DEVELOPER API · MCP SERVER

Your website, as an API.
Ready for your AI assistant.

Read your pages, posts, media and SEO settings over REST. Stage page edits and blog drafts from your own code. Or connect Claude, ChatGPT or Cursor to your site’s MCP server and let it draft the work. A person always publishes.

  • REST with an OpenAPI spec
  • MCP server built in
  • Drafts only, people publish
Terminal
$ curl https://app.workspacecms.ai/api/v1/your-site/pages \
    -H "Authorization: Bearer wcms_live_…"

{
  "data": [{
    "slug": "services",
    "title": "Our Services",
    "status": "published"
  }, …],
  "meta": { "total": 24, "page": 1, "per_page": 50 }
}
Three ways in

One key. Your code, your tools, your AI.

  1. REST

    Read your site as data

    Pages, posts, media, redirects and SEO settings as JSON. Use it for a headless frontend, a reporting dashboard, a Zapier or Make automation, or your own app.

  2. Draft writes

    Stage edits from your own code

    With a draft key, change a page’s fields or write a blog post from a script. Edits land as unpublished changes and new posts land as drafts.

  3. MCP

    Let your AI assistant work on it

    Point Claude, ChatGPT or Cursor at your site’s MCP server. It reads your pages and drafts edits and posts, and a person on your team publishes.

REST API

Ten endpoints. No surprises.

Every path starts with /api/v1/your-site. Reads work with any key. Writes need a key with draft permission, and a read key gets a 403.

MethodPathWhat it doesKey
GET/pagesPublished pages, paginatedAny key
GET/pages/{slug}One published pageAny key
GET/postsPublished posts, newest firstAny key
GET/posts/{slug}One published postAny key
GET/assetsYour media libraryAny key
GET/seoSite SEO settingsAny key
GET/redirectsYour redirect rulesAny key
PATCH/pages/{id or slug}Stage page changes, not publishedDraft key
POST/postsCreate a new post as a draftDraft key
PATCH/posts/{id}Edit a post that is still a draftDraft key
MCP serverNew

Bring Claude, ChatGPT or Cursor. Keep the publish button.

Your site has its own MCP server. Add it to your assistant as a custom connector, paste a draft key, and ask it to rewrite your services page or draft next week’s post. It runs on your own AI account, and everything it writes waits for a person to publish.

  1. In Settings, create an API key and tick Let AI assistants draft changes.
  2. Copy your MCP server address from the Connect an AI assistant card.
  3. In your assistant, add a custom connector with that address and paste the key.

Read tools, any key

  • list_pagesEvery page, with its template and whether it has unpublished changes
  • get_pageA page as it stands in the editor, with its fields and what each one is
  • list_postsYour most recent blog posts
  • get_postOne post, including its body
  • list_mediaRecent uploads, with their public addresses

Draft tools, draft keys only

  • draft_page_changesSave changes to a page without publishing them
  • create_draft_postWrite a new blog post as a draft
  • update_draft_postEdit a post that is still a draft

A read-only key never sees the draft tools.

Quick start

Draft a page edit in one request.

Send only the fields you want to change. The response links to the page in your dashboard, where someone reviews it and clicks Publish changes.

Stage a change
curl -X PATCH https://app.workspacecms.ai/api/v1/your-site/pages/services \
  -H "Authorization: Bearer $WCMS_DRAFT_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "fields": { "hero.title": "Same-day estimates" } }'

# Saved as unpublished changes. The live page has not changed.
Guardrails

Built so a script or an AI can’t break your site.

  • Nothing goes live on its ownPage edits wait as unpublished changes. New posts wait as drafts. Publishing is a click by a person.
  • No deletesNeither the API nor an assistant can delete a page, a post or a file.
  • Web addresses stay putIt cannot change a slug, a page’s status, its template, robots settings or canonical URL.
  • Published posts are lockedOnly posts that are still drafts can be edited. Published and scheduled posts are left alone.
  • You hear about itOwners and editors get a dashboard notification when an assistant starts a draft. Not another email.
  • Turn it off anytimeRevoke a key and the connection stops. A key without draft permission can only read.
The details

Keys, limits and formats.

Included on Premium and Ultra. Need higher limits? Ask us about Enterprise. Full terms: Developer API Terms.

Authentication
Bearer API keys starting wcms_live_. Only a hash of each key is stored.
Permissions
Read, or read plus draft. Choose per key.
Keys
Up to 5 active keys per site, with an optional expiry date.
Rotation
Rotate a key and the old one keeps working for 7 days, so you can deploy without downtime.
Rate limits
600 requests a minute per key and 50,000 a day per site.
Limit headers
X-RateLimit-* on every response, and 429 with Retry-After when you go over.
Pagination
page and per_page, up to 100 per page, with total in the response.
Field selection
fields= returns only the fields you ask for.
Reads
REST reads return published content only.
CORS
Open, so you can call read endpoints from a browser app.
OpenAPI
An OpenAPI 3.1 spec for the read endpoints, plus a PDF guide, in Settings > Developer API.
Usage
A usage page in your dashboard shows the requests each key makes.
FAQ

Developer API questions,
answered.

Which plans include the Developer API?

Premium and Ultra. It covers the REST API, draft keys and the MCP server. Use is governed by our Developer API Terms.

Can the API or an AI assistant publish to my live site?

No. Writes are drafts only. Page edits are saved as unpublished changes and new posts are saved as drafts. Someone on your team reviews them in WorkspaceCMS and clicks Publish.

Which AI assistants work with it?

Any assistant that can connect to a custom MCP server with an API key, such as Claude, ChatGPT and Cursor. Copy your server address from Settings and paste a draft key as the API key or Bearer token.

Does the AI assistant cost extra?

It runs on your own AI account, so it adds nothing to your WorkspaceCMS bill and uses none of your AI credits. Each call counts toward the normal API rate limits.

Can I build a headless frontend on it?

Yes. Read your published pages, posts, media, redirects and SEO settings as JSON and render them however you like. Reads are open to browser apps, and you can trim responses with fields=.

Are there webhooks?

Not yet. Today you read on demand and stay inside the rate limits shown above.

I am not a developer. Do I need this?

No. We build and run your site for you. On Premium we also connect one system for you, such as your CRM, as part of the plan. The API is there for when you or your developer want to build on top of it.

More tools

See what else your site runs on.

Every tool lives in the same dashboard as your site. Here are the others, each with its own walkthrough.

Everything every plan includesEvery tool, shown in fullCompare plans

Built for you, open to your code

We run the site.
You build on top of it.

Premium and Ultra include the Developer API and the MCP server. We build and look after your site, and you or your developer can connect anything you like.

Want to compare plans first? see pricing