All integrations

Replit

REPLIT · DEVELOPER

Replit apps through Replit’s own remote MCP server, per user.

Connecting Replit in practice

Replit’s only documented REST API is the Enterprise Admin API at api.replit.com/v1, it is in beta, and a key can be created only by an account admin on an Enterprise account — there is no public API for creating a project or running code. Its published spec is read-mostly: twenty-two operations, of which four write, and those four set a budget or approve an access request.

Scopes that draw scrutiny

  • read:* The single read scope every GET in the spec requires. There is no narrower read scope, so a key built for usage reporting also reads members, projects, deployments and budgets.
  • write:budgets Sets or clears an account or workspace budget and reviews usage-limit increase requests, so it can raise or remove the ceiling on spend.
  • write:deployments Approves public-publishing requests, which decides whether a project becomes reachable on the open internet.
  • write:members Approves or denies member access requests, including turning a workspace viewer into a paid member seat.
  • compliance:messages:read Returns the full promptText behind retained project.message_sent audit events — the actual text people typed into Agent, which is the most sensitive data the API exposes.

Rate limits

  • No numeric limit is published. Responses carry X-RateLimit-Limit, described as the maximum requests allowed "in the most constrained applicable rate-limit window", plus X-RateLimit-Remaining and X-RateLimit-Reset, and exceeding it returns 429 rate_limited.
  • GET /usage: the requested interval cannot exceed 366 days.
  • GET /compliance/messages: the first request must supply an occurredAfter and occurredBefore window no longer than 24 hours.
  • Compliance continuation cursors expire after one hour, and window, limit and messageRef must match the original request.
  • A compliance response is capped at 8 MiB of uncompressed UTF-8 JSON; a single event that does not fit returns 422 audit_log_content_too_large rather than being truncated.

Who has to approve

Keys are created in Settings → Developer → API keys and only by an account admin on an Enterprise account — Replit states that "Workspace admins and other account members cannot access the Admin API or create its keys". The key is chosen as read-only or read and write at creation, and its prefix is rpl_.

Worth knowing

  • Pagination cursors are bound to the account and to the original query parameters, so replaying one with a different limit or filter returns invalid_request, and adding or removing breakdownBy invalidates it outright.
  • GET /audit-logs is a deprecated alias for GET /compliance/messages; keys that still hold audit-logs:read keep working, but new integrations must use compliance:messages:read.
  • Compliance events can become available after their occurredAt and Replit publishes no completion watermark, so the documented approach is polling overlapping windows and de-duplicating on eventId — completeness is not guaranteed.
  • A read issued immediately after approving a request can briefly return the request’s previous state, so an approve-then-verify loop needs a delay rather than an immediate assertion.

Checked against Replit Enterprise Admin API (2026-09-29), Replit API OpenAPI specification (2026-09-29), Replit API reference (2026-09-29), Workspace advanced settings and access requests (2026-09-29)

Acts as the person, not as itself

Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.

Credentials never touch the agent

Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.

Every call on the record

Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.

What an agent can do

Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.

replit_apps_ask_questionREAD

Ask Replit Agent a natural-language question about one of the user's Replit Apps WITHOUT changing it — how routing works, why a request fails, where a bug might be. Use this for explanation, debugging help and inspection; use replit_apps_update_app_using_prompt when the user wants the app's behaviour changed. Returns `phase` plus Agent's answer: `paused` means it answered, `busy` means Agent was already working and the question was NOT submitted, so retry later. The question is visible to the user inside their own Replit App.

apps:read
replit_apps_create_app_from_promptWRITE

Create a NEW Replit App from a natural-language description; Replit Agent builds, hosts and runs it. Additive — it leaves every existing app untouched, which is why it is not marked destructive. Returns the new app's `replId`. Describe intent in natural language only: implementation is Agent's job, not the caller's.

apps:write
replit_apps_get_publish_statusREAD

Check the progress of a publish started by replit_apps_publish_app. Publishing is asynchronous, so this is how to tell whether the app is live yet.

apps:read
replit_apps_list_appsREAD

List the user's Replit Apps, most recently updated first. START HERE: each app carries the `replId` UUID that replit_apps_ask_question, replit_apps_update_app_using_prompt, replit_apps_publish_app and replit_apps_get_publish_status all require — none of them accepts an app name, and a replId must never be guessed.

apps:read
replit_apps_publish_appWRITE

DESTRUCTIVE — publish a Replit App, making it reachable by anyone on the public internet. The exposure is OUTWARD and one-way in practice: unpublishing later does not retract what was fetched, indexed, screenshotted or archived while it was live. Confirm the user wants the app public before calling. Some app kinds still need their FIRST publish done from replit.com, and Replit says so in the result rather than failing. Poll replit_apps_get_publish_status for progress.

apps:write
replit_apps_resolve_app_by_nameREAD

Resolve one Replit App by its EXACT title and return its `replId`. Replit compares case-insensitively but exactly: substrings, prefixes and fuzzy matches do NOT resolve. If the user's wording might not be the literal title, use replit_apps_search_apps instead.

apps:read
replit_apps_search_appsREAD

Search the user's Replit Apps by keywords (ranked against app titles), or resolve one directly from its Replit URL. Use this rather than replit_apps_resolve_app_by_name when the name is approximate: resolve_app_by_name requires an exact title. Returns each app's `replId`.

apps:read
replit_apps_update_app_using_promptWRITE

DESTRUCTIVE — have Replit Agent CHANGE an existing Replit App. Agent rewrites the app's code in place and Agentic Fabriq cannot restore the previous version; Replit's own tool annotation marks this destructive too. Use replit_apps_ask_question when the user only wants to understand the app rather than change it. Describe the change in natural language only — no code, no file paths, no implementation guidance.

apps:write

Put Replit behind one governed endpoint.

Same permissions, same audit trail, whatever else you connect next.