Replit
REPLIT · DEVELOPER
Replit apps through Replit’s own remote MCP server, per user.
Connecting Replit in practice
Replit’s only documented REST API is the Enterprise Admin API at api.replit.com/v1, it is in beta, and a key can be created only by an account admin on an Enterprise account — there is no public API for creating a project or running code. Its published spec is read-mostly: twenty-two operations, of which four write, and those four set a budget or approve an access request.
Scopes that draw scrutiny
read:*The single read scope every GET in the spec requires. There is no narrower read scope, so a key built for usage reporting also reads members, projects, deployments and budgets.write:budgetsSets or clears an account or workspace budget and reviews usage-limit increase requests, so it can raise or remove the ceiling on spend.write:deploymentsApproves public-publishing requests, which decides whether a project becomes reachable on the open internet.write:membersApproves or denies member access requests, including turning a workspace viewer into a paid member seat.compliance:messages:readReturns the full promptText behind retained project.message_sent audit events — the actual text people typed into Agent, which is the most sensitive data the API exposes.
Rate limits
- No numeric limit is published. Responses carry X-RateLimit-Limit, described as the maximum requests allowed "in the most constrained applicable rate-limit window", plus X-RateLimit-Remaining and X-RateLimit-Reset, and exceeding it returns 429 rate_limited.
- GET /usage: the requested interval cannot exceed 366 days.
- GET /compliance/messages: the first request must supply an occurredAfter and occurredBefore window no longer than 24 hours.
- Compliance continuation cursors expire after one hour, and window, limit and messageRef must match the original request.
- A compliance response is capped at 8 MiB of uncompressed UTF-8 JSON; a single event that does not fit returns 422 audit_log_content_too_large rather than being truncated.
Who has to approve
Keys are created in Settings → Developer → API keys and only by an account admin on an Enterprise account — Replit states that "Workspace admins and other account members cannot access the Admin API or create its keys". The key is chosen as read-only or read and write at creation, and its prefix is rpl_.
Worth knowing
- Pagination cursors are bound to the account and to the original query parameters, so replaying one with a different limit or filter returns invalid_request, and adding or removing breakdownBy invalidates it outright.
- GET /audit-logs is a deprecated alias for GET /compliance/messages; keys that still hold audit-logs:read keep working, but new integrations must use compliance:messages:read.
- Compliance events can become available after their occurredAt and Replit publishes no completion watermark, so the documented approach is polling overlapping windows and de-duplicating on eventId — completeness is not guaranteed.
- A read issued immediately after approving a request can briefly return the request’s previous state, so an approve-then-verify loop needs a delay rather than an immediate assertion.
Checked against Replit Enterprise Admin API (2026-09-29), Replit API OpenAPI specification (2026-09-29), Replit API reference (2026-09-29), Workspace advanced settings and access requests (2026-09-29)
What an agent can do
Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.
Often connected alongside
Put Replit behind one governed endpoint.
Same permissions, same audit trail, whatever else you connect next.