Quick answer: Bubble’s official MCP beta lets Claude, Claude Code, Codex, ChatGPT and VS Code with GitHub Copilot create or edit Bubble apps through your own AI account. The server URL is https://mcp.bubble.io/mcp. For Codex, run the two commands below; for Claude Code, add the server and then authenticate through /mcp.[1][2]
Fast setup commands
Codex:
codex mcp add bubble --url https://mcp.bubble.io/mcp codex mcp login bubble
Claude Code:
claude mcp add --transport http --scope user bubble https://mcp.bubble.io/mcp
After connecting, start with a test app and ask the agent to create a savepoint before making a large change. Review the preview and issue checker yourself; Bubble MCP cannot deploy the app for you.[2]
What launched on October 6, 2026
Bubble released its official MCP server in beta on October 6, alongside Agent 2. Bubble describes the MCP as an option for experienced builders who want to work from their own agentic environment and choose their own model. It supports existing apps as well as new web and native mobile apps.[1][3]
The MCP does not use Bubble AI credits. The AI usage runs through the provider you connect, so Claude or OpenAI plan limits can still apply. Bubble’s own Agent 2 is the simpler option if you prefer a built-in experience inside the Bubble editor.[1][2]
Supported clients and the current compatibility catch
| Client | Official setup path | Important note |
|---|---|---|
| Claude | Customize → Connectors → Bubble MCP | Enable the connector in each chat |
| Claude Code | claude mcp add, then /mcp |
--scope user makes it available across projects |
| ChatGPT | Developer mode → Plugins → Create custom MCP server | Enterprise/Edu requires admin enablement |
| Codex | codex mcp add, then codex mcp login |
Browser authentication grants Bubble access |
| VS Code / GitHub Copilot | Add Bubble to .vscode/mcp.json |
Start the server from the file and sign in |
Bubble uses Client ID Metadata Documents (CIMD) for sign-in. Its documentation says Cursor and Composio do not yet support this sign-in method, so do not assume every MCP client can connect to the official server today.[2]
How to connect Bubble MCP to Codex
- Open Terminal on macOS/Linux or PowerShell/Command Prompt on Windows.
- Run
codex mcp add bubble --url https://mcp.bubble.io/mcp. - Run
codex mcp login bubble. - Complete the Bubble sign-in and permission approval in the browser window.
- Open Codex and ask it to identify the Bubble account and list the apps available to that account before requesting any edits.
The connection acts as your logged-in Bubble user. It cannot exceed your collaborator permissions or unlock features excluded from the app’s Bubble plan.[2]
How to connect Bubble MCP to Claude Code
- Run
claude mcp add --transport http --scope user bubble https://mcp.bubble.io/mcp. - Open Claude Code.
- Type
/mcp. - Select bubble, choose authentication and complete Bubble’s browser sign-in.
Use --scope user only if you want Bubble available in every Claude Code project. For a project-specific or shareable configuration, Bubble provides this .mcp.json structure instead:[2]
{
"mcpServers": {
"bubble": {
"type": "http",
"url": "https://mcp.bubble.io/mcp"
}
}
}
How to connect ChatGPT
- For a personal account, open Settings → Security and login and enable Developer mode. For Enterprise or Edu, a workspace admin must allow developer mode.
- Open Plugins, select the plus button and choose Create custom MCP server, then Create MCP app.
- Set the name to Bubble.
- Keep Server URL selected and paste
https://mcp.bubble.io/mcp. - Leave authentication set to OAuth, create the app and approve access in Bubble.
These labels reflect Bubble’s launch-day documentation and can change while the feature remains in beta.[2]
VS Code and GitHub Copilot configuration
Add the following entry to .vscode/mcp.json. If the file already contains servers, add bubble alongside them instead of replacing the existing entries.
{
"servers": {
"bubble": {
"type": "http",
"url": "https://mcp.bubble.io/mcp"
}
}
}
Click Start above the Bubble entry, then complete the Bubble sign-in when prompted.[2]
What Bubble MCP can do
The official toolset can create apps, pages, mobile views, elements, styles, workflows, expressions, data types, privacy rules, development records, API Connector calls and plugin installations. It can also inspect issues, return preview links, create test-case descriptions, batch changes, undo supported changes and create or restore savepoints.[2]
- Build: create a web or mobile app, page, reusable component or workflow.
- Edit: change elements, styles, conditionals, data structures and workflow actions.
- Debug: inspect an app, run the issue checker and create a debug-mode session.
- Use development data: create or update allowed data types in the development database.
- Integrate: configure API Connector collections and install eligible plugins.
- Recover: create a savepoint, undo supported changes or restore a savepoint.
Important limitations before you trust it
- No deployment: the MCP cannot deploy an app. Changes stay away from the live app until you deploy manually.
- No branch merging: it can work on a specified branch, but it cannot merge branches.
- No log reading: Bubble lists log access as unavailable in the current release.
- OAuth2 setup remains manual: complete it in the Bubble editor.
- Paid plugins must be purchased first: the agent cannot bypass the purchase requirement.
- Deleted records are not recoverable through undo: treat database-delete requests as high risk.
Bubble’s launch announcement and manual both identify deployment, branch merging and log reading as current gaps.[1][2]
Data access and privacy: what actually leaves Bubble
The AI tool can read and change records in the development database only for data types an admin has explicitly allowed. Bubble says live database records are read-only, not writable. Records that the MCP reads are sent to the connected AI provider, so sensitive data types should remain inaccessible unless there is a clear, reviewed need.[2]
Safe first-run checklist
- Use a test app: do not begin with a production-critical app.
- Confirm identity: ask the agent which Bubble account is connected and which apps it can see.
- Name the exact app and branch: never rely on the agent to infer the target.
- Create a savepoint: do this before any multi-step build or refactor.
- Restrict data access: allow only the development data types needed for the task.
- Start read-only: request an app outline and issue report before edits.
- Apply one bounded change: add a test page or small non-critical component.
- Review the preview: inspect the page, workflow, privacy rules and data changes manually.
- Run the issue checker: do not treat a successful tool call as proof the app works.
- Deploy manually only after review: the MCP cannot and should not make that final decision for you.
Copy-paste prompts for safer Bubble MCP work
1. Read-only audit
Use the Bubble app named [EXACT APP NAME] on branch [BRANCH]. Do not change anything. Return the app outline, pages, data types, privacy rules, plugins and current issue-checker findings. If the app or branch is ambiguous, stop and ask for confirmation.
2. Small test change with a savepoint
In the development version of [EXACT APP NAME], create a savepoint named "before-mcp-test". Then add a page named mcp-test with a heading and one disabled button. Do not edit existing pages, workflows, data types, privacy rules or records. Run the issue checker and return a preview link. Do not deploy.
3. Controlled feature build
Work only in [EXACT APP NAME] on [BRANCH]. Create a savepoint first. Implement this approved feature: [FEATURE SPEC]. Use existing styles where possible. Do not install plugins, delete records, weaken privacy rules or change unrelated workflows. After applying the change, list every page, workflow and data type changed, run the issue checker and stop for review.
4. Roll back one conversation
Undo everything you changed in this conversation. Do not undo earlier work by other collaborators. After the undo, inspect the affected nodes and report whether the prior state was restored.
Bubble notes that MCP changes do not appear in the editor’s normal undo history. Ask the agent to undo or restore a savepoint instead. Restoring a savepoint can replace all changes made since it, including manual editor changes, so confirm the scope first.[2]
Bubble Agent 2 or Bubble MCP?
| Choose Agent 2 when… | Choose Bubble MCP when… |
|---|---|
| You want the built-in Bubble editor experience | You already work in Claude, Codex, ChatGPT or Copilot |
| You prefer minimal setup | You want to choose the model and agent |
| You are comfortable using Bubble AI credits | You prefer usage billed/limited by your AI provider |
| You want preview and editing inside Bubble | You want to combine Bubble with specs or context from other connected tools |
You can use both on the same app. They produce ordinary Bubble elements, workflows and data types that remain editable in the visual editor.[2]
Frequently asked questions
What is the official Bubble MCP server URL?
https://mcp.bubble.io/mcp.[2]
Does Bubble MCP use Bubble AI credits?
No. Bubble says MCP usage runs through your connected AI provider instead, although that provider’s plan or rate limits still apply.[1]
Can Bubble MCP deploy my app?
No. Deployment remains a manual action in the Bubble editor, giving you a review gate before changes reach the live app.[2]
Can it change live database records?
No. Bubble documents development data as readable and writable, while live data is read-only. Access is also limited to data types approved by an admin.[2]
Does the official Bubble MCP work with Cursor?
Not at launch according to Bubble’s documentation, because Cursor does not yet support the CIMD sign-in method used by the official server.[2]
Can I undo MCP changes from the Bubble editor?
Not with the editor’s normal undo history. Ask the connected agent to undo its changes or restore a savepoint. Database records deleted by the agent cannot be recovered through undo.[2]
Last checked: October 6, 2026. Bubble MCP is a beta feature, so re-check the official documentation before granting access to a sensitive app.