Install
$ agentstack add mcp-21st-dev-claude-code-plugin ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
21st — Claude Code plugin
One install wires up both the 21st MCP server and the 21st.dev Agent Skills in Claude Code, so Claude searches, installs and publishes on 21st.dev from the terminal or via MCP tool calls, instead of hand-writing UI.
What's inside
- MCP server
21st— the remote endpointhttps://21st.dev/api/mcp
(JSON-RPC over HTTP), exposing 21 tools: search, get_component, get_theme, bookmarks + bookmark lists, teams, get_usage, generate, and edit/delete for components/themes/templates. Metadata search is free; component code, generation and writes are metered.
- Skills — seven focused Agent Skills that teach the
21stCLI
(npx @21st-dev/cli), auto-activating when the project has a components.json: 21st-cli-use (search / install), 21st-ai (generate, iterate on, and grab code from 21st AI drafts), 21st-registry (publish & manage components/themes/templates), and 21st-design-sync (publish the project's design tokens as a theme), plus project-aware Build, Explore, and Review workflows.
Install
- Set your 21st API key in the environment (get one at
https://21st.dev/settings/api-keys):
``bash export API_KEY_21ST="sk_..." ``
- Add this marketplace and install the plugin from inside Claude Code:
`` /plugin marketplace add 21st-dev/claude-code-plugin /plugin install 21st@21st ``
(21st@21st = plugin 21st from marketplace 21st. Replace 21st-dev/claude-code-plugin with the actual / that hosts this directory, or a local path / git URL.)
- Restart Claude Code (or reload) so the MCP server connects. Verify with
/mcp — you should see the 21st server with its full tool list (search, get_component, get_theme, bookmarks, teams, generate, …).
Auth
The MCP server reads your key from the API_KEY_21ST environment variable and sends it as the x-api-key header (see plugins/21st/.mcp.json). If tool calls report "Not authenticated," confirm API_KEY_21ST is exported in the shell that launched Claude Code, then reconnect via /mcp.
Layout
.claude-plugin/
marketplace.json # marketplace listing this plugin
plugins/
21st/
.claude-plugin/
plugin.json # skills + mcpServers (via ${CLAUDE_PLUGIN_ROOT})
.mcp.json # remote 21st MCP (x-api-key: ${API_KEY_21ST})
skills/
21st-cli-use/
SKILL.md # bundled Agent Skills (same source as
21st-ai/ # https://21st.dev/api/skills/)
SKILL.md
21st-registry/
SKILL.md
21st-design-sync/
SKILL.md
Bundled paths in plugin.json use ${CLAUDE_PLUGIN_ROOT} so they resolve regardless of where the plugin is installed.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: 21st-dev
- Source: 21st-dev/claude-code-plugin
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.