Claude connector
Connect my-app.engineer to Claude and it gets a real Linux workspace: write code, run tests, deploy to a live URL, and read the logs when something breaks.
Last updated 2026-10-01
Connecting my-app.engineer gives Claude somewhere to actually work: a private Linux workspace on a real machine. It writes and edits files, installs dependencies, runs your tests and linters, deploys the result to a live HTTPS URL, and reads back the logs and crash reasons when something fails. The workspace persists between conversations.
What you need
A free my-app.engineer account. No payment, no API key and nothing installed locally — the workspace, the shell and the deploy target are all provided. The thinking is done by your own Claude subscription, so there is no second model bill.
Connect it
From claude.ai
Open Settings → Connectors → Add custom connector and enter:
https://my-app.engineer/mcp
Claude sends you here to sign in, then shows a permission screen listing exactly what it is asking for. Approve it and you are connected. Nothing is shared before you approve, and you can revoke it at any time from Agent Settings → Connect an Agent.
From Claude Code
Generate a key under Agent Settings → Connect an Agent, then run:
claude mcp add --transport http workspace \
https://my-app.engineer/mcp \
--header "Authorization: Bearer <your key>"
Check it worked:
curl -H "Authorization: Bearer <your key>" \
https://my-app.engineer/api/bridge/whoami
Permissions
Permissions are granted per group and chosen by you at the moment you connect. A connection that only needs to read files is never offered the deploy tools — the tools it does not hold are not listed to it, so it cannot try one and fail halfway through a task.
| Permission | What it allows | Changes things |
|---|---|---|
| Read files | Browse and read anything in your workspace | No |
| Write files | Create, edit and overwrite workspace files | Yes |
| Run commands | A shell in your workspace: installs, builds, tests | Yes |
| Read deployments | Your apps, their URLs, status, health and logs | No |
| Deploy apps | Ship, restart and stop your own apps | Yes |
| Watch builds | Follow a build and read why one stopped | No |
| Start builds | Put the platform's build agent to work | Yes |
The live tool list, with each tool's description and whether it modifies anything, is published at /api/bridge/catalog. That endpoint is the same list the server answers requests from, so it cannot describe a tool that does not exist.
What it can do
- Build and deploy. Claude writes the files, verifies they run, and deploys the folder as an app on its own HTTPS subdomain.
- Diagnose a failure. If a deployment crash-loops, Claude can read the health state and the logs of the container that died — most deploy integrations can ship code but cannot tell you why it broke.
- Run your toolchain. npm, builds, test suites, linters. Node 20 and npm are available in the workspace.
Security and isolation
- Every connection is bound to one account's workspace and cannot reach another account, a cluster node, or the Kubernetes API. That capability does not exist in the tool set.
- File paths are workspace-relative and validated; absolute paths and parent traversal are refused.
- Credentials are stored hashed. A key is shown once and never again.
- Keys expire (90 days by default) and can be revoked instantly, which immediately ends access for anything using them.
- Authorization is OAuth 2.1 with PKCE (S256). Tokens are issued for this server only and are rejected elsewhere.
Data handling
The workspace holds whatever you and Claude put in it: your source files, dependencies and build output. my-app.engineer does not train on your workspace contents. Tool calls are recorded in an audit log with the tool name, the account and the time — not file contents. Deleting your account removes the workspace and its apps. See the privacy policy and sub-processors for the full detail.
For IT administrators
The practical questions, answered directly:
- What can it reach? One workspace belonging to one account. There is no tool that reads another tenant, the host, or the cluster.
- Can it run arbitrary code? Yes, if Run commands is granted — that is the point of a workspace. It runs inside that account's isolated namespace with CPU and memory limits, not on a shared host. Withhold that permission if you do not want it.
- Can it reach our network? No. The workspace runs on my-app.engineer's infrastructure and has no route into your environment.
- How do we revoke it? Agent Settings → Connect an Agent → Revoke. It takes effect on the next request.
- What does it cost? The free tier covers the workspace. Your Claude subscription does the thinking, so there is no model spend to approve.
Troubleshooting
A tool is missing. You did not grant the permission that covers it. Tools are only offered to a connection that holds their permission; reconnect and tick it.
A deploy succeeded but the site is down. Ask Claude to check the app's health and read its logs. It will report the real reason, such as a crash loop or a start command pointing at a file that does not exist.
The connection stopped working. Keys expire after 90 days and can be revoked. Generate a new one, or reconnect from claude.ai.