AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified Apache-2.0 Self-run

Objectstack

mcp-objectstack-ai-objectstack · by objectstack-ai

A complete business system in 16k tokens. ObjectStack compresses an entire app — data model, UI, workflows, permissions — into typed metadata an AI agent can hold in context, reason about, and refactor whole.

No reviews yet
0 installs
36 views
0.0% view→install

Install

$ agentstack add mcp-objectstack-ai-objectstack

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-objectstack-ai-objectstack)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Objectstack? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

ObjectStack

[](./LICENSE)

> ## A complete business system in 16k tokens. > > ObjectStack compresses an entire app — data model, UI, workflows, > permissions — into typed metadata an AI agent can hold in context, reason > about, and refactor whole ([a complete CRM is under 2,000 > lines](#why-the-mistakes-dont-ship)). That metadata is your business > ontology — an open, versioned definition of your objects, permissions, and > flows that you own, not code scattered across a framework. Strict TypeScript, > Zod schemas, and a validation gate catch the agent's mistakes at authoring > time; the runtime derives the database, REST API, UI, and MCP server, and > enforces permissions and audit on every call.

Fits in an agent's context · Typed, validated, governed · Self-host anywhere · Apache-2.0

Everything in this repo is the open stack — protocol, microkernel, SDK, CLI, and the production runtime, Apache-2.0 with no open-core asterisks. The workflow here is build & ask with Claude Code (or any coding agent): the agent writes the metadata in your repo, and operates the running app over MCP. Rather build & ask online — in the browser, nothing to install? That's ObjectOS, the commercial runtime environment built on this stack.

One typed definition → database · REST API · client SDK · UI · MCP tools.

The loop

1 · Create a project. The scaffolder installs the AI skills bundle and writes an AGENTS.md, so your agent starts with the protocol's rules already loaded — not with generic "write me some TypeScript" priors.

npm create objectstack@latest my-app && cd my-app

2 · Describe the requirement. Open the project in Claude Code (or Cursor, Copilot, …) and say what the business needs:

> Build a support desk. Add a ticket object with subject, description, a > priority select and a status select. Add a Resolve action that only shows > on tickets that aren't already resolved. Add an "Open tickets" list view and a > Support nav group. Run npm run validate when you're done.

The agent writes typed metadata — not a codebase. The gate rejects what would fail silently at runtime, and the agent fixes it before you ever see it.

3 · Preview in the browser.

npx os dev --ui   # → http://localhost:3000/_console/

The Console renders the real app — records, boards, dashboards. Something wrong? Say what to change. Requirement changes run the same loop, on a diff you can actually read.

Prefer clicking? Studio authors the same metadata visually — same artifacts, same gate.

What can it actually build?

Point an agent at an empty repo and you get a one-off codebase: every screen hand-invented, every mistake yours to find at runtime. ObjectStack gives the agent a vocabulary instead — typed, validated primitives for what enterprise software is actually made of. The agent composes the definition; the runtime already knows how to run it.

| | Capability | | :--- | :--- | | Objects & fields | Typed schemas with relations, validation, formulas, files | | Permissions | RBAC plus row- and field-level security, enforced by the runtime | | Automation | DAG flows, record triggers, scheduled jobs, webhooks | | Approvals | Multi-step chains with queues and a full audit trail | | Views | Lists, kanban, calendars, gantt, galleries — declared, not coded | | Dashboards & reports | Charts, aggregations, KPIs bound to live data | | Actions | Permission-checked buttons and server operations | | APIs & SDK | Generated REST + realtime endpoints, typed client SDK | | AI tools | Every object and exposed action doubles as a governed MCP tool | | Translations | Labels and UI text as metadata, per locale | | Seed data | Fixtures and demo datasets that ship with the app | | Datasources | PostgreSQL, MySQL, SQLite, MongoDB, or in-memory |

Here's the shape of it — one object, and the database table, REST API, UI views, and MCP tools all follow:

import { ObjectSchema, Field } from '@objectstack/spec/data';

export const Ticket = ObjectSchema.create({
  name: 'support_desk_ticket',
  label: 'Ticket',
  sharingModel: 'private',            // org-wide default — the security gate requires it
  fields: {
    subject: Field.text({ label: 'Subject', required: true, searchable: true }),
    status: Field.select({
      label: 'Status',
      required: true,
      options: [
        { label: 'Open', value: 'open', color: '#3B82F6', default: true },
        { label: 'Resolved', value: 'resolved', color: '#10B981' },
      ],
    }),
    due_date: Field.date({ label: 'Due Date' }),
  },
});

Why the mistakes don't ship

"AI writes it" is only useful if AI's mistakes don't reach production. Four gates stand between the agent and your users:

| Gate | Catches | | :--- | :--- | | Typed | Strict TypeScript + Zod — shape errors die in the editor, seconds after the agent writes them | | Validated | os validate rejects metadata that type-checks but would fail silently at runtime: dangling bindings, bad CEL predicates, missing security posture | | Reviewed | You approve a small readable diff in the Console — not fifty thousand lines of glue | | Governed | The runtime enforces permissions and audit on every call, so even a wrong app stays inside the fence |

The reason this works is the same reason TypeScript was the right host language: an agent's errors become located, corrective text it can read and fix itself, in seconds — instead of a silent runtime failure nobody traces back.

The other half is size. The CRM in this repo — [examples/app-crm](./examples/app-crm): six objects, views, a dashboard, a lead-conversion flow, permission sets, actions, translations — is 31 files, 1,792 lines, roughly 16k tokens. That's the whole business system, in about 8% of a 200k-token context window. Count it yourself:

find examples/app-crm/src -name '*.ts' -not -name '*.test.ts' | xargs cat | wc -l

Because it fits in an agent's context window, the agent can load it end-to-end, reason about every dependency, and refactor across data, API, UI, and permissions in one change — it can answer "what breaks if I change this?" instead of grepping and hoping. That's the difference between AI as autocomplete and AI as a co-maintainer.

> Your objects, permissions, and flows are your business ontology — and the > definition layer of the AI era should be an open protocol you own. > Read why.

Your app is AI-operable, for free

Because the app is typed metadata, the runtime serves it as an MCP server at /api/v1/mcp — on by default. Point any MCP client at it and an agent can inspect and operate the app you just built, under the same permissions and RLS as a human:

claude mcp add --transport http my-app http://localhost:3000/api/v1/mcp

Objects are exposed automatically; actions opt in with ai: { exposed: true }. See Connect an MCP Client.

This repo

The framework: the protocol (@objectstack/spec), kernel, SDK, CLI, and the production runtime. os start or the official Docker image [ghcr.io/objectstack-ai/objectstack](./docker) ships your compiled app — Console and governance included — entirely on open source. Try a live app in ~30s on StackBlitz (no install).

Three layers sit on a microkernel: ObjectQL (data), Kernel (control), ObjectUI (view). Everything starts as a Zod schema — 1,600+ of them — and TypeScript types, JSON Schemas, REST routes, UI metadata, and agent tools are all derived from that one source. See [ARCHITECTURE.md](./ARCHITECTURE.md).

Want it governed and hosted, with Build & Ask AI built in? ObjectOS is the commercial runtime for these definitions — objectstack-ai/objectos is its public home (docs, issue tracker, trademark policy).

Ship it

The scaffolded project is container-ready:

docker build -t my-app . && docker compose up -d   # app + Postgres on the official runtime image

See Self-Hosted Deployment for bare Node, Kubernetes, and the secrets you must pin — and Build with Claude Code to run the whole loop end-to-end.

Working on the framework itself

git clone https://github.com/objectstack-ai/objectstack.git
cd objectstack
pnpm install     # Node 18+, pnpm 8+ (corepack enable)
pnpm build       # build all packages
pnpm dev         # run the showcase example (REST + Console on :3000)

Monorepo Scripts

| Script | Description | | :--- | :--- | | pnpm build | Build all packages (excludes docs) | | pnpm dev | Run the showcase kitchen-sink example (@objectstack/example-showcase) — REST + Studio; exercises every metadata type, view, automation, AI & security chain | | pnpm dev:showcase | Same as pnpm dev (explicit alias) | | pnpm dev:crm | Run the minimal CRM example (@objectstack/example-crm) | | pnpm dev:todo | Run the Todo example (@objectstack/example-todo) | | pnpm objectui:refresh | Pull the sibling ../objectui build into packages/console/ | | pnpm test | Run all tests (Turborepo) | | pnpm setup | Install dependencies and build the spec package | | pnpm docs:dev | Start the documentation site locally | | pnpm docs:build | Build documentation for production |

CLI Commands

The CLI binary ships as both os and objectstack.

os init [name]    # Scaffold a new project
os create         # Interactive project / object scaffolder
os dev            # Start dev server with hot-reload (REST + console)
os start          # Start the production server
os serve          # Serve a compiled artifact
os compile        # Build a deployable JSON Environment Artifact
os validate       # Validate metadata against the protocol
os lint           # Lint metadata for best-practice violations
os info           # Display project metadata summary
os generate       # Scaffold objects, views, flows, agents, migrations
os doctor         # Check environment health
os explain        # Explain protocol concepts on the command line

Cloud, package registry, and environment management subcommands (os package publish, os package install, os login, os whoami, os environments, os cloud …) are available when targeting an ObjectStack Cloud control plane.

Use the generated API

Every object ships a REST API automatically — no controllers to write:

# CRUD endpoints for the `todo_task` object you defined above
curl http://localhost:3000/api/v1/data/todo_task

For the browser, the typed client SDK and React hooks (useQuery / useMutation / usePagination) live in [@objectstack/client-react](packages/client-react). Need a new capability? Write a plugin, driver, or service against the same kernel APIs — every built-in is one (see below).

Package Directory

72 published packages across core, engine, drivers, client, plugins, services, adapters, tools, and examples — click to expand.

Core

| Package | Description | | :--- | :--- | | [@objectstack/spec](packages/spec) | Protocol definitions — Zod schemas, TypeScript types, JSON Schemas, constants | | [@objectstack/core](packages/core) | Microkernel runtime — Plugin system, DI container, EventBus, Logger | | [@objectstack/types](packages/types) | Shared TypeScript type utilities | | [@objectstack/formula](packages/formula) | Canonical expression engine — CEL (cel-js) + ObjectStack stdlib for formula fields, predicates, conditions, dynamic defaults | | [@objectstack/platform-objects](packages/platform-objects) | Built-in platform object schemas — identity, security, audit, notification, package, and environment |

Engine

| Package | Description | | :--- | :--- | | [@objectstack/objectql](packages/objectql) | ObjectQL query engine and schema registry | | [@objectstack/runtime](packages/runtime) | Runtime bootstrap — DriverPlugin, AppPlugin | | [@objectstack/metadata](packages/metadata) | Metadata loading and persistence | | [@objectstack/rest](packages/rest) | Auto-generated REST API layer |

Drivers

| Package | Description | | :--- | :--- | | [@objectstack/driver-memory](packages/plugins/driver-memory) | In-memory driver (development and testing) | | [@objectstack/driver-sql](packages/plugins/driver-sql) | SQL driver — PostgreSQL, MySQL, SQLite (production) | | [@objectstack/driver-mongodb](packages/plugins/driver-mongodb) | MongoDB driver (native document database) |

> Turso / libSQL driver (@objectstack/driver-turso) and the libSQL-backed vector knowledge plugin (@objectstack/knowledge-turso) live in the ObjectStack Cloud monorepo as of this release.

Client

| Package | Description | | :--- | :--- | | [@objectstack/client](packages/client) | Client SDK — CRUD, batch API, error handling | | [@objectstack/client-react](packages/client-react) | React hooks — useQuery, useMutation, usePagination |

Plugins

| Package | Description | | :--- | :--- | | [@objectstack/plugin-hono-server](packages/plugins/plugin-hono-server) | Hono-based HTTP server plugin | | [@objectstack/mcp](packages/mcp) | Model Context Protocol server — exposes ObjectStack to AI agents | | [@objectstack/plugin-auth](packages/plugins/plugin-auth) | Authentication plugin (better-auth) | | [@objectstack/plugin-security](packages/plugins/plugin-security) | RBAC, Row-Level Security, Field-Level Security | | [@objectstack/plugin-sharing](packages/plugins/plugin-sharing) | Record-level sharing — sys_record_share + enforcement middleware | | [@objectstack/plugin-approvals](packages/plugins/plugin-approvals) | Approval as a flow node — approver resolution, record lock & status mirror over sys_approval_request + sys_approval_action | | [@objectstack/plugin-audit](packages/plugins/plugin-audit) | Audit logging plugin | | [@objectstack/plugin-email](packages/plugins/plugin-email) | Pluggable outbound email transport | | [@objectstack/plugin-webhooks](packages/plugins/plugin-webhooks) | Outbound webhook delivery — fan-out data.record.* events | | [@objectstack/plugin-reports](packages/plugins/plugin-reports) | Saved reports + scheduled email digests | | [@objectstack/plugin-dev](packages/plugins/plugin-dev) | Developer mode — in-memory stubs for all services |

Services

| Package | Description | | :--- | :--- | | [@objectstack/service-analytics](packages/services/service-analytics) | Analytics — aggregations, time series, funnels, dashboards | | [@objectstack/service-automation](packages/services/service-automation) | Automation engine — flows, triggers, and workflow state machines | | [@objectstack/service-cache](packages/services/service-cache) | Cache — in-memory, Redis, multi-tier | | [@objectstack/service-feed](packages/services/service-feed) | Activity feed / chatter | | [@objectstack/service-i18n](packages/services/service-i18n) | Internationalization service | | [@objectstack/service-job](packages/services/service-job) | Cron & interval job scheduler | | [@objectstack/service-package](packages/services/service-package) | Package registry — publish, version, retrieve metadata packages | | [@objectstack/service-queue](packages/services/service-queue) | Background job queue (in-memory, BullMQ) | | [@objectstack/service-realtime](packages/services/service-realtime) | Real-time events and subscriptions | | [@objectstack/service-settings](packages/services/service-settings) | Settings — manifest registry + K/V resolver (Env > Tenant > User) | | [`@objectstack/service-sto

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.