Writespace Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Writespace Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A remote, hosted Model Context Protocol server for Writespace — a real-time collaborative document editor. Give Claude, ChatGPT, Gemini, Cursor, or any MCP-speaking agent a shared docs workspace it can read, write, organise and search alongside you.
Endpoint: https://app.writespace.io/mcp (HTTP transport, Bearer auth) Free tier: yes — up to 10 documents, no card required → sign up
Writespace is a markdown-first doc editor for humans with an MCP server built in for agents. Every action you can take in the app is exposed as a tool your model can call:
{ status: "accepted" })Agent writes broadcast over Realtime, so open editors reload live. Humans and agents work on the same canvas — no export step, no format negotiation.
Three steps, two minutes:
https://app.writespace.io/mcpclaude mcp add --transport http writespace \
https://app.writespace.io/mcp \
--header "Authorization: Bearer ws_pat_YOUR_TOKEN_HERE"~/Library/Application Support/Claude/claude_desktop_config.json
Claude Desktop's config supports only local (stdio) servers, so a remote HTTP server is bridged through mcp-remote, which Claude Desktop launches locally and which forwards to the endpoint:
{
"mcpServers": {
"writespace": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://app.writespace.io/mcp",
"--header",
"Authorization:${AUTH_HEADER}"
],
"env": {
"AUTH_HEADER": "Bearer ws_pat_YOUR_TOKEN_HERE"
}
}
}
}Notes:
AUTH_HEADER env var (and --header Authorization:${AUTH_HEADER} with no space after the colon) because mcp-remote mishandles spaces in --header arguments.PATH. If npx isn't found, use its absolute path (e.g. /usr/local/bin/npx, or your nvm path) — and add a matching "PATH" entry to env if it relies on a versioned node.Settings → MCP → Add server
Type: HTTP
URL: https://app.writespace.io/mcp
Header: Authorization: Bearer ws_pat_YOUR_TOKEN_HERE~/.gemini/settings.json
{
"mcpServers": {
"writespace": {
"httpUrl": "https://app.writespace.io/mcp",
"headers": {
"Authorization": "Bearer ws_pat_YOUR_TOKEN_HERE"
}
}
}
}Any other spec-compliant MCP client works the same way: HTTP transport + Authorization: Bearer header.
Every tool except list_workspaces takes a workspace_id — call list_workspaces first to discover them.
| Tool | Description |
|---|---|
list_workspaces | List every workspace you belong to |
list_folders | List folders, optionally nested under a parent |
list_docs | List documents, optionally scoped to a folder; returns metadata per row |
get_doc | Fetch a doc by ID — canonical Tiptap JSON + markdown rendering + metadata |
search | Ranked full-text search with <<match>> snippets |
query_docs | Find docs whose metadata contains a JSON object (Postgres JSONB @>) |
create_doc | Create a doc from Tiptap JSON or markdown |
update_doc | Update title, content, or metadata (shallow-merge; null deletes a key) |
upsert_doc | Create-or-update by title within an optional folder — idempotent |
append_to_doc | Append markdown / Tiptap JSON to an existing doc |
replace_section | Replace a section's body by its heading text — surgical edits |
delete_doc | Delete a doc by ID |
move_doc | Move a doc to another folder (folder_id: null → root) |
create_folder | Create a folder, optionally nested |
rename_folder | Rename a folder — IDs stay stable, links don't break |
delete_folder | Delete a folder and its contents |
Full reference with format notes and troubleshooting: writespace.io/connect
content (Tiptap JSON) and content_markdown; writes accept either. Markdown round-trips for everything the editor supports, including tables, task lists, and mermaid diagrams.include_content: true to echo the body.metadata field. Treat it as queryable frontmatter: write it, shallow-merge it, query by containment.writespace://doc/<id>; IDs survive renames and moves.Authorization: Bearer ws_pat_… header; spec-compliant HTTP transport© 2026 Writespace · Pro is $5/user/month, free tier available.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.