Butterbase

Live

BEARER TOKEN

DEVELOPER TOOLS

Developer Tools

Butterbase gives agents authenticated access to developer tools for a full backend: apps, tables, key-value storage, functions, frontend deploys, and AI agents, each call on the user's own access token.

  • Per-user credentials: each call uses the actual user's access token, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
Butterbase
agent · Acme Q3
Run
List my Butterbase apps and show the latest frontend deploy for the first one.
S
butterbase_apps_list
110ms
Butterbase agent
3 apps found. The first app, storefront-api, deployed its frontend 2 hours ago and the deploy finished cleanly.
Sources: 3 apps, 1 deployment
butterbase
3 apps
18:29
Message Claude...

Tools your developer tools agent reaches for on Butterbase, scoped per user.

CALL ANY TOOL
Run a developer tools backend end to end: apps, schema and table rows, key-value storage, functions, frontend deploys, RAG collections, and agents.
butterbase_agent_create
Create agent
Create a new agent in a Butterbase app from a tool-calling graph specification. Returns the created agent's name, model, visibility, and creation timestamp; Butterbase's docs don't publish the full response shape. Use butterbase_agent_create to define a brand-new agent. Use butterbase_agent_validate first to check a graph_spec before saving it, and butterbase_agent_update to change an agent afterward.
Parameters
Name
Type
Required
Description
app_id
string
Required
The Butterbase app's unique ID to create the agent in.
default_model
string
Required
The model this agent's llm nodes use by default, in Butterbase's provider/model id format (e.g. anthropic/claude-haiku-4-5). Individual llm nodes in graph_spec can override this per node.
graph_spec
object
Required
The agent's tool-calling graph specification. FULLY CONFIRMED live via butterbase_agent_validate and an end-to-end agent run (Butterbase's docs previously described a different, incorrect shape). The object requires: spec_version (string, e.g. "1"), entry (the starting node id), nodes (an OBJECT keyed by node id: each llm node needs type:"llm", model, system_prompt, input_template, and output_key (the state key its output is written to); each end node needs type:"end" and output_template), edges (a top-level ARRAY of {"from": "<node_id>", "to": "<node_id>"} objects connecting the nodes: node linking is NOT a per-node field), tools (object: {"builtin": [], "mcp_servers": [], "functions": []}), and limits (object with 5 required numeric fields: max_steps, max_tool_calls, max_parallel_tools, timeout_seconds, human_timeout_seconds). Node prompts and templates can reference shared run state via {{ state.key }} templating. Example (validated live, ran to completion): {"spec_version": "1", "entry": "start", "nodes": {"start": {"type": "llm", "model": "anthropic/claude-haiku-4-5", "system_prompt": "You are a helpful assistant.", "input_template": "{{ state.user_question }}", "output_key": "answer"}, "done": {"type": "end", "output_template": "{{ state.answer }}"}}, "edges": [{"from": "start", "to": "done"}], "tools": {"builtin": [], "mcp_servers": [], "functions": []}, "limits": {"max_steps": 10, "max_tool_calls": 10, "max_parallel_tools": 1, "timeout_seconds": 60, "human_timeout_seconds": 3600}} ADDITIONAL CONFIRMED FACTS (from a dedicated live investigation): graph_spec.nodes[id].type actually has THREE valid values, not two -- "llm", "tool", and "end" (confirmed via agent_validate's own invalid_union_discriminator error). A "tool" node calls exactly one tool deterministically as its own graph step (distinct from an "llm" node, where the model decides whether/when to call from its available tools list); it needs {"type": "tool", "tool_ref": <tool reference, see below>, "args_template": <object, may use {{ state.* }} templating>, "output_key": "<string>"}. Separately: an "llm" node's per-node "tools" array entries, and a "tool" node's "tool_ref", are NOT plain strings -- they are a discriminated union keyed by "source": {"source": "builtin", "name": "<string>"} for a builtin tool (confirmed real names: delete_row, update_row -- validate does not check tool-name existence, only the runtime does, failing fast with a clean "unknown builtin tool" error if wrong), {"source": "mcp", "server_id": "<string>", "name": "<string>"} for an MCP tool, or {"source": "function", "name": "<string>"} for a Butterbase function. This is a completely separate shape from the top-level graph_spec.tools.{builtin, mcp_servers, functions} registration object, which remains flat string arrays as originally documented -- that object registers what the agent may use overall, while each node's own tools/tool_ref field is where a specific tool is actually referenced and invoked. Confirmed end-to-end: a "tool" node targeting {"source": "builtin", "name": "delete_row"} successfully deleted a real row and produced a full run_start -> node_start -> tool_call_start -> tool_call_end -> node_end -> run_end event trace.
name
string
Required
A unique, URL-safe name for the agent within this app. Used as the {name} path segment in every other agent and run endpoint, so pick something stable.
safety_acknowledged
boolean
Required
Confirms you've reviewed this agent's graph_spec for tool calls that can take real-world action (e.g. sending email, modifying data) and accept the associated risk. Butterbase requires this to be true before it will create the agent.
visibility
string
Required
Whether this agent can be run anonymously through its /public/agents/{name}/runs endpoint (public), only via authenticated calls made with your platform API key (private), or only by a signed-in end-user session (authenticated) -- CONFIRMED via live testing as a valid, accepted third value not previously documented here. One of: `public`, `private`, `authenticated`.
daily_budget_usd
number
Optional
Caps this agent's total spend per day in US dollars; Butterbase stops starting new runs once the cap is hit for the day. Omit for no daily budget cap.
description
string
Optional
A free-text description of what the agent does, for your own reference; not shown to end users.
display_name
string
Optional
A human-friendly label for the agent shown in the Butterbase dashboard. Falls back to name if omitted.
max_concurrent_runs
integer
Optional
Caps how many runs of this agent can be in progress at the same time across all users. Omit for no concurrency limit.
max_runs_per_user_per_hour
integer
Optional
Caps how many runs a single end user can start against this agent per hour, for authenticated per-user rate limiting. Omit for no per-user limit.
butterbase_agent_delete
Delete agent
butterbase_agent_get
Get agent
butterbase_agent_run_cancel
Cancel agent run
butterbase_agent_run_events_list
List agent run events
butterbase_agent_run_resume
Resume agent run
butterbase_agent_update
Update agent
butterbase_agent_validate
Validate agent
butterbase_auth_verify_email
Auth verify email
butterbase_billing_order_get
Get billing order
butterbase_billing_orders_list
List billing orders
butterbase_billing_product_create
Create billing product
butterbase_billing_product_update
Update billing product
butterbase_frontend_deployment_start
Start frontend deployment
butterbase_frontend_deployment_sync
Sync frontend deployment
butterbase_integration_configure_delete
Delete integration configure
butterbase_integration_connections_list
List integration connections
butterbase_integration_tool_execute
Execute integration tool
butterbase_kv_decr
Kv decr
butterbase_kv_expose_rule_set
Set kv expose rule
butterbase_kv_ttl_get
Get kv ttl
butterbase_meeting_bot_create
Create meeting bot
butterbase_meeting_bot_stop
Stop meeting bot
butterbase_people_search_company
People search company
butterbase_public_models_list
List public models
butterbase_rag_document_delete
Delete rag document
butterbase_rag_query
Query rag
butterbase_repo_blobs_batch_presign
Repo blobs batch presign
butterbase_repo_snapshot_latest_get
Get repo snapshot latest
butterbase_substrate_attention_rule_firings_list
List substrate attention rule firings

For more tools, view docs.

Build your Agent
Same auth pattern across LangChain, OpenAI, Anthropic, and Google ADK.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Butterbase tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["butterbase"], toolNames: [
    "butterbase_apps_list",
    "butterbase_table_rows_list",
    "butterbase_function_deploy"] },
  pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "List my Butterbase apps and the last 5 function deploys" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["butterbase"] }, pageSize: 100,
});

const res = await openai.chat.completions.create({
  model: "gpt-5",
  messages: [{ role: "user", content: "List my Butterbase apps and the last 5 function deploys" }],
  tools,
});

// Execute the tool call with the user's vaulted butterbase credential
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["butterbase"] }, pageSize: 100,
});

const msg = await anthropic.messages.create({
  model: "claude-sonnet-5",
  max_tokens: 1024,
  messages: [{ role: "user", content: "List my Butterbase apps and the last 5 function deploys" }],
  tools,
});

// Tool call runs with the user's vaulted butterbase credential
await sk.tools.executeTool(msg.content, "user_123");
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["butterbase"] }, pageSize: 100,
});

const agent = new Agent({
  name: "butterbase_agent",
  model: "gemini-2.5-pro",
  instruction: "Butterbase tools scoped to this user",
  tools,
});

await agent.run("List my Butterbase apps and the last 5 function deploys");
Try these prompts
Copy any prompt into your agent. Each maps directly to a Butterbase tool. Click to copy, paste into your agent, done.
Apps and data
Copy the prompt
Copied
List all my Butterbase apps and their regions.
Copy the prompt
Copied
Show the schema for the app storefront-api.
Copy the prompt
Copied
List the last 20 rows in the orders table.
Copy the prompt
Copied
Create a new app named billing-service in us-east-1.
Functions and deploys
Copy the prompt
Copied
Deploy the latest version of the send-receipt function.
Copy the prompt
Copied
Show the logs for the send-receipt function from the last hour.
Copy the prompt
Copied
List frontend deployments for storefront-api.
Copy the prompt
Copied
Update the frontend environment variable API_URL.
Storage and AI
Copy the prompt
Copied
Get the value stored under the key feature_flags.
Copy the prompt
Copied
Create a RAG collection named support-docs.
Copy the prompt
Copied
Query the support-docs collection for refund policy.
Copy the prompt
Copied
List the AI models available through the gateway.
SEE HOW AUTH WORKS
Your users connect once. Their Butterbase access tokens stay vaulted, every call is checked, and every action is logged.
1
Authorize
Your user connects
Butterbase
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Butterbase
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Butterbase
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Butterbase
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other developer tools and database connectors.
Engineering Teams
DevOps assistant agent
Polls GitHub for failing checks and stale PRs, opens Linear issues for the ones that need work, and posts a daily digest to Slack. It acts as the engineer, not a shared service account.
Engineering Teams
Auto release notes agent
Reads merged GitHub PRs, groups them into structured release notes, publishes the page to Notion, and announces the release in Slack. Every call runs on the engineer's own delegated OAuth.
Engineering Teams
Engineering standup agent
Pulls commits from GitHub and GitLab, tracks issue movement in Jira, and posts a per-engineer standup brief to Slack. Each engineer's activity is read on their own delegated OAuth.
Engineering Teams
Slack triage
Polls Slack for new messages, classifies bugs and support requests with a LangGraph router, files GitHub issues or Zendesk tickets, and confirms in the thread.
Test other agents
See the same per-user auth pattern across other developer tools and database connectors.
ENGINEERING
DevOps assistant agent
Poll GitHub for failing checks and stale pull requests, open Linear issues for the ones that need work, and digest to Slack.
ENGINEERING
Auto-release notes agent
Group merged GitHub PRs into structured release notes, publish the page to Notion, and announce the release in Slack.
ENGINEERING
Engineering standup agent
Pull commits from GitHub and GitLab, track Jira issue movement, and post a per-engineer standup brief to Slack.
ENGINEERING
Slack triage agent
Classify new Slack messages as bugs or support requests, file the GitHub issue or Zendesk ticket, and reply in the thread.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared Butterbase access token looks fine in a demo. In production every schema change and deploy looks like one service account, and you cannot tell which user triggered it. Scalekit resolves the credential of the actual user who triggered the agent, never a shared bot.
// shared token
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Butterbase today. Ten connectors tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access Butterbase as the user or through a shared key?
As the user. Each user connects their own Butterbase access token once, and Scalekit sends it with every call, so every app change, deploy, and data write in your audit trail is attributed to a real user, not a shared service account.
Where is the Butterbase access token stored?
In an AES-256 encrypted vault with per-tenant namespacing. Tokens are resolved at request time, never enter LLM context, and can be revoked from one dashboard. To rotate one, the user reconnects with a new access token.
Can I limit what the agent does in Butterbase?
Yes. Butterbase exposes 210 tools, including 22 destructive ones such as butterbase_app_delete and butterbase_kv_flush. Filter by tool name in listScopedTools to expose only what you want. Scalekit also enforces scope checks before every API call.
What happens when a user revokes access?
The credential is invalidated at the next tool call. The call fails closed, other users' connections are unaffected, and the revocation is logged in the audit chain.
Can the agent work across multiple Butterbase apps?
Yes. Most tools take an app_id, so the agent can list apps with butterbase_apps_list and then act on each one, all under the same user's access token.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""butterbase"": {
""url"": ""https://mcp.scalekit.com/butterbase"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.butterbase]
url = ""https://mcp.scalekit.com/butterbase""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""butterbase"": {
""url"": ""https://mcp.scalekit.com/butterbase"",
""type"": ""http""
}
}
}