For developers · Chapter 25
MCP
When an AI assistant in an editor builds a page for a client, it likes to guess colours. Over MCP, the Model Context Protocol, it asks nexbrand instead and builds with the real values.
Setting it up
MCP uses the same tokens as the API. Create a token under My account, Connections, and enter nexbrand in your editor's MCP settings:
{"mcpServers": {"nexbrand": {
"type": "http",
"url": "https://brand.example.com/api/mcp",
"headers": {"Authorization": "Bearer nxb_…"}
}}}nexbrand speaks MCP under /api/mcp as Streamable HTTP without streams: every request gets its answer as JSON, there is no session, and every request carries the token.
Eight tools
| Tool | What it does |
|---|---|
list_clients | the clients with their current version, main colours and projects |
get_brand | a client's CI: colours, fonts, logos with file addresses, sizes, rules, checks; for a version, a day or a project too |
get_code | the CI as CSS, Tailwind, SCSS or design tokens |
list_versions | every version with the day it applies from |
compare_versions | what changed between two versions, as in the comparison |
check_contrast | contrast of a text colour on a ground, with grades and the nearest passing colour |
audit | colour values and CSS against the CI |
propose_version | writes a redesign back as a draft, with a name and a note |
Only a token of the level Read and propose drafts sees propose_version. For a token that only reads, the tool does not exist at all.
What the AI is told
nexbrand gives the assistant a short instruction: call get_brand before building, never invent colour values, propose a redesign with propose_version. Such a draft appears in nexbrand with the origin over MCP and the token's name as author. A person publishes it, or throws it away.
The same safeguards as the API
MCP follows the same rules as /api/v1: the operator's switch, the token, 600 requests a minute, no requests from web pages, and the same rights as in the interface. A token sees no more over MCP than through the API.
Pavo saysA token for the editor usually only needs to read. Give the level for writing back only when the AI really should propose drafts.