For programs
Brand guidelines as code, not as a PDF.
If you build a website, you do not need page 14 of a style guide, you need variables. nexbrand puts out every version as code, an API reads it for programs, and an AI tool in your editor fetches it over MCP instead of inventing colours.
As code
“As code” on every client and every project opens the version shown in four formats, to copy or download:
- CSS variables under
:root - Tailwind 4 as
@theme - SCSS with
$variables - Design tokens (JSON) after the W3C draft, with Pantone as an extension
They hold every colour, its steps from 50 to 950 (except for neutrals), the fonts with their fallback, every type size in rem with line height and weight, and the dark mode mapping. The interface, public pages, the API and MCP return the same text, character for character.
/* Morgenrot Bakery 2026 */
:root {
--color-oven-red: #A12E26;
--color-honey: #E8A33D;
--color-flour: #F4E8CF;
/* … */
--color-oven-red-50: #FBF4F4;
--color-oven-red-500: #D24B41;
--color-oven-red-950: #311412;
/* … */
--font-headings: 'Fraunces', serif;
--font-body-text: 'Inter', sans-serif;
--font-price-tags: 'Morgenrot Hand', cursive;
--text-h1: 3rem;
--text-h1--line-height: 1.1;
--text-h1--font-weight: 700;
/* … */
/* Dark mode: which colour is what. Map them onto your own variables. */
--dark-ground: var(--color-night);
--dark-primary: var(--color-honey);
}One token per connection
Programs sign in with a token, never with a password. The operator allows tokens, then every account creates its own under My account, Connections:
- Clients: every client you may see, later ones too, or only chosen ones.
- What the token may do: “Read only” or “Read and propose drafts”.
- Expires: in 30 days, in 90 days, in a year or never.
A token sees only what its account may see, and withdrawn rights apply at once. It is shown exactly once; nexbrand stores only a checksum. The operator sees every token without knowing it and can block any of them.
The API under /api/v1
What is under /api/v1 stays: new fields may come, but nothing is renamed or removed. Clients, versions and projects can be addressed by name or by id.
| Request | What | Level |
|---|---|---|
GET /api/v1/me | Who the token is and what it may do | read |
GET /api/v1/clients | Clients with the current version and main colours | read |
GET /api/v1/clients/{client} | The whole set with files and checks; with ?at= as on a given day, with ?version= or ?project= | read |
GET /api/v1/clients/{client}/versions | Every version with its valid-from date | read |
GET /api/v1/clients/{client}/code | The set as css, tailwind, scss or json | read |
POST /api/v1/clients/{client}/audit | Check colour values or a style sheet against the guidelines | read |
POST /api/v1/clients/{client}/drafts | Write a redesign back as a draft | draft |
GET /api/v1/contrast | Contrast of two colours, with colour vision and the nearest colour that passes | read |
GET /api/v1/files/{id} | A logo, a free font or an example | read |
curl -H "Authorization: Bearer nxb_…" \
"https://brand.example.com/api/v1/clients/Harbour%20Bakery/code?format=tailwind&at=2023-05-01"Pavo saysThe API is meant for programs, not browsers: nexbrand turns down a request with an Origin header. Programs such as nexdeck or n8n read with a token as a header.
Checking code against the guidelines
Send up to 500 colour values or a whole style sheet to audit, and nexbrand says for each colour: the same, nearly the same as the colour the guidelines mean, foreign or unreadable. It understands HEX, rgb() and hsl(), and resolves variables within the style sheet.
For a style sheet nexbrand also checks every rule that sets both text colour and background against the forbidden pairs of the guidelines and against 4.5:1. That is kept simple on purpose: it means pairs within one rule, it does not see inheritance in the document.
MCP for AI tools in your editor
Under /api/mcp nexbrand speaks the Model Context Protocol. An AI tool in your editor receives the instruction to fetch the guidelines before building and never to invent colour values.
| Tool | What | Level |
|---|---|---|
list_clients | Clients with the current version and main colours | read |
get_brand | The whole set of a client or project, also as on a given day | read |
get_code | The set as CSS, Tailwind, SCSS or JSON | read |
list_versions | Every version, then the drafts | read |
compare_versions | The difference between two versions | read |
check_contrast | Contrast of two colours | read |
audit | Colour values and CSS against the guidelines | read |
propose_version | Write a redesign back as a draft | draft |
{
"mcpServers": {
"nexbrand": {
"type": "http",
"url": "https://brand.example.com/api/mcp",
"headers": { "Authorization": "Bearer nxb_…" }
}
}
}To a token of the level “Read only”, nexbrand does not even show propose_version. With “Read and propose drafts” the tool writes a redesign back as a draft, with the origin “over MCP” and the token's name as author. It cannot publish; that stays with a person in the app.
The same holds for every way in: at most 600 requests per minute and token, the same rights as in the interface, and an in-house font never comes out as a file.