Skip to content

MCP server ​

Diggama speaks the Model Context Protocol, so you can connect your project to Claude, Cursor or any other MCP client and have it read and write your content directly: no wrapper to build, no scripts to maintain.

The AI sees exactly what its connection allows, and nothing else.

https://api.diggama.com/mcp

What the AI can do ​

Once connected, the assistant can discover your content types, read records, and (if you allow it) create, update, publish and delete them.

ToolWhat it doesAbility needed
list_blueprintsList your content types and what the connection may do with eachnone (always offered)
describe_blueprintGet one type's fields, with a JSON Schema for its attributesany, on at least one type
list_resourcesList, filter, search and sort recordsview
get_resourceGet one record in fullview
create_resourceCreate a recordcreate
bulk_create_resourcesCreate up to 25 records at once, for seeding and importscreate
update_resourceUpdate a recordupdate
delete_resourcePermanently delete a recorddelete
publish_resourcePublish or schedule a recordpublish
unpublish_resourceRevert a record to draftpublish

preview also satisfies view, and publish also satisfies create, as in the REST API.

Tools you have not granted never appear. A connection with only view is offered four read tools and no way to write at all. It is not a matter of the model choosing to behave: the write tools are simply not there.

Each tool's blueprint argument is restricted to the exact content types the connection covers for that tool, so the assistant cannot even name one it has no right to. The type of content type narrows it further: a single-record type is never offered to create_resource, bulk_create_resources or delete_resource, and a read-only type (form submissions and the like) is never offered to publish_resource or unpublish_resource.

Setup ​

1. Create a connection ​

In the Diggama dashboard, open Connect to AI in the sidebar's Configuration group.

Under Access, pick a preset. It applies the same abilities to every content type in the project:

PresetAbilitiesTools offered
Read only (preselected)viewThe four read tools. Published records only, no drafts.
Read & writeview, preview, create, updateAlso create_resource, bulk_create_resources, update_resource. Sees drafts; what it writes stays a draft.
Full accessall six: view, preview, create, update, delete, publishAll ten tools, including publishing and permanent deletion.

For anything finer, click Customise per content type and tick abilities per type in the matrix. Only the six content abilities above matter to MCP; see Authentication for what each one means.

Name the connection (it defaults to "Claude") and click Create connection. The token is shown once, right after you create it: copy it now.

Presets do not cover content types created later

A preset lists the project's content types by name at the moment you create the connection. A content type added afterwards is not covered, and the assistant will not see it. Edit the connection's token (see Managing connections) or create a new connection, then reconnect the client.

2. Add the server to your client ​

The Endpoint section of the same page shows the URL and these snippets. Replace {your token} with the token you copied.

bash
claude mcp add --transport http diggama https://api.diggama.com/mcp \
  --header "Authorization: Bearer {your token}"
jsonc
// ~/.cursor/mcp.json
{
  "mcpServers": {
    "diggama": {
      "url": "https://api.diggama.com/mcp",
      "headers": { "Authorization": "Bearer {your token}" }
    }
  }
}
jsonc
// .vscode/mcp.json
{
  "inputs": [
    { "id": "diggama-token", "type": "promptString", "description": "Diggama token", "password": true }
  ],
  "servers": {
    "diggama": {
      "type": "http",
      "url": "https://api.diggama.com/mcp",
      "headers": { "Authorization": "Bearer ${input:diggama-token}" }
    }
  }
}
json
{
  "mcpServers": {
    "diggama": {
      "type": "http",
      "url": "https://api.diggama.com/mcp",
      "headers": { "Authorization": "Bearer ${DIGGAMA_TOKEN}" }
    }
  }
}

Keep your token out of version control

.mcp.json and .vscode/mcp.json are project files, usually committed. Use claude mcp add --scope user, the VS Code inputs prompt, or an environment variable (${DIGGAMA_TOKEN} above, expanded by Claude Code) so the token stays on your machine.

3. Try it ​

List the last 5 blog posts

Draft a blog post about our new pricing, and leave it unpublished

Which products are still drafts?

Claude.ai and Claude Desktop ​

Custom connectors in claude.ai and Claude Desktop require OAuth, which Diggama does not offer yet. Connections authenticate with a bearer token only.

As a workaround, Claude Desktop can reach the server through the mcp-remote bridge, which runs locally and forwards to the endpoint with your token. It needs Node.js. In claude_desktop_config.json:

json
{
  "mcpServers": {
    "diggama": {
      "command": "npx",
      "args": [
        "-y", "mcp-remote", "https://api.diggama.com/mcp",
        "--header", "Authorization: Bearer ${DIGGAMA_TOKEN}"
      ],
      "env": { "DIGGAMA_TOKEN": "{your token}" }
    }
  }
}

Restart Claude Desktop after saving. mcp-remote is a third-party package, not maintained by Diggama. There is no workaround for claude.ai on the web.

Managing connections ​

Connections. The Connect to AI page lists every connection with a plain-language summary of what it can do and when it was last used. A connection is an ordinary project token whose name starts with MCP — , so it also appears on the API Tokens page. A token created on the API Tokens page works over MCP too, but it is not listed under Connections.

Changing permissions. Edit the token's abilities on the API Tokens page. That is also how you add a content type created after the connection. Or create a new connection and revoke the old one. Either way, reconnect the client afterwards: it caches the tool list.

Recent activity. The page shows the last 20 tool calls made in the project, from any token: tool, content type, record id, connection name, client and time, each marked read, write or failed. Only tool calls are recorded, not discovery requests.

Revoking. Hover a connection and click the bin icon, or delete the token on the API Tokens page. It stops working immediately; any client using it needs a new token.

What to know before you let it write ​

Writes fire your automation. Every create, update, publish and delete runs the same workflows and webhooks a dashboard edit would. An assistant creating twenty articles sends twenty webhooks.

Deletion is permanent. There is no soft delete and no undo. Grant delete only when you mean it.

Updates merge by default. update_resource leaves omitted fields alone. There is a replace mode that blanks omitted fields, but it demands the record's current updated_at, so it cannot silently overwrite an edit someone else made while the assistant was working.

Ask for a dry run. Any create or update accepts dry_run, which validates the payload and shows the resulting record or a field-by-field diff without writing anything or running a workflow. Telling the assistant "show me the diff first" is the cheapest safety net there is.

Bad writes are refused, not dropped. A field name that does not exist on the type is an error, not silently ignored. So is a value that still carries a truncation marker from a read: writing it back would cut the field short.

Drafts stay hidden without preview. A connection without preview sees only published records, and asking for drafts returns a clear error rather than an empty list. The Read only preset has no preview.

Page builder fields are read-only. The assistant can read a page's blocks (up to 40 per field; the compiled HTML and stylesheet are left out), but it cannot write them. Those are edited in the dashboard.

No file uploads. There is no upload tool. Image and file fields accept the URL or storage path of a file that is already uploaded, so give the assistant the URL.

Slash commands ​

Clients that support MCP prompts show these as slash commands. Each appears only if the connection could carry it out.

Appears when the connection has
Audit contentMissing required fields, empty title fields, stale drafts. Read-only.access to any content type
Draft a recordDrafts from a brief, showing the fields and a dry run before writing.create on a type
Translate a recordCopies a record into another language variant.update on a multilingual type
Plan a bulk editTurns "change X everywhere" into a reviewed plan, then applies it one record at a time.update on a type

Clients that support completion suggest content-type slugs as you type the blueprint argument.

Transport and limits ​

  • Streamable HTTP, stateless: every message is a POST. GET and DELETE answer 405: there is no server-sent event stream and no session.
  • One JSON-RPC message per request; batching is not supported.
  • Authentication is the project token as Authorization: Bearer. No OAuth.
  • Requests from a browser page are refused unless they come from claude.ai or claude.com. Desktop and CLI clients send no Origin and are unaffected.
  • Lists return 25 records per page by default, at most 50 (10 with detail: "full"). Long text is shortened in lists; get_resource returns each value whole up to 20,000 characters.
  • Only creating has a bulk tool, capped at 25 and all-or-nothing. There is no bulk update, delete or publish, and no export: ask the assistant to loop over single records instead, so each change is visible and reversible one at a time.
  • Writes are capped at 60 a minute per project, shared by every connection and token, dry runs included. Reads go through the shared API limit of 1,000 requests a minute per project.
  • MCP requests count towards your plan's API usage, like any other request.

The full argument-by-argument contract is in the tool reference.

If the tool list looks wrong ​

The catalogue is computed from the token on every request, but clients cache it and the server cannot push an update. Reconnect the client after changing a connection's permissions or adding a content type.

Diggama Documentation