This guide shows you how to connect Claude to NextBlock CMS over an open standard, no proprietary connector required. Cortex AI turns your site into a Model Context Protocol server. Claude Code, Codex, Cursor, and VS Code can then read your database schema, draft page layouts, and update navigation from their own chat window. The ChatGPT and Gemini chat apps only connect to servers that sign in with OAuth, which /api/mcp does not offer yet. Codex, included with ChatGPT plans, works today. You pay for the AI subscription you already have, with no token markup in between.
One config block
Setup in minutes.
Paste one config entry into Claude Code, Codex, Cursor, or VS Code. The CMS settings card writes it for you.
Free to try
30 days, no credit card.
The CMS is free forever and open source. Cortex AI, which includes the MCP server, starts with a 30-day free trial.
Live Drafts
You stay in control.
Page rewrites land as Live Drafts, and new pages stay drafts unless you ask to publish. Your MCP client’s approval prompt and the token scope decide what the agent may change.
Every prompt becomes a structured database record rather than a pile of generated code. Your editors keep a visual CMS, and your developers keep a clean Next.js 16 app. Agent edits to pages, posts, and products are saved as revisions you can restore.
The Problem with Traditional AI Web Builders
Prompt builders such as Lovable, Bolt, and v0 are impressive on day one. You describe a page and get a working React app in minutes. The trouble starts on day two.
Side by side
Prototype tools versus NextBlock.
What happens after the first prompt.
| What you get | Lovable, Bolt, v0 | NextBlock |
|---|---|---|
| Day one | ✗Disposable code with no content layer. | ✓A live Next.js 16 and Supabase website with a CMS. |
| Changing a headline | ✗Another prompt or another pull request. | ✓An editor types it in a Notion-style editor. |
| Drafts and revisions | ✗Code history only. | ✓Live Drafts, revisions, and one-click restore. |
| Translations and SEO | ✗Not built in. | ✓Linked translations for every page and SEO checks as you type. |
| AI costs | ✗Platform credits, bought from the tool. | ✓Your own subscription over MCP, no markup. |
| Price | ✗A monthly plan. | ✓Free CMS. Cortex AI after a 30-day free trial. |
NextBlock takes the opposite view from the prototype tools. AI should draft the site, and people should own it. The MCP connection is how those two worlds meet.
How Cortex AI Uses Model Context Protocol (MCP)
Model Context Protocol is an open standard for giving AI agents tools. A client such as Claude Code lists the tools a server offers, calls them with typed arguments, and reads typed results back. Cortex AI ships that server inside your NextBlock install at /api/mcp.
Model Context Protocol · NextBlock Cortex AI
From prompt to production, without a redeploy.
Your AI client talks to the CMS over an open standard. Output lands as data, not as code you have to host.
Step 1 · Your AI client
Prompt
Any MCP client you already pay for.
One config entry in your client registers the server. That is the setup.
Your subscription · no token markup
Step 2 · /api/mcp
Cortex AI MCP server
Streamable HTTP · bearer token · scoped.
get_database_schemacreate_page_layoutgenerate_jsonb_layoutupdate_site_navigationquery_site_analyticssearch_stock_media6 contract tools · 50 typed tools
Step 3 · PostgreSQL
Validated JSONB blocks
Supabase · one Zod schema per block.
✓Rewrites staged as Live Drafts.
✓Editors refine in the visual CMS.
✓Revisions and SEO checks built in.
Draft or publish, with revisions
Step 4 · Next.js 16
Published page
Server Components · cache cleared on publish.
✓No rebuild, no redeploy.
✓100/100 Lighthouse defaults.
✓Same site on day two.
A website plus a CMS
Editors keep a visual CMS. Developers keep a clean Next.js 16 codebase. The agent never touches either.
The endpoint speaks Streamable HTTP. Your client posts JSON-RPC messages over a normal HTTPS request, and the server answers in the same response. There is no long-lived SSE stream to babysit and no SDK to install on the server side. The same 50 typed tools that power Cortex AI inside the editor are exposed over the wire, so the agent in your IDE and the agent in your CMS never drift apart.
Safety rule one
Page rewrites stage as Live Drafts.
generate_jsonb_layout stages a Live Draft, and create_page_layout saves new pages as drafts unless told otherwise. Other write tools can publish or edit live content, so keep your MCP client’s tool-approval prompt on for them.
Safety rule two
Every token carries a scope.
A read-only token never even sees a tool that could change data. Mutating tools are absent from its list.
Available MCP Database Tools
Six tool names form the public MCP contract. Each one forwards to a tested Cortex AI executor.
get_database_schemareadReturns every table the agent may read or change, with columns, primary keys, and read-only flags.
create_page_layoutwriteCreates a new page from a slug, a title, and validated blocks in one call. It stays a draft unless you ask to publish it.
generate_jsonb_layoutwriteTurns a prompt into a full page layout, validates each block against the NextBlock schema, and stages it as a Live Draft.
update_site_navigationwriteAdds, renames, or reorders header menu items per locale.
query_site_analyticsreadReads revenue, order counts, status breakdowns, and top products over a date range.
search_stock_mediareadFinds free stock photos with alt text and photographer credits ready for an image block.
And 44 more.
Create posts and products, translate pages, upload media, manage themes and scripts. Three resources expose the database, block, and custom block schemas. Four prompts (build-site, build-page, clone-from-url, translate-content) script the common jobs.
Step by Step: Connect Claude to NextBlock CMS in Cursor and Claude Code
The server is off by default because it is a remote write surface onto live content. Turning it on takes three steps, and the trial means the first month costs nothing.
01
Start the free trial.
Start the 30-day trial, no credit card, from the welcome screen, the dashboard checklist, or Administration → Packages. The Cortex AI setup guide comes next. After activating from Packages, click Cortex AI in the sidebar to open it.
02
Mint a token.
In the guide, choose Use my own AI app (MCP), then Enable MCP & continue. That switches the server on and mints a read + write token. For a read-only token, enough for planning and audits, untick Allow writes when you create one on the MCP server access card.
03
Copy the config.
A tab per client holds values ready to copy: Claude Code (terminal), Claude Code in VS Code, Claude Desktop, Codex, Cursor, and VS Code (Copilot).
Claude Code needs "type": "http" in the entry, or it skips the server without a warning. Cursor infers the transport from the URL and needs no type field. VS Code uses a top-level servers key and prompts for the token instead of storing it.
Starting from nothing?
Ask your coding agent to build a site with NextBlock. In Claude Code, first add the plugin that teaches it the steps: /plugin marketplace add nextblock-cms/nextblock, then /plugin install nextblock@nextblock. The agent runs npx create-nextblock@latest my-site --non-interactive, which writes .mcp.json and .cursor/mcp.json with its token. You only create your admin account and start the free 30-day Cortex AI trial in the browser. Then reopen the agent in the project folder so it loads the connection. See the agent install steps.
Localhost Configuration Without a Token
While you build, keep Trust localhost without a token checked on the MCP server access card (the default). A dev server on your machine then accepts loopback calls with no header at all. In a project scaffolded with create-nextblock, npm run dev serves port 3000. In the monorepo clone, npm run dev (it runs nx serve nextblock) serves port 4200. The local Docker stack also answers on port 3000 by default. It runs a production build, so localhost trust does not apply and every client needs a token. The agent install already writes one into .mcp.json and .cursor/mcp.json.
Add this block to .mcp.json in your project root for Claude Code.
{
"mcpServers": {
"nextblock": {
"type": "http",
"url": "http://localhost:3000/api/mcp"
}
}
}The CLI form does the same thing in one line.
claude mcp add --transport http nextblock http://localhost:3000/api/mcpDevelopment only
Localhost trust is ignored in production builds, because a proxy can spoof the host header. Production always uses a token.
Production Authentication via Bearer Tokens
In production every client sends a bearer token. Tokens start with nbmcp_, are shown once at mint time, and are stored only as SHA-256 hashes. Revoking one is a single click, and the same value can never be minted again.
Add this to .cursor/mcp.json for Cursor, or drop the same entry into .mcp.json with a type field for Claude Code.
{
"mcpServers": {
"nextblock": {
"url": "https://your-site.com/api/mcp",
"headers": { "Authorization": "Bearer nbmcp_your_token" }
}
}
}Try it
Once the client connects, ask for something concrete. Try “inspect the database schema and draft a pricing page with three tiers.” The agent reads the schema, then creates the page as a draft with create_page_layout, ready for review in your CMS.
Zero-Redeploy Production Rendering
The reason this works is where the output lands. Cortex AI writes strict JSONB block records into PostgreSQL, not source files. Each block has a Zod schema, so a bad field is rejected before it is stored.
0
Rebuilds to publish
1
Zod schema per block
100
Lighthouse by default
At request time Next.js 16 renders those records with Server Components, from a public content cache that clears the moment you publish. There is no build step between publish and live, and no HTML sanitizer tax on every render. The 100/100 Lighthouse defaults you get on an empty site are the same ones you get after the agent has drafted fifty pages.
Next step
Up in ten minutes, free for thirty days.
Deploy the free CMS to Vercel in one click, start the Cortex AI trial with no credit card, and connect Claude to NextBlock CMS today. Read how the block registry keeps all of it safe if you want the full picture.
