# What the API is

Source: https://modulify.ai/docs/api/overview

Every Modulify tool as an HTTP method, with the same tokens, scopes and workspaces as the MCP server.

The Modulify API is the [MCP server](https://modulify.ai/docs/mcp)'s tool catalog served over plain HTTP. Each tool is one method. You call it with a `POST` to `https://api.modulify.ai/v1/` followed by the method name, send its arguments as a JSON object, and get a JSON answer back.

```bash
curl -X POST https://api.modulify.ai/v1/list_workspaces \
  -H "Authorization: Bearer YOUR_TOKEN"
```

## One catalog, two ways in

MCP is for AI clients such as Claude Code, Claude Desktop and Cursor. The API is for your own code: a script, a server, a scheduled job or an app. Both reach the same 239 methods, and both run every call through the same checks, so a method behaves the same way whichever door it came through.

| | MCP | API |
| --- | --- | --- |
| Who calls it | An AI client | Your code |
| How | The Model Context Protocol at `https://api.modulify.ai/mcp` | `POST https://api.modulify.ai/v1/<method>` |
| Signs in with | An access token | The same access token |
| Answers with | Text written for a model | A JSON envelope and an HTTP status code |
| Long results | Cut at 60,000 characters | Returned in full |

A token works in both places at once. Calls over MCP and calls over the API share one per-minute budget, counted per token. See [Rate limits](https://modulify.ai/docs/api/rate-limits).

## What a token can reach

A token acts as you. It reaches the workspaces you belong to, or only the ones you picked when you created it, and only the methods its scopes allow. Inside a workspace, your role must also hold the **API access** permission. Everything else you could do in the dashboard follows the same rules over the API: plan limits, credit balances, site locks and permissions all apply. See [Authentication](https://modulify.ai/docs/api/authentication).

Modulify records which way each call came in. A deploy hook called through the API shows the source **API** in the hook's call log, an email sent through the API shows **API** in the email history, and site email turned off through the API reads "Turned off through the API", the same way calls over MCP show as coming from MCP.

## What the API does not do

The API covers what the tools cover. A few things stay in the dashboard on purpose:

- Changing a plan, buying credits and anything else that charges a card.
- Deleting a workspace.
- Downloading a backup or a file out of one.

## The other APIs

Two other kinds of address can be called from code. Neither takes an access token.

- **Your site's own APIs.** Code running inside your site reads and writes its file storage, sends email and reads its visitor numbers with a key that belongs to that one site. See the [Storage HTTP API](https://modulify.ai/docs/data/storage-http-api), the [Email HTTP API](https://modulify.ai/docs/automations/email-http-api) and the [Analytics HTTP API](https://modulify.ai/docs/grow/analytics-http-api).
- **Deploy hooks.** A deploy hook is a secret address that publishes one site when anything calls it. See [Deploy hooks](https://modulify.ai/docs/automations/deploy-hooks).

Use those from the site's code or a build service. Use the API when your code acts for you across your workspaces.

## Next

- [Quick start](https://modulify.ai/docs/api/quick-start) for a first working call.
- [All methods](https://modulify.ai/docs/api/methods) for the full catalog.