AppCrane is the self-hosted home for the apps your AI builds and your AI deploys. It exposes 35 appcrane_* MCP tools so any MCP client (Claude Code, Cursor, Codex) can run the full deploy lifecycle — create app, deploy to sandbox/production, manage secrets, stream logs, list releases, roll back — every action bound to a user and audit-logged. Enterprise SSO (SAML/OIDC/SCIM), Docker isolation per a
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
Multer vulnerable to Denial of Service via deeply nested field names
Multer vulnerable to Denial of Service via unhandled exception from malformed request
Multer vulnerable to Denial of Service via unhandled exception
Multer vulnerable to Denial of Service via resource exhaustion
process.env. You'll be asked to provide them before it can run.ANTHROPIC_API_KEY— Add under [Service]: Environment="=sk-ant-..."APPCRANE_API_KEYAPPCRANE_AUDIT_REQUIREDAPPCRANE_DEBUG_CREDSAPPCRANE_GH_MCP_CALL_TIMEOUT_MSAPPCRANE_GH_MCP_DISABLEDAPPCRANE_GITHUB_TOKENAPPCRANE_MCP_URLAPPCRANE_PR_POLL_DISABLEDAPPCRANE_PR_POLL_MSAPPCRANE_SPA_AUTOBUILDAPPCRANE_URLAPPSTUDIO_CODER_MODELAPPSTUDIO_CONTEXT_TIMEOUT_MSAPPSTUDIO_IMAGEAPPSTUDIO_MAX_PLAN_PARALLELAPPSTUDIO_PLANNER_MODELAPPSTUDIO_PLAN_TIMEOUT_MSAPPSTUDIO_POLL_MSAPPSTUDIO_TIMEOUT_MSASK_TIMEOUT_MSBASE_URLCADDY_ADMIN_URLCADDY_HTTP_PORTCC_API_KEYCC_API_URLCODER_IDLE_MSCODER_TIMEOUT_MSCRANE_DOMAINDATA_DIRENCRYPTION_KEYGRAPH_CLIENT_IDGRAPH_CLIENT_SECRETGRAPH_TENANT_IDHOSTLOG_LEVELPORTSESSION_DURATION_HOURSSMTP_FROMSMTP_HOSTSMTP_PASSSMTP_PORTSMTP_USERSTAGED_MAX_BYTESSTAGED_TTL_MINTLS_CERT_FILETLS_KEY_FILE[](https://m8ven.ai/mcp/gitayg-appcrane-4mhsl4)