BEARER TOKEN
TECH LOOKUP
BuiltWith MCP gives agents authenticated tech-stack lookup: profile the technologies behind any domain, watch for stack changes, and pull firmographics under the user's own key.
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
// BuiltWith tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["builtwithmcp"], toolNames: [
"builtwithmcp_list_api",
"builtwithmcp_ask_api",
"builtwithmcp_vat_api"] },
pageSize: 100,
});
const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "What is stripe.com built on, and have they changed their analytics stack lately?" }] });import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["builtwithmcp"] }, pageSize: 100,
});
const res = await openai.chat.completions.create({
model: "gpt-5",
messages: [{ role: "user", content: "What is stripe.com built on, and have they changed their analytics stack lately?" }],
tools,
});
// Execute the tool call with the user's vaulted BuiltWith credential
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["builtwithmcp"] }, pageSize: 100,
});
const msg = await anthropic.messages.create({
model: "claude-sonnet-5",
max_tokens: 1024,
messages: [{ role: "user", content: "What is stripe.com built on, and have they changed their analytics stack lately?" }],
tools,
});
// Tool call runs with the user's vaulted BuiltWith credential
await sk.tools.executeTool(msg.content, "user_123");import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";
const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["builtwithmcp"] }, pageSize: 100,
});
const agent = new Agent({
name: "builtwith_agent",
model: "gemini-2.5-pro",
instruction: "Manage BuiltWith for the signed-in user.",
tools,
});
await agent.run("What is stripe.com built on, and have they changed their analytics stack lately?");// shared token
audit → bot_service_account
// scalekit
audit → user_abc ✓Does the agent access BuiltWith as the user or as a shared key?
As the user. Each workspace member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.
Where is the BuiltWith bearer token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Tokens never appear in prompts, logs, or LLM context.
Can I limit what the agent is allowed to do in BuiltWith?
Yes. Pass a tool name filter to listScopedTools so the analytics agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches BuiltWith.
What happens when a user revokes BuiltWith access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Does the agent respect BuiltWith permissions?
Yes. Every call runs as the authorizing user. Native roles, sharing settings, and scope restrictions in BuiltWith apply to each request, and actions log to the audit chain.