
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
webcake-storefront-mcp
Advanced tools
MCP server for the WebCake/StoreCake storefront builder — page CRUD, page authoring, products, orders, and more
English · Tiếng Việt
Describe a store page in plain words — your AI builds it, validates it, and publishes it to your WebCake storefront.
⭐ If this saves you an afternoon of dragging blocks around, give it a star — every star keeps a solo project alive.
"Build a page for my coffee shop — a hero with a Shop Now button, a product grid, and an order form. Save it and publish."
…and a real, editable page appears on your WebCake/StoreCake site. No dragging blocks, no learning the schema, no hand-writing JSON.
This server is the bridge between your AI assistant and your storefront. The AI never guesses what a page looks like — it asks this MCP, which knows the entire BuilderX component model, validates the result, and saves it.
You AI assistant webcake-storefront MCP WebCake / StoreCake
┌──────┐ prompt ┌────────────┐ tools ┌───────────────────────┐ API ┌──────────┐
│ idea │ ───────► │ Claude / │ ─────► │ • knows the BuilderX │ ───► │ a real │
│ │ │ Cursor / │ │ component model │ │ editable │
│ │ ◄─────── │ Windsurf │ ◄───── │ • builds + validates │ ◄─── │ page on │
└──────┘ live URL └────────────┘ result │ • saves + publishes │ │ your site│
└───────────────────────┘ └──────────┘
{ sections: [...] } page source. validate_page catches duplicate ids, broken grids, and form fields without a name before anything is saved.publish_site makes it live.| 📚 Knows the real model | Serves 130+ BuilderX component types (text, image, button, form, product grid, cart, countdown, gallery…) ported straight from the builder's own factory — the exact same shapes the editor produces. |
| ✅ Validates before saving | Structural checks (unique ids, valid grid, form fields with names, working event targets) so the page isn't broken when it lands. |
| 🛡️ Safe by default | Every write is dry-run first — preview the change, nothing touches your site until you confirm. |
| ✏️ Edits surgically | Ask for one change ("make the CTA green") and it edits only that element — every other id, style, and block stays exactly as it was. |
💡 Selling COD or online? It speaks the full commerce model too — products, variations, cart, orders, promotions, combos.
One sentence to your AI → a finished, editable storefront page:
| Just say… | |
|---|---|
| 🛒 Product page | "A one-product page for my skincare serum — gallery, price, an order form with cart." |
| 🏬 Storefront home | "A homepage — hero banner, featured product grid, a newsletter form." |
| ⚡ Flash sale | "A flash-sale page — big countdown, discounted product grid, a sticky Buy button." |
| 🎟️ Event / webinar | "A registration page — countdown, agenda, a sign-up form." |
| 💌 Invitation | "A wedding invite — names, date, a map, an RSVP form." |
| 📰 Blog / content | "A blog index with featured posts and a subscribe box." |
| 🔗 Link-in-bio | "A link-in-bio — avatar, short bio, 5 link buttons, socials." |
…then "make the CTA green" or "add a 4th feature" and it edits only that block.
🤖 Works in Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, or any MCP-capable client — and the build guide + element catalog tools need zero backend calls, so you can explore the model before pasting a token.
An MCP (Model Context Protocol) server that teaches AI agents the WebCake/StoreCake storefront builder
(BuilderX) component model and connects them to the backend. The AI produces the full { sections: [...] }
page source; build_page creates the page and saves it, and publish_site makes the whole site live.
Beyond page authoring, it exposes your real store: pages & custom code, products, orders, collections, blog articles, promotions, combos, themes, customers, and automation — ~280 tools in total.
| Method | Best for | Auth |
|---|---|---|
| npx (local) — runs on your machine | Personal daily use, full control | browser login, or a token + session |
Remote (serve) — self-host Streamable-HTTP | Teams, the claude.ai dialog, always-on | ?jwt= link / x-webcake-jwt header |
The build + catalog tools (get_build_guide, list_elements, get_element, new_section,
validate_page) work with zero config; everything that reads or writes your site needs a token + session.
Pick one. Both hand your AI tool the full storefront toolkit. No coding.
npx — runs on your machine (recommended)Zero install, always the latest version, needs Node.js 18+. One line configures your IDE:
# Interactive — pick your IDE(s) and paste your credentials
npx -y webcake-storefront-mcp install
# Non-interactive — configure every supported IDE at once
npx -y webcake-storefront-mcp install --ide all --token <token> --session <session-id>
# Remove the server from every IDE config
npx -y webcake-storefront-mcp uninstall
Targets: claude-desktop, claude-code, cursor, windsurf, vscode, or all.
Just want to run the server (configure by hand)? npx -y webcake-storefront-mcp.
npx -y webcake-storefront-mcp login
Opens the builder's connect page; click Connect and your token + session are saved locally and picked up automatically.
npx -y webcake-storefront-mcp serve --port 8787
Then point any client at http://<host>:8787/mcp?jwt=<TOKEN> (clients that support headers can send
x-webcake-jwt instead; pick the site in chat with switch_site). Server-side secrets like PEXELS_API_KEY
live on the host — handy on a VPS.
⚠️ A
?jwt=link contains your personal token — treat it like a password and use HTTPS in production.
Two values are required: WEBCAKE_TOKEN (Bearer JWT) and WEBCAKE_SESSION_ID (sent as
x-session-id). You pick the site at runtime — just ask in chat and the AI calls list_my_sites /
switch_site (your choice is saved and reused next session), so no WEBCAKE_SITE_ID is needed.
Base URLs come from a named environment — set WEBCAKE_ENV (or --env) and you never type a URL:
WEBCAKE_ENV | api | app (login) | preview |
|---|---|---|---|
local | http://localhost:24679 | http://localhost:5173 | demo.localhost:24679/<siteId> |
staging | https://api.staging.storecake.io | https://staging.webcake.io | staging2.webcake.me/<siteId> |
prod (default) | https://api.storefront.webcake.io | https://webcake.io | <site_slug>.webcake.me |
Override a preset with WEBCAKE_API_URL / WEBCAKE_APP_URL. Optional, configured server-side:
PEXELS_API_KEY (search_images). Token / session / site can also be set
in chat via update_auth and switch_site — saved to a local config file at ~/.webcake-storefront-mcp/.
F12) → Network tab → click any API request.Authorization: Bearer … → WEBCAKE_TOKEN; x-session-id: … → WEBCAKE_SESSION_ID.list_my_sites then switch_site to choose the site (remembered next time).~280 tools. The headline group builds pages; the rest read and edit your live store.
| Group | Tools | Needs |
|---|---|---|
| Build a page | get_build_guide · list_elements · get_element · new_element · new_section · new_page_skeleton · validate_page · build_page · add_section | catalog tools: nothing |
| Media & ingest | search_images (Pexels) · upload_images (CDN) · ingest_html · ingest_url (recreate a reference page) | — |
| Pages & code | list_pages · get_page_source · search_page_elements · get_page_element · update_page_element(s) · create_page · update_page · update_page_source · custom CSS/JS · page contents · global sections · publish_site | token + session |
| Commerce | products · orders · collections · promotions · combos | token + session |
| Content & store | blog articles · themes / site style · apps · customers · send_mail | token + session |
| Backend code | HTTP-function CRUD (get_http_function, edit_http_function, run_function, debug_function…) | token + session |
| Context | get_current_context · list_my_sites · switch_site · update_auth · toggle_confirm_mode | token |
Every write defaults to dry_run=true — it previews the exact change and only touches your site when you re-run with dry_run=false.
Build me a WebCake storefront page for <brand/offer>. Use the webcake-storefront MCP: call
get_build_guide,list_elements, build the sections withnew_section,validate_pageuntil zero errors, thenbuild_page(dry-run first) andpublish_site.
This is a solo, open-source project — every ⭐ genuinely keeps it moving and helps other builders find it.
Built with ❤️ for the WebCake community. Thanks for being here.
FAQs
MCP server for the WebCake/StoreCake storefront builder — page CRUD, page authoring, products, orders, and more
We found that webcake-storefront-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.