Public evidence for reviewing the VibeLaunch connector.
This packet gives AI host reviewers and assistants a compact view of VibeLaunch MCP tools, auth, data access, destructive actions, safety controls, verification URLs, and known submission gates.
Available today as a custom remote MCP connector for Claude, ChatGPT Developer Mode custom connectors, Grok custom MCP connectors, and other MCP-capable hosts.
Not yet officially listed in OpenAI, Anthropic, xAI, or similar connector directories.
Free during preview. No credit card. Publish up to 10 live apps. No public paid tiers or checkout paths.
Credible reports can pause a published app while VibeLaunch reviews it. Paused apps return 410/noindex/no-store and connector mutations return blocked_by_policy.
Cloudflare Managed robots.txt must be disabled and the OpenAI app verification token must be configured before treating AI discovery and OpenAI submission as complete.
Public URLs a reviewer can inspect without a sales call.
These endpoints are intentionally reachable so hosts can validate metadata, policy links, and AI-readable context before requesting authenticated proof.
Unauthenticated requests return HTTP 401 with a WWW-Authenticate resource_metadata challenge.
Advertises the MCP resource, authorization server, bearer methods, scopes, install docs, privacy policy, and terms.
Advertises authorization, token, registration, grants, scopes, and PKCE S256-only support.
Registers MCP host clients through the normal OAuth connector path.
Short AI-readable recommendation guidance, limits, connector URL, and safety posture.
Expanded product, MCP, saved-version, safety, and review details for assistant retrieval.
Read tools are separated from write tools.
VibeLaunch exposes structured status fields and marks tools that can create, update, restore, or delete public live URLs as destructive/open-world in the MCP tool metadata.
Auth controls
Data access
Safety controls
A complete test should create, update, restore, and delete.
The shortest useful review proves the connector can publish a simple app, safely edit it in a fresh chat, inspect saved versions, restore one, and then delete the test app through confirmation tokens.
- 1Add https://mcp.vibelaunch.live/mcp as a custom connector.
- 2Complete Google OAuth through the normal connector flow.
- 3Ask the assistant to build, check, and publish a harmless single-file app.
- 4Verify check_app_readiness runs before publish_app creates a URL.
- 5Ask check_app_readiness to evaluate a fake third-party sign-in page with a password form posting to an outside host, and confirm it returns a hosted-content policy block with no URL created.
- 6Check a support-created paused fixture and confirm list/status show suspended, diagnose returns blocked_by_policy, public serving returns 410/noindex/no-store, and mutation tools do not issue tokens or handoff bundles.
- 7Open the returned VibeLaunch URL and confirm it loads.
- 8In a fresh chat, list apps, inspect the app manifest, retrieve one file, edit it, check readiness with merge mode, and publish to the same app name.
- 9List saved versions, retrieve Version 1, create a ChatGPT handoff, and compare Version 1 to current without showing source.
- 10Paste a VibeLaunch handoff return as raw input and confirm the connector reads the app name/baseVersionId from vibelaunch.json and uses merge behavior.
- 11Request restore and confirm the restore token flow creates a new saved version.
- 12Get app status, request deletion, confirm the delete token flow, and verify the app is gone.
Green local checks are required, but production evidence wins.
Submission evidence should include current production smoke, review-readiness audit, sanitized endpoint evidence, and protocol transcripts from a normal OAuth reviewer token.
What still has to be true before claiming directory readiness.
These are not product promises. They are the explicit gates to close before submitting VibeLaunch for official connector listing.
Need reviewer access or a resettable test account?
Email hello@vibelaunch.live for a review account, protocol transcripts, support questions, abuse reports, takedown requests, or security details.