Webflow MCP Server
Webflow’s official MCP server for AI-assisted website design, CMS management, and content work on a live project.
- Skill Road
- Webflow MCP Server
Description
The Webflow MCP Server is Webflow’s official interface that lets an MCP-capable AI client work directly with Webflow projects. Instead of handling design, CMS content, and page structure exclusively by hand in the Webflow Designer, an agent inside Cursor, Claude Desktop, Claude Code, or another compatible client can connect to a Webflow account and carry out tasks described in natural language. According to the provider, this covers responsive layouts built from sections, containers, and grids, individual elements such as rich text, buttons, forms, and media, plus CSS classes, combo classes, and raw CSS. Reusable components with props, variants, and slots, custom code, custom fonts, and design-system variables for color schemes are also part of the documented feature set.
Beyond visual design, the server covers content management: CMS collections and fields including bulk updates, pages, assets, forms, the sitemap, SEO metadata, and comments can all be read and edited through the agent. Webflow also offers Analyze capabilities that surface sessions, users, pageviews, top pages, and traffic sources through chat — according to Webflow, this analytics add-on requires a paid site plan and is not included with every account.
Two access paths, one repository
Webflow publishes the server in the official webflow/mcp-server repository (MIT license, TypeScript, exactly 140 GitHub stars via the API on September 21, 2026) and offers two ways to run it. The recommended path is the hosted remote server at https://mcp.webflow.com/sse: authentication happens through OAuth, no local API token is needed, and for Designer-specific features like visual snapshots or canvas navigation, Webflow automatically installs a companion “MCP Bridge App” into the workspace during authorization. Alternatively, the server can run locally via the webflow-mcp-server npm package through npx; this requires a self-registered Webflow app and a personal API token supplied through the WEBFLOW_TOKEN environment variable. Both paths require Node.js 22.3.0 or newer. This entry treats both official paths as one server (deployment_type = both) because they ship from the same repository and expose the same tools.
MCP 2.0 and the role of the bridge app
In August 2026, Webflow rolled out what its own announcement calls “MCP 2.0”: the earlier requirement to run the bridge app was removed “for most use cases,” which allows working on several pages at once and is meant to make workflows more reliable. New additions include full access to design-system components with props, slots, and variants, centrally stored “Agent Instructions” for tone, design, and compliance guidance, full enforcement of team roles and permissions including branching, and a complete audit trail of changes with AI attribution in the Activity Log. According to the provider, MCP 2.0 is “available on all site plans, at no additional cost” — so baseline use is not tied to a specific paid plan, even though certain analytics features still require a separate, paid add-on.
Governance built on existing permissions
Webflow deliberately describes its permission model as tied to existing user rights: an agent using the MCP server can only do what the connected account could already do inside the Webflow Designer, nothing more. This role-based access control sits on top of OAuth authorization and is reinforced by the Activity Log, which keeps changes — including AI authorship — traceable. For teams, this is an important difference from MCP servers that grant blanket access to an entire account: someone who can only edit specific pages or collections in the Designer cannot use an agent to go beyond that boundary.
Who benefits from the Webflow MCP Server
The server suits anyone already building or maintaining websites in Webflow who wants to handle recurring work — new CMS entries, structural or copy changes, SEO metadata, linking older blog posts, or drafting new sections — through a prompt instead of manual clicking. For teams that take governance seriously, it matters that Designer permissions carry over one-to-one and that every change is logged. Anyone looking for a fully independent headless CMS with no tie to the Webflow design surface may be better served by generic REST/GraphQL access through the Webflow Data API than by this Designer-oriented MCP toolkit.
Security, data flow, and limits
Webflow projects can contain content from other people — form submissions, CMS entries sourced externally, or comments — that may end up in prompts or tool results. Such content should be treated as untrusted text, not as an instruction to the agent. Tool results pass through the connected AI client and may be processed by that client’s model provider; before sensitive customer data, credentials, or unpublished content are involved, it is worth checking the data policies of the client and model in use. For production sites, it is advisable to test write actions on non-critical pages or in a staging setup first and to review changes in the Activity Log before they go live. When running locally with WEBFLOW_TOKEN, treat that token like any other API secret and avoid sharing it in plain text.
Requirements
An MCP-compatible AI client (e.g. Cursor or Claude Desktop), a Webflow account with access to the target project, and for local use Node.js 22.3.0 or newer plus a Webflow API token.
Installation instructions
Remote (recommended): add https://mcp.webflow.com/sse as an MCP server in the client configuration and complete the OAuth flow; Webflow automatically installs the MCP Bridge App. Local: register your own Webflow app, set WEBFLOW_TOKEN, and configure npx -y webflow-mcp-server@latest as the command in the MCP configuration.
npx -y webflow-mcp-server@latest
Authentication
Remote server: OAuth authorization on connect. Local operation: a personal Webflow API token supplied via the WEBFLOW_TOKEN environment variable.
Required access permissions
According to the provider, an agent using the MCP server can only do what the connected account could already do in the Webflow Designer itself; team roles and permissions are fully enforced.
Transmitted or stored data
The server returns project, CMS, and analytics data to the connected AI client, which may forward results to its model provider; review that provider’s data policy separately. All changes are logged in the Webflow Activity Log with AI attribution.
Security risks
Project content (forms, CMS entries, comments) can contain untrusted text. Test write actions on non-critical pages first, treat the local WEBFLOW_TOKEN like any secret, and review changes in the Activity Log.
License and costs
- License
- MIT
- Cost
- free
According to the provider, MCP 2.0 is available on all Webflow site plans at no additional cost; the optional Webflow Analyze add-on requires a paid site plan. Check current details on the official Webflow pricing pages.
Alternatives
Not recorded yet.
At a glance
- Provider
- Webflow
- Status
- Official server
- Deployment
- Local and remote
- Current version
- 1.0.1
- GitHub stars
- 140
- Last reviewed
- 21.09.2026
Repository and documentation
Categories
Supported clients
Not recorded yet.
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026