v0.3.2 · Published on npm
Make any JS/TS app AI-ready in one line.
An auto-generated MCP server so agents can operate your product, plus an embedded knowledge base so they understand it. No external services, no build step on Node.
// server.ts import { aiReady } from "@exposify/express"; app.use(aiReady()); // MCP endpoint live at /mcp
Everything an agent needs, nothing you have to build.
Writes are opt-in
Reads are auto-exposed. Writes stay hidden until you opt them in with exposed(), hidden(), or describe() — right where the route lives.
Mounted routers, discovered
Routers mounted on Express 4 or 5 are found automatically, with an explicit mounts option as the fallback.
Auth passthrough
Agents act with exactly the caller's existing credentials — no separate service account to manage.
Built-in knowledge base
A knowledge base built from your README and docs, searchable by agents through the search_docs tool.
Guardrails by default
Byte-accurate size caps, header stripping, rate limiting, sanitized errors, and per-dispatch timeouts.
No external services
No extra infrastructure and no build step on Node — mount it and the MCP endpoint is live.
Opt in to writes right where the route lives.
Writes are hidden until you opt them in. Wrap a handler with exposed() to expose it as-is, or describe() to enrich the tool while opting in.
import { aiReady, exposed, describe } from "@exposify/express"; // Writes are hidden until you opt them in: app.post("/orders", exposed(createOrder)); // Or enrich the tool while opting in: app.post("/orders/:id/refund", describe(refundOrder, { name: "refund_order", description: "Refund an order. Reversible within 30 days.", }));
import { aiReady } from "npm:@exposify/supabase"; Deno.serve(aiReady({ writes: ["orders.insert", "orders.update"], rpc: ["place_order"], }));
Make the backend itself AI-ready.
For Supabase-backed apps, @exposify/supabase serves MCP straight from a Deno edge function — tools are generated from the database (PostgREST + RLS) plus explicitly registered edge functions, with the caller's JWT passed through untouched.
RLS is the authorization layer: the agent can do exactly what that logged-in user can do.
Get notified about new releases.
New adapters and features ship regularly — get an email when something new lands.
No spam. Release notes only.