Botstar for AI agents
BotStar is a chatbot platform for Messenger and websites that businesses use to design bot logic, manage CMS content, and publish updates live. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Botstar.
Check a bot's entities and attributes
Read-only lookup of a bot's CMS entities and user attributes before updating its conversation logic.
Publish a bot to live
Publish a bot's current build to live after the user confirms the changes are ready.
Require approval before deleting a CMS entity
Treat deleting a CMS entity or entity field as destructive since it removes content the bot serves to users.
31 Botstar actions, graded by risk.
Every Botstar action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
8Look things up. Allowed by default.
- botstar.get_botGet Bot
- botstar.list_botsList Bots
- botstar.get_bot_app_idGet BotStar Application IDs
- botstar.get_cms_entityGet CMS Entity
- botstar.get_entity_itemGet Entity Item
- botstar.list_cms_entitiesList CMS Entities
- botstar.list_entity_itemsList Entity Items
- botstar.list_bot_attributesList Bot Attributes
write
17Create and change things. Allow, or ask the user first.
- botstar.create_botCreate Bot
- botstar.create_cms_entityCreate CMS Entity
- botstar.update_cms_entityUpdate CMS Entity
- botstar.create_entity_itemCreate Entity Item
- botstar.update_entity_itemUpdate Entity Item
- botstar.create_bot_attributeCreate Bot Attribute
- botstar.create_entity_fieldsCreate Entity Fields
- botstar.update_bot_attributeUpdate Bot Attribute
- botstar.update_entity_fieldsUpdate Entity Fields
- botstar.create_user_attributesCreate User Attributes
- botstar.publish_botPublish Bot to Live
- botstar.livechat_bootLivechat boot
- botstar.livechat_openLivechat open
- botstar.livechat_updateLivechat update
- botstar.livechat_on_openLivechat on open
- botstar.webview_get_parameterGet BotStar Webview Parameter
destructive
6Delete, cancel or archive. Ask first, or deny outright.
- botstar.delete_cms_entityDelete CMS Entity
- botstar.delete_entity_itemDelete Entity Item
- botstar.delete_bot_attributeDelete Bot Attribute
- botstar.delete_entity_fieldsDelete Entity Fields
- botstar.livechat_closeClose BotStar Livechat Widget
- botstar.livechat_on_closeBotStar LiveChat onClose Callback
Botstar in three steps.
- 01Your users connect BotstarThey add their Botstar api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Bot” can wait for the user, and “delete CMS Entity” can be denied outright.
- 03Any agent can actYour agent calls Botstar through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('botstar', { read: 'allow', write: 'ask', // create_bot destructive: 'deny', // delete_cms_entity }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Botstar connects.
Users add their Botstar api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Botstar connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Botstar from any agent.
Botstar and Arc0, answered.
Can I use Botstar with Claude, ChatGPT or Cursor?
Yes. Connect Botstar to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Botstar actions you allow.
How do users connect Botstar?
Users add their Botstar api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Botstar actions can my agent take?
31 in total: 8 read, 17 write and 6 destructive, such as “create Bot”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Botstar?
Yes. Actions like “delete CMS Entity” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Botstar too?
Yes. The same Botstar connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Botstar into your agent.
Your users connect Botstar once, under your brand. Your agent gets 31 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan