Botstar for AI agents

BotStar is a chatbot platform for Messenger and websites that businesses use to design bot logic, manage CMS content, and publish updates live. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

AI and modelsAPI keyMCP + RESTbotstar.com
AUDIT LOG · BOTSTARPOLICY: acme-support
09:41:07 · claude · u_8f2read
botstar.list_bots
List Bots✓ allowed · 212ms
09:41:08 · claude · u_8f2read
botstar.get_bot
Get Bot✓ allowed · 164ms
09:41:09 · claude · u_8f2write
botstar.create_bot
Create Bot✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
botstar.delete_cms_entity
Delete CMS Entity✕ blocked · policy: deny
EVERY BOTSTAR CALL, ON THE RECORD
01 · USE CASES

What agents do in Botstar.

01

Check a bot's entities and attributes

Read-only lookup of a bot's CMS entities and user attributes before updating its conversation logic.

02

Publish a bot to live

Publish a bot's current build to live after the user confirms the changes are ready.

03

Require approval before deleting a CMS entity

Treat deleting a CMS entity or entity field as destructive since it removes content the bot serves to users.

02 · ACTIONS

31 Botstar actions, graded by risk.

Every Botstar action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

8

Look things up. Allowed by default.

  • botstar.get_bot
    Get Bot
  • botstar.list_bots
    List Bots
  • botstar.get_bot_app_id
    Get BotStar Application IDs
  • botstar.get_cms_entity
    Get CMS Entity
  • botstar.get_entity_item
    Get Entity Item
  • botstar.list_cms_entities
    List CMS Entities
  • botstar.list_entity_items
    List Entity Items
  • botstar.list_bot_attributes
    List Bot Attributes

write

17

Create and change things. Allow, or ask the user first.

  • botstar.create_bot
    Create Bot
  • botstar.create_cms_entity
    Create CMS Entity
  • botstar.update_cms_entity
    Update CMS Entity
  • botstar.create_entity_item
    Create Entity Item
  • botstar.update_entity_item
    Update Entity Item
  • botstar.create_bot_attribute
    Create Bot Attribute
  • botstar.create_entity_fields
    Create Entity Fields
  • botstar.update_bot_attribute
    Update Bot Attribute
  • botstar.update_entity_fields
    Update Entity Fields
  • botstar.create_user_attributes
    Create User Attributes
  • botstar.publish_bot
    Publish Bot to Live
  • botstar.livechat_boot
    Livechat boot
  • botstar.livechat_open
    Livechat open
  • botstar.livechat_update
    Livechat update
  • botstar.livechat_on_open
    Livechat on open
  • botstar.webview_get_parameter
    Get BotStar Webview Parameter
+ 1 MORE

destructive

6

Delete, cancel or archive. Ask first, or deny outright.

  • botstar.delete_cms_entity
    Delete CMS Entity
  • botstar.delete_entity_item
    Delete Entity Item
  • botstar.delete_bot_attribute
    Delete Bot Attribute
  • botstar.delete_entity_fields
    Delete Entity Fields
  • botstar.livechat_close
    Close BotStar Livechat Widget
  • botstar.livechat_on_close
    BotStar LiveChat onClose Callback
03 · HOW IT WORKS

Botstar in three steps.

  1. 01Your users connect BotstarThey add their Botstar api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Bot” can wait for the user, and “delete CMS Entity” can be denied outright.
  3. 03Any agent can actYour agent calls Botstar through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('botstar', {
  read: 'allow',
  write: 'ask',        // create_bot
  destructive: 'deny',  // delete_cms_entity
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Botstar connects.

Users add their Botstar api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Botstar connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Botstar from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Botstar and Arc0, answered.

Q01

Can I use Botstar with Claude, ChatGPT or Cursor?

Yes. Connect Botstar to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Botstar actions you allow.

Q02

How do users connect Botstar?

Users add their Botstar api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Botstar actions can my agent take?

31 in total: 8 read, 17 write and 6 destructive, such as “create Bot”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Botstar?

Yes. Actions like “delete CMS Entity” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Botstar too?

Yes. The same Botstar connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Botstar into your agent.

Your users connect Botstar once, under your brand. Your agent gets 31 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan