io.github.springrolldev/springroll

MCPcommunitylive
v0.1.0io.github.springrolldevUnknownUpdated 1mo ago

Register, deploy, review, and govern internal applications built with coding agents.

Endpoint healthlive
checked 6 days ago · 363ms
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1mo agoLast update
Package
Authorio.github.springrolldev
LicenseUnknown
Version0.1.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface15 tools · none privileged
Security scan✓ Cleanvlive · 6d agoHow well does this scan work?
EvalsNone
IndexedAug 14, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

15 tools · none privileged
Observed live from the vendor's endpoint6d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://springroll.dev/api/mcp15 tools · 363ms
springroll.contextReturns the organization, identity, and permissions this agent token acts as, together with the deployment runtimes configured for it. Call this first: it tells you which tenant you are in, what you are allowed to do, and whether a deployment can actually land. It never returns credentials.

Returns the organization, identity, and permissions this agent token acts as, together with the deployment runtimes configured for it. Call this first: it tells you which tenant you are in, what you are allowed to do, and whether a deployment can actually land. It never returns credentials.

ParameterTypeDescription
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.deployRegisters the project if it is new, attaches whatever source you give it, and deploys it using the application's Deployment workflow. Direct applications go to Production; Staged applications go to Development. Returns the live URL, or a deployment id to poll if the build is still running. **You d…

Registers the project if it is new, attaches whatever source you give it, and deploys it using the application's Deployment workflow. Direct applications go to Production; Staged applications go to Development. Returns the live URL, or a deployment id to poll if the build is still running. **You d…

ParameterTypeDescription
applicationstringAn existing app's slug or id. Omit on the first ship; `name` implies it.
namestring—
slugstring—
manifeststringA SpringRoll manifest. Supersedes the metadata fields below; the source fields still apply.
descriptionstring—
departmentstring—
supportContactstringTeam channel or email for users of this app. Required before production.
dataClassificationstring—
tagsarray—
repositoryUrlstring—
refstringBranch, tag, or full commit SHA. Defaults to the app's default revision.
archivestringBase64 of a gzipped tar of the project source. Preferred over `files`.
filesobjectPath-to-contents map. Use `archive` for anything beyond a few files.
filesEncodingstring—
preferSourcestringTie-breaker when both a repository and files are given. Defaults to git.
frameworkstring—
installCommandstring—
buildCommandstring—
outputDirectorystring—
rootDirectorystring—
placementobjectOptional, provider-neutral hints about what this application needs. SpringRoll chooses the provider and plan; these only inform that choice. Leave out anything…
waitSecondsintegerHow long to wait for the build before returning. Defaults to 20. A real build usually outlasts this; poll springroll.deploy.status after.
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.deploy.statusReturns a deployment's current status, refreshing it from the runtime provider when the build is still in progress. Statuses: QUEUED, VALIDATING, BUILDING, DEPLOYING, READY, FAILED, CANCELLED, SUPERSEDED, ROLLED_BACK. Poll this after deploying rather than assuming success. Pass `includeLogs` to ge…

Returns a deployment's current status, refreshing it from the runtime provider when the build is still in progress. Statuses: QUEUED, VALIDATING, BUILDING, DEPLOYING, READY, FAILED, CANCELLED, SUPERSEDED, ROLLED_BACK. Poll this after deploying rather than assuming success. Pass `includeLogs` to ge…

ParameterTypeDescription
deploymentId*string—
includeLogsbooleanInclude build and deploy log lines. Defaults to false.
logLimitintegerHow many log lines to return, counting from the end. Defaults to 200.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.deploy.promotePromotes a tested deployment into the next environment (development -> uat, uat -> production). Reuses the already-built artifact rather than rebuilding, so the bytes that were tested are the bytes that ship. Promotion into an environment that requires approval will be refused until the approval e…

Promotes a tested deployment into the next environment (development -> uat, uat -> production). Reuses the already-built artifact rather than rebuilding, so the bytes that were tested are the bytes that ship. Promotion into an environment that requires approval will be refused until the approval e…

ParameterTypeDescription
deploymentId*stringThe tested deployment to promote.
targetEnvironmentType*stringCanonical environment class. SpringRoll promotes development -> uat -> production.
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.placement.previewScores where SpringRoll would place this application and what it would cost, without deploying or writing anything. It shares its implementation with springroll.deploy, so the receipt it returns is what a deploy right now would decide: the provider and plan, the estimated monthly cost range, every…

Scores where SpringRoll would place this application and what it would cost, without deploying or writing anything. It shares its implementation with springroll.deploy, so the receipt it returns is what a deploy right now would decide: the provider and plan, the estimated monthly cost range, every…

ParameterTypeDescription
application*stringApplication slug or id.
environmentTypestringEnvironment class to score for. Defaults to production, which is the strictest: plans published as unsuitable for production are excluded there.
placementobjectOptional, provider-neutral hints about what this application needs. SpringRoll chooses the provider and plan; these only inform that choice. Leave out anything…
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.getReturns an application's registry record: metadata, lifecycle stage, risk score, and whichever of the optional sections you ask for. No secrets are included. Sections, all returned by default: • `source`: repository or uploaded bundle, and `cannotBuildReason` when a deploy would be refused for wa…

Returns an application's registry record: metadata, lifecycle stage, risk score, and whichever of the optional sections you ask for. No secrets are included. Sections, all returned by default: • `source`: repository or uploaded bundle, and `cannotBuildReason` when a deploy would be refused for wa…

ParameterTypeDescription
application*stringApplication slug or id.
includearraySections to return. Defaults to all of them.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.listLists applications in this organization, newest first. Use `search` to find one by name or slug.

Lists applications in this organization, newest first. Use `search` to find one by name or slug.

ParameterTypeDescription
searchstring—
limitinteger—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.updateUpdates App Portal metadata: description, icon, tags, department, support contact, and data classification. Visibility is deliberately not editable here, because widening an audience requires an approval request (sec. 15.4).

Updates App Portal metadata: description, icon, tags, department, support contact, and data classification. Visibility is deliberately not editable here, because widening an audience requires an approval request (sec. 15.4).

ParameterTypeDescription
application*stringApplication slug or id.
descriptionstring—
iconUrlstring—
tagsarray—
departmentstring—
supportContactstring—
dataClassificationstring—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.approval.submitSubmits an approval request of any supported type: UAT_PROMOTION, UAT_SIGN_OFF, PRODUCTION_PROMOTION, VISIBILITY_CHANGE, OWNERSHIP_TRANSFER, RETIREMENT, DOMAIN_CHANGE, or ROLLBACK. **An agent may submit but never decide**: SpringRoll requires a human approver, and an agent token cannot approve its…

Submits an approval request of any supported type: UAT_PROMOTION, UAT_SIGN_OFF, PRODUCTION_PROMOTION, VISIBILITY_CHANGE, OWNERSHIP_TRANSFER, RETIREMENT, DOMAIN_CHANGE, or ROLLBACK. **An agent may submit but never decide**: SpringRoll requires a human approver, and an agent token cannot approve its…

ParameterTypeDescription
application*stringApplication slug or id.
requestType*string—
releaseIdstringRelease this concerns. For PRODUCTION_PROMOTION, defaults to the latest release.
targetEnvironmentTypestringCanonical environment class. SpringRoll promotes development -> uat -> production.
justificationstringWhy this should happen. Shown to reviewers. Required for ROLLBACK and RETIREMENT, and at least 10 characters when required.
payloadobjectType-specific detail, e.g. { visibility: 'TENANT' }, { newOwnerMembershipId: '…' }, or { targetDeploymentId: '…' } for a rollback.
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.approval.getReturns an approval request with its assigned reviewers, decisions so far, and the policy snapshot taken at submission. Poll this to find out whether a release has been approved.

Returns an approval request with its assigned reviewers, decisions so far, and the policy snapshot taken at submission. Poll this to find out whether a release has been approved.

ParameterTypeDescription
approvalRequestId*string—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.policy.checkReports which governance policies an application would pass or fail for an environment. Send `manifest` (YAML or JSON) to validate a document without creating anything. Call this before springroll.deploy to avoid a rejected submission. Read the `springroll://manifest/example` resource for the docu…

Reports which governance policies an application would pass or fail for an environment. Send `manifest` (YAML or JSON) to validate a document without creating anything. Call this before springroll.deploy to avoid a rejected submission. Read the `springroll://manifest/example` resource for the docu…

ParameterTypeDescription
manifeststringThe manifest document, as YAML or JSON. Mutually exclusive with `application`.
applicationstringAn existing application to explain. Mutually exclusive with `manifest`.
environmentTypestringEnvironment to evaluate against. Defaults to production.
releaseIdstringRelease to evaluate. Only meaningful with `application`.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.connect.data_productsWithout `dataProduct`, lists the governed data products this organization publishes: what each one holds, who owns it, and how sensitive it is. With `dataProduct`, returns that product's schema: its datasets, the available fields with their types and sensitivity, the business glossary its owner wr…

Without `dataProduct`, lists the governed data products this organization publishes: what each one holds, who owns it, and how sensitive it is. With `dataProduct`, returns that product's schema: its datasets, the available fields with their types and sensitivity, the business glossary its owner wr…

ParameterTypeDescription
dataProductstringData product slug. Omit to list every product this organization publishes.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.connect.request_accessRequests access to a data product for one environment, naming the exact fields the application needs. A data owner must approve, and may narrow the field list or add a row filter before doing so. Nothing is readable until then. You never receive a credential: an approved grant lets the deployed app…

Requests access to a data product for one environment, naming the exact fields the application needs. A data owner must approve, and may narrow the field list or add a row filter before doing so. Nothing is readable until then. You never receive a credential: an approved grant lets the deployed app…

ParameterTypeDescription
application*stringApplication slug or id.
dataProduct*stringData product slug from springroll.connect.data_products.
environmentType*stringCanonical environment class. SpringRoll promotes development -> uat -> production.
fields*arrayQualified field names to request, as `dataset.field`. Ask for what the application actually reads, because a narrower request is approved faster and survives r…
purposestringWhy the application needs this data. Shown to the data owner.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.connect.access_statusReturns the status of a data access request: REQUESTED, APPROVED, REJECTED, REVOKED, or EXPIRED, with the fields actually approved. Approved fields are often narrower than requested, and a row filter may restrict which rows the application can see at all.

Returns the status of a data access request: REQUESTED, APPROVED, REJECTED, REVOKED, or EXPIRED, with the fields actually approved. Approved fields are often narrower than requested, and a row filter may restrict which rows the application can see at all.

ParameterTypeDescription
grantId*string—
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…
springroll.app.record_promptsAttaches the conversation that produced this application to its record, as reference for whoever maintains it next and for the reviewer who has to approve it. Ask the user before calling this, every time. The transcript is STORED and is READABLE BY ANYONE who can see the application record. Spring…

Attaches the conversation that produced this application to its record, as reference for whoever maintains it next and for the reviewer who has to approve it. Ask the user before calling this, every time. The transcript is STORED and is READABLE BY ANYONE who can see the application record. Spring…

ParameterTypeDescription
application*stringApplication slug or id.
sessionKey*stringStable identifier for this build conversation.
turns*arrayUp to 50 turns per call, in order.
startTurnIndexintegerWhere this batch starts. Defaults to after the last recorded turn.
agentNamestring—
modelNamestring—
inputTokensinteger—
outputTokensinteger—
releaseIdstring—
idempotencyKey*stringRequired. A stable, caller-generated key. Retrying with the same key returns the original result instead of creating a duplicate.
context*stringExplain why you are calling this tool and how it fits into the user's overall goal. This parameter is used for analytics and user intent tracking. YOU MUST pro…

15 of 15 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Register, deploy, review, and govern internal applications built with coding agents.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.