a server that completes the handshake can still refuse half its tools when the stored credential's scope does not cover them. One real call settles all three. This runs the tool for real, with the organization's own credential and whatever side effects the tool has. It is not a dry run and there is no preview: a tool that sends, writes, or deletes will do so. Prefer a read-only tool when you are only learning the shape, and ask the user before running anything that changes their systems. The connector must already be attached to the site — attach_site_connector does that — and must be an HTTP MCP server. A tool that answers with an error is reported as an error carrying the connector's own text, which is usually the sentence that says what to fix. Requires connecting a Valet account.Destructive
create_connectorCreate an organization connector from a Valet catalog entry. It is the step after list_catalog_connectors found the entry for the product the user named; attach_site_connector then lets a website's pages call it. It creates an entry whose credential is a secret. Pass each slot the entry asks for in secrets, as slot name to value. A slot the organization already holds as a secret needs no value here. If a required slot has neither, nothing is created and the answer names the slots still needed. A key given here passes through this conversation. That is a real cost and it is the user's call to make: if they hand you the key, use it, and say that they could instead enter it on the dashboard's Integrations page, where it goes straight to Valet. The answer names the slots that were filled and never the values in them. An entry that authorizes in a browser — OAuth, or a Composio toolkit — is not created here. The answer gives the entry's name and the Integrations page, which creates the connector and runs the authorization in one place. An entry the organization already has is reported as already there; no second connector is made. Requires connecting a Valet account.Changes data
delete_resourceDelete a resource and all of its data, such as every table and row in a database. This cannot be undone, so confirm with the user first. A resource attached to any app is refused, and the answer names those apps: detach it from each with detach_resource, then delete it. The provider removes it in the background. Deleting a resource that is already being deleted changes nothing. Requires connecting a Valet account.Destructive
delete_servicePermanently delete a website or app and stop serving it. This cannot be undone, so confirm with the user first. Pass kind to say which you mean; a name holding another kind is then refused rather than deleted. Deleting an app stops it and removes its releases and source; its resources are detached and kept, because they belong to the organization and may serve other apps, and the answer names them for delete_resource. Identify the service by name, which requires connecting a Valet account, or a website published anonymously by the site_token returned when it was published — whoever published a site can always take it down. Agents are deleted with the Valet CLI.Destructive
detach_connectorDetach a connector from a website, app, or agent, ending the grant attach_connector made. The connector itself stays in the organization. A page or agent that still calls it starts getting an error, which is the intended outcome. Detaching a connector that is not attached leaves the same absence. Requires connecting a Valet account.Destructive
detach_resourceDetach a resource from an app: remove the environment variables it set and restart the app if it is running, so a running app loses them at once. The resource itself and its data are unchanged, and other apps that hold it keep it. Detaching a resource that is not attached changes nothing. Requires connecting a Valet account.Destructive
detach_site_connectorDetach a connector from a website, so pages served from that site can no longer call it. The connector itself is left in place for the rest of the organization, and nothing else about the site changes. This is how the grant attaching made is taken back. While a connector is attached, everyone who can open the page can call every tool it exposes with the credential Valet holds, so detaching is the way to end that reach. A page that still calls the connector starts getting an error, which is the intended outcome. Requires connecting a Valet account.Destructive
get_buildFollow a build publish_app started: its state, the log it has written so far, and, once it succeeds, the release it produced, the URL that serves it, and its deploy: deploy_state and every process with the release it targets and the release it runs. Poll every ten to fifteen seconds until deploy_state is up or crashed, or the build failed; most deploys finish within five minutes. starting means a process is still booting the release. crashed means a process kept failing on it and was stopped: a web process that had a running release keeps serving it, so a working URL does not prove the new release is live, and other crashed processes are down until fixed. Its state_reason says why. When it is the app's own output, usually a start command that exited or a server not listening on $PORT, fix the code and publish again; when it names a platform or configuration failure, fix that or publish again. A failed build's log is where the reason is, usually a missing dependency. Requires connecting a Valet account.Read-only
get_connector_clientGet how a page served from a Valet site talks to the connectors attached to it. It is the pair to get_skill with design-system: consult that for the artifact's identity, this one for how it talks to its connectors. Call it before writing any page code that fetches from a connector. Returns the same-origin request contract and a paste-whole session helper that handles both sessionless and stateful connectors, plus the rules a page has to follow: handling a 403, recovering a lapsed session, and never caching a response on the caller's behalf. This needs no Valet account. It answers with static guidance about how pages work — nothing here reads an organization or a site — so an agent can call it before running any OAuth flow.Read-only
get_serviceGet one website, app, or agent by name. The result carries the fields every kind has, then a section for its kind. A website: access mode, the people it is shared with, and attached connectors. An app: each process type with its scale and current state, attached resources with their state, environment variable names, and the active release. An agent: channels, connectors, declared skills, and blueprint state. Every kind: whether a draft is open and who opened it. Fields another kind would have are absent. A shared website lists each recipient's email, as the dashboard does. A password-protected website reports that it is gated and never its visitor password. An app reports access as public and that no other mode exists. Identify it by name, which requires connecting a Valet account, or, for a website published anonymously, by the site_token that publish returned.Read-only
get_skillGet one skill by name: the organization's own when it has published one under that name, otherwise the default Valet supplies for a well-known name. Call it with governance before any work and again before any publish; that skill says what the organization expects and names the other skills to read. Call it with any name list_skills reports, or any name the governance skill tells you to read. The result says where the skill came from. source: org is the organization's own content and overrides anything Valet would have said. source: default is Valet's, returned because the organization has not written its own; for design-system it is the preset the organization selected, and reason says why a selection could not be honored when one could not. Supporting files are listed by path and read with get_skill_file. By default this requires a connected account. Pass anonymous: true only when building an explicitly anonymous site; no organization is then consulted, and only a well-known name has an answer.Read-only
get_skill_fileRead one supporting file of a skill, by the path get_skill listed. A skill's SKILL.md points at its files for the detail it does not inline: a checklist, a template, a schema, an example. Read the ones the skill tells you to; do not read every file on principle. Binary files are listed but not returned here. Requires connecting a Valet account.Read-only
get_sourceRead what is published: the files of a website, app, or agent's active release. Without path it lists them; with path it returns one file's text. Read before you change something someone else built, so your publish carries their work forward rather than replacing it with yours. Binary files are listed and not returned. Requires connecting a Valet account.Read-only
list_attachable_connectorsList the organization connectors a website can hold — the discovery step before attach_site_connector. Only connectors a page can actually call appear: HTTP MCP servers reached over the sse or streamable-http transport. Command connectors and stdio MCP servers are excluded by definition — they run inside an agent's container and no page can reach them — so a connector the organization has that is not listed here cannot back a site. Pass site to mark which connectors that site already holds; attached connectors stay listed because attaching is idempotent. Tool schemas are not included — attach the connector, then list_site_connectors reports its live tools and their schemas, which is the moment to write the page's calls. Requires connecting a Valet account.Read-only
list_catalog_connectorsList the connectors Valet curates — the catalog an organization creates a connector from. Reach for it when list_attachable_connectors returned nothing that serves the data a page needs: the organization has no connector for it yet, and this says whether Valet has an entry for the product and what setting it up would take. Each entry says how its credential arrives. An entry that takes a secret names each slot it asks for and what the slot is. An entry that authorizes in a browser, or connects through Composio, says so — a person completes those on the dashboard's Integrations page, and no answer here can stand in for that. Each entry also says whether a website's pages could call it. That is a marker, not a filter: an entry only an agent's container can run is still listed, because "Valet has your product, but no page can call it" is a real answer and reporting it as missing is not. Requires connecting a Valet account.Read-only
list_resource_catalogList the resource providers this server can provision from, such as a PostgreSQL database: each one's plans, the first being the default, and the environment variables an attachment sets. Read it before attach_resource creates a resource. Requires connecting a Valet account.Read-only
list_servicesList what the organization has published: every website, app, and agent, with its kind, URL, access mode, and when it was last published. It is the first read when the user names something and you do not know what it is, and the way to recover a name an earlier publish has scrolled out of the conversation. Pass kind to narrow to one kind. Apps are always public; the row says so. Requires connecting a Valet account.Read-only
list_site_connectorsList the connectors attached to a website, each with the tools a page served from that site can call. Read it before writing a page that calls one: the tool names and argument schemas it returns are what the page's own calls have to match, and guessing them produces a page that fails on its first click. It lists what is attached to this one site, not what the organization has available. A connector nobody attached to this site does not appear here, and attaching one is a separate, deliberate act — it hands the connector's reach to everyone who can open the page. Each connector says whether a page can call it, and whether the server keeps an MCP session the page must hold — the page runs the initialize handshake, replays the Mcp-Session-Id header, and re-initializes when the session lapses. The broker forwards the handshake and the tool calls, and always hands the page one JSON document per request, whatever framing the server chose. A connector that could not be reached reports its own error and leaves every other row intact, so one expired credential does not hide the rest. Requires connecting a Valet account.Read-only
list_skillsList every skill the organization has: the well-known names with whichever source currently answers for each, then every skill the organization wrote or installed from the catalog. Each row carries the skill's description, which is the sentence saying when it applies. The governance skill tells you to call this and read every skill whose description applies to the work at hand; this is how an organization's own standards reach you without anyone naming them. Names and descriptions only; get_skill reads content. Requires connecting a Valet account.Read-only
publish_appPublish source as an app: a process Valet builds from your files and runs behind a public URL. Use it when the work needs a server, a background process, or a database. A Procfile at the root says how to start each process type; the web type serves the app's URL and must listen on $PORT, which Valet sets. Node, Python, and Go are supported. Apply the governance skill before calling. title and description are required and a call missing either is refused: Valet writes the app's valet.yaml from them, and any valet.yaml in files is replaced. Content is text: source files, lockfiles, Procfile, configuration. Images and other binary assets are not supported on this surface. Dependencies are installed during the build from the manifest you publish: package.json, with its lockfile when you have one; requirements.txt; or go.mod, where go.sum is optional and the build completes it. Do not include installed packages. Publishing to a name that exists replaces its source with these files, so read get_source first when the app is not yours. The publish returns a build id. Poll get_build until deploy_state is up or crashed; the first deploy can take a few minutes. A build that succeeded is not yet live: its processes still have to start on the new release. On crashed, a web process that had a running release keeps serving it, so a working URL does not prove the new release is live; other crashed processes are down until fixed. Read each crashed process's state_reason: if it is the app's own output, fix the code and publish again; if it names a platform or configuration failure, fix that or publish again. The first publish creates the app, so set environment variables and attach resources after it: set_env_vars and attach_resource each restart the app with its new variables. Write the app to start without them and serve a page saying what is missing, never exiting, and give the user the URL once its resources are attached. Apps are public: anyone with the URL can reach one, and there is no private mode yet, so say so before publishing organization data. Requires connecting a Valet account.Destructive
publish_sitePublish files as a live website on the public internet, served over HTTPS. Use it when a report, essay, slide-like narrative, dashboard, marketing surface, or other static artifact reads better at a live URL than as conversation text. Honor an artifact form the user requests. Otherwise choose the artifact form and treatment from its audience, job, and material. A request for a live URL chooses delivery, not one long scrolling page. Apply the governance skill before calling: get_skill with governance says what the organization expects of a published page and names the design-system skill, which supplies identity, not structure. Follow each wherever it speaks. title and description are required on every publish, and a call missing either is refused: title names the site for a person, and description says in one sentence what it holds. A site's name becomes part of its URL, so those two are what a reader has to go on wherever the site is listed. Write them for the person who will come back to this page in a month. Content is text written here: HTML, CSS, JavaScript, Markdown, JSON, SVG. Images, PDFs, video, and other binary assets are not supported on this surface — publish those with the Valet CLI. Publishing uses a connected Valet account by default and creates a permanent, private site. Pass anonymous: true only when the user explicitly wants a temporary public site. It is public to anyone who has the link, and it may be removed 36 hours after it is created, unless it is claimed. The result carries a claim URL that moves the site into a Valet account and makes it permanent, and a site_token that updates the same site on a later call. Give that token back to revise the site instead of publishing a second copy of it; with an account, give the site's name instead.Destructive
publish_skillCreate or replace an organization skill from a SKILL.md and optional supporting files. The skill's name and description come from its frontmatter. Publishing under a well-known name, governance or design-system, replaces what Valet would otherwise supply for every agent in the organization from the next read on, so do it when the user has asked to change how the organization works, and show them the content first. Publishing under a new name adds a skill the default governance process finds through list_skills when its description applies. Destructive because it replaces the previous version's content for every reader. Repeating a call with identical content mints no new version and reports deduped. Requires connecting a Valet account.Destructive
rename_serviceRename a website or app and move it to https://<org>.valet.run/<new-name>. The old address stops serving it and its name becomes available to another site or app in the same organization. Pass kind to say which you mean; a name holding another kind is then refused rather than renamed. Agents are renamed with the Valet CLI. Requires connecting a Valet account.Destructive
set_env_varsSet environment variables on an app or agent, as name to value. A secret, the default, is encrypted and never shown again; plain configuration is readable from the dashboard. A value given here passes through this conversation, which is a real cost and the user's call: say that they could instead enter it on the dashboard, where it goes straight to Valet. Setting a name that exists replaces its value, which is why this is destructive. The process sees new values on its next start. The answer names the variables set and never their values. Requires connecting a Valet account.Destructive
set_site_accessSet who can reach a website: public serves it to anyone who has the link, private serves it only to members of the organization that owns it, and password serves it to anyone who enters a shared visitor password. Requires connecting a Valet account. Password mode takes the password as the password argument. It is a shared visitor password the owner hands to whoever should see the site, not a Valet credential, and it is at most 72 bytes.Changes data
share_siteShare a website with specific people by email, whether it is private or password-protected — sharing does not change who else can reach it. Each address is mailed a link from Valet that opens the site; the recipient needs no Valet account of their own, only the link, so anyone holding the email can open the site and forwarding it forwards access. Sharing again with an address that already has access re-sends the same link rather than creating a second one. Requires connecting a Valet account.Destructive

Change history

  1. publish_app: description changed (+"id. Poll get_build until deploy_state" +"up or crashed;" +"A build that succeeded is not yet live: its processes still have to start on the new release. On crashed, a web process that had a running release keeps serving it, so a working URL does not prove the new release is live; other crashed processes are down until fixed. Read each crashed process's state_reason: if it is the app's own output, fix the code and publish again; if it names a platform or configuration failure, fix that or publish again.")
  2. get_build: description changed (+"produced," +"it, and its deploy: deploy_state and every process with the release it targets and the release it runs." +"deploy_state is up or crashed, or")
  3. set_env_vars: tool added
  4. rename_site: tool removed
  5. rename_service: tool added
  6. publish_skill: tool added
  7. publish_site: description changed (+"Apply the governance skill before calling: get_skill with governance says what the" +"expects of a published page and names the design-system skill, which" +"each")
  8. publish_app: tool added
  9. list_skills: tool added
  10. list_sites: tool removed
  11. list_services: tool added
  12. list_resource_catalog: tool added
  13. get_source: tool added
  14. get_skill_file: tool added
  15. get_skill: tool added
  16. get_site: tool removed
  17. get_service: tool added
  18. get_design_system: tool removed
  19. get_connector_client: description changed (+"get_skill with design-system:" -"get_design_system:" -"tool")
  20. get_build: tool added
  21. detach_resource: tool added
  22. detach_connector: tool added
  23. delete_site: tool removed
  24. delete_service: tool added
  25. delete_resource: tool added
  26. attach_resource: tool added
  27. attach_connector: tool added
  28. server instructions changed (+"hosts software an organization builds for itself: websites, Procfile apps, and agents, each served at its own URL." +"create, publish, read back, and update them, and read the organization's standards for doing so. Before any work, call get_skill with governance and follow it. It says what the organization expects, in what order to work, and which other skills to read" +"when. Read it again before any publish call. An organization may have replaced it; the result says whether you are holding the organization's version or Valet's default.")
Source listings
SourceListingFirst seenLast seenVersions
Official MCP Registryio.github.valetdotdev/valet2 Oct 20267 Oct 20261