Builder.io for AI agents

Builder.io is a visual platform for managing website content, models, and assets, letting marketing and product teams update pages without waiting on a developer. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Website buildersAPI keyMCP + RESTbuilder.io
AUDIT LOG · BUILDER.IOPOLICY: acme-support
09:41:07 · claude · u_8f2read
builder_io.list_assets
List Assets✓ allowed · 212ms
09:41:08 · claude · u_8f2read
builder_io.list_models
List Models✓ allowed · 164ms
09:41:09 · claude · u_8f2write
builder_io.create_content_entry
Create Content Entry✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
builder_io.delete_content_entry
Delete Content Entry✕ blocked · policy: deny
EVERY BUILDER.IO CALL, ON THE RECORD
01 · USE CASES

What agents do in Builder.io.

01

Create a content entry

Add a new content entry to a model, such as a landing page section or blog draft.

02

Check what's currently live

Fetch a content entry to see what's published before changing anything on top of it.

03

Confirm before deleting an entry

Confirm before deleting a content entry, since anything referencing it on a live page would break.

02 · ACTIONS

10 Builder.io actions, graded by risk.

Every Builder.io action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

7

Look things up. Allowed by default.

  • builder_io.list_assets
    List Assets
  • builder_io.list_models
    List Models
  • builder_io.list_space_users
    List Space Users
  • builder_io.get_content_entry
    Get Content Entry
  • builder_io.get_space_details
    Get Space Details
  • builder_io.list_content_entries
    List Content Entries
  • builder_io.list_content_folders
    List Content Folders

write

2

Create and change things. Allow, or ask the user first.

  • builder_io.create_content_entry
    Create Content Entry
  • builder_io.update_content_entry
    Update Content Entry

destructive

1

Delete, cancel or archive. Ask first, or deny outright.

  • builder_io.delete_content_entry
    Delete Content Entry
03 · HOW IT WORKS

Builder.io in three steps.

  1. 01Your users connect Builder.ioThey add their Builder.io api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Content Entry” can wait for the user, and “delete Content Entry” can be denied outright.
  3. 03Any agent can actYour agent calls Builder.io through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('builder_io', {
  read: 'allow',
  write: 'ask',        // create_content_entry
  destructive: 'deny',  // delete_content_entry
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Builder.io connects.

Users add their Builder.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Builder.io connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Builder.io from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Builder.io and Arc0, answered.

Q01

Can I use Builder.io with Claude, ChatGPT or Cursor?

Yes. Connect Builder.io to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Builder.io actions you allow.

Q02

How do users connect Builder.io?

Users add their Builder.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Builder.io actions can my agent take?

10 in total: 7 read, 2 write and 1 destructive, such as “create Content Entry”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Builder.io?

Yes. Actions like “delete Content Entry” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Builder.io too?

Yes. The same Builder.io connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Builder.io into your agent.

Your users connect Builder.io once, under your brand. Your agent gets 10 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan