Botpress for AI agents
Botpress is an open-source chatbot platform that developers use to build, deploy, and monitor bots, tracking usage and conversations across workspaces. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Botpress.
Check workspace usage
Read-only lookup of workspace usage broken down by bot before deciding to scale or archive one.
Review a bot's conversations
Pull recent conversations and action runs for a bot to check how it is performing.
Require approval before deleting a workspace
Treat deleting an admin workspace or knowledge base as destructive since it removes a bot's entire setup.
53 Botpress actions, graded by risk.
Every Botpress action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
34Look things up. Allowed by default.
- botpress.get_accountGet Account
- botpress.list_pluginsList Plugins
- botpress.get_table_rowGet Table Row
- botpress.get_workspaceGet Workspace
- botpress.list_file_tagsLIST_FILE_TAGS
- botpress.get_integrationGet Integration
- botpress.list_bot_issuesLIST_BOT_ISSUES
- botpress.list_workspacesLIST_WORKSPACES
- botpress.list_action_runsLIST_ACTION_RUNS
- botpress.get_public_pluginGet Public Plugin
- botpress.list_integrationsList Integrations
- botpress.list_conversationsLIST_CONVERSATIONS
- botpress.list_usage_historyLIST_USAGE_HISTORY
- botpress.get_workspace_quotaGet Workspace Quota
- botpress.list_public_pluginsLIST_PUBLIC_PLUGINS
- botpress.get_public_interfaceGet Public Interface
write
15Create and change things. Allow, or ask the user first.
- botpress.create_botBOTPRESS_CREATE_BOT
- botpress.send_messageBOTPRESS_SEND_MESSAGE
- botpress.update_accountUpdate Account
- botpress.update_workflowBOTPRESS_UPDATE_WORKFLOW
- botpress.update_admin_botsBOTPRESS_UPDATE_ADMIN_BOTS
- botpress.create_conversationBOTPRESS_CREATE_CONVERSATION
- botpress.create_admin_workspaceBOTPRESS_CREATE_ADMIN_WORKSPACE
- botpress.update_admin_workspaceUPDATE_ADMIN_WORKSPACE
- botpress.create_admin_integrationBOTPRESS_CREATE_ADMIN_INTEGRATION
- botpress.run_vrlBOTPRESS_RUN_VRL
- botpress.set_account_preferenceSet Account Preference
- botpress.set_workspace_preferenceSet Workspace Preference
- botpress.charge_workspace_unpaid_invoicesBOTPRESS_CHARGE_WORKSPACE_UNPAID_INVOICES
- botpress.request_integration_verificationRequest Integration Verification
- botpress.break_down_workspace_usage_by_botBreak Down Workspace Usage By Bot
destructive
4Delete, cancel or archive. Ask first, or deny outright.
- botpress.delete_fileDelete File
- botpress.delete_knowledge_baseDelete Knowledge Base
- botpress.delete_admin_workspaceDelete Admin Workspace
- botpress.delete_integration_shareable_idDelete Integration Shareable ID
Botpress in three steps.
- 01Your users connect BotpressThey add their Botpress api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “bOTPRESS_CREATE_BOT” can wait for the user, and “delete File” can be denied outright.
- 03Any agent can actYour agent calls Botpress through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('botpress', { read: 'allow', write: 'ask', // create_bot destructive: 'deny', // delete_file }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Botpress connects.
Users add their Botpress api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Botpress connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Botpress from any agent.
Botpress and Arc0, answered.
Can I use Botpress with Claude, ChatGPT or Cursor?
Yes. Connect Botpress to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Botpress actions you allow.
How do users connect Botpress?
Users add their Botpress api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Botpress actions can my agent take?
53 in total: 34 read, 15 write and 4 destructive, such as “bOTPRESS_CREATE_BOT”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Botpress?
Yes. Actions like “delete File” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Botpress too?
Yes. The same Botpress connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Botpress into your agent.
Your users connect Botpress once, under your brand. Your agent gets 53 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan