AppDrag for AI agents

AppDrag is a cloud platform for building websites, APIs, and databases with drag-and-drop tools and code editing, used by developers and small teams to ship apps with built-in hosting. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsAPI keyMCP + RESTappdrag.com
AUDIT LOG · APPDRAGPOLICY: acme-support
09:41:09 · claude · u_8f2write
appdrag.visual_sql_select
Visual SQL SELECT✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
appdrag.visual_sql_delete
Visual SQL Delete✕ blocked · policy: deny
EVERY APPDRAG CALL, ON THE RECORD
01 · USE CASES

What agents do in AppDrag.

01

Run a SQL query against a database

Run a visual SQL select query to pull records for a report.

02

Call a production backend function

Execute a function in the production environment to retrieve or process data.

03

Confirm before a SQL update or delete

Writing or deleting data with visual SQL should be confirmed before it runs.

02 · ACTIONS

11 AppDrag actions, graded by risk.

Every AppDrag action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

0

Look things up. Allowed by default.

  • No read actions.

write

8

Create and change things. Allow, or ask the user first.

  • appdrag.visual_sql_select
    Visual SQL SELECT
  • appdrag.visual_sql_update
    Visual SQL Update
  • appdrag.execute_function_get_prod
    Execute PROD API Function (GET)
  • appdrag.execute_function_patch_dev
    Execute Dev Function (PATCH)
  • appdrag.execute_function_put_default
    Execute Cloud Backend function via PUT (default)
  • appdrag.execute_function_put_preprod
    Execute Cloud Backend function via PUT (preprod)
  • appdrag.execute_function_post_default
    Execute Cloud Backend function via POST
  • appdrag.execute_function_post_preprod
    Execute Function POST (Preprod Env)

destructive

3

Delete, cancel or archive. Ask first, or deny outright.

  • appdrag.visual_sql_delete
    Visual SQL Delete
  • appdrag.execute_function_delete_default
    Execute Cloud Backend function via DELETE
  • appdrag.execute_function_delete_preprod
    Execute Preprod Function (DELETE)
03 · HOW IT WORKS

AppDrag in three steps.

  1. 01Your users connect AppDragThey add their AppDrag api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “visual SQL SELECT” can wait for the user, and “visual SQL Delete” can be denied outright.
  3. 03Any agent can actYour agent calls AppDrag through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('appdrag', {
  read: 'allow',
  write: 'ask',        // visual_sql_select
  destructive: 'deny',  // visual_sql_delete
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How AppDrag connects.

Users add their AppDrag api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same AppDrag connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use AppDrag from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

AppDrag and Arc0, answered.

Q01

Can I use AppDrag with Claude, ChatGPT or Cursor?

Yes. Connect AppDrag to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the AppDrag actions you allow.

Q02

How do users connect AppDrag?

Users add their AppDrag api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which AppDrag actions can my agent take?

11 in total: 0 read, 8 write and 3 destructive, such as “visual SQL SELECT”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in AppDrag?

Yes. Actions like “visual SQL Delete” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call AppDrag too?

Yes. The same AppDrag connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug AppDrag into your agent.

Your users connect AppDrag once, under your brand. Your agent gets 11 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan