Modulify

New features, improvements and fixes, newest first.

fixed

Affiliate stats match what a payout pays

Active Referrals and Est. Payout now count only the referrals that are paying right now, with the same rule a payout uses. They go down when a referral cancels or falls overdue and come back when it pays again.

Referral numbers you can trust

Active Referrals and Est. Payout used to go up when a referral started paying and never come down. Payouts already skipped canceled and overdue workspaces, so the cards could show more than a payout paid.

  • Both cards now count your referrals as they stand: a workspace on Starter, Pro or Enterprise whose subscription is neither canceled nor overdue.
  • A referral drops out as soon as a payment fails or it is canceled, even when it is only set to end at the close of its billing period. It counts again if its payment recovers or the plan is resumed before it ends.
  • A referred workspace never counts more than once.
  • Est. Payout is what a payout raised today would come to.
  • The cards refresh about every 10 seconds while the page is open.
  • Canceled and overdue referrals stay in your list with their badge.

See Affiliates and Referrals and payouts.

improved

Chat drafts follow you across devices

Whatever you leave unsent in a project's chat box is saved as you type and waits for you on any device.

Your draft waits for you

Text you leave unsent in a project's chat box is saved as you type, together with its chips, finished attachments and any log or error you referenced. Close the tab or open the project on another device and it is still in the box. Only you see your draft, and sending or clearing the message clears it everywhere.

See Send a message.

improved

Chat keeps working through drops and updates

A chat run now carries on through a dropped connection or an update to Modulify instead of failing halfway.

Runs that finish

A run no longer fails when the link to your preview drops for a moment or when Modulify is updated while it works. It picks up where it was and finishes. Close the tab or lose your connection and the run keeps going too, and when you come back the reply shows everything it did in the meantime. A preview that falls behind an update restarts on its own.

See Leave while it runs.

improved

CMS files live in a managed Storage folder

Images and files you upload in the CMS live in a managed CMS folder in Storage and are deleted with the items that use them.

Files that follow their items

The CMS folder in Storage now belongs to the CMS. You can browse, preview and download its files as before, but they can no longer be moved, renamed or deleted by hand, so a page never loses an image by accident. When you replace a file, delete an item or clear a collection, the files nothing uses anymore are removed for you, and every image and file field shows where its file is saved in Storage.

See The CMS folder.

improved

Faster sign in and dashboard

Signing in, the dashboard and your project list now load sooner, and the first visit downloads less.

Quicker from sign in to your projects

Signing in no longer waits for your profile picture to be imported, and requests sent at the same moment now share one check of your session. Your projects and folders start loading as soon as you are signed in, and the project list runs its lookups together instead of one after another. The first visit downloads less, because each page loads only the code and icons it uses and fonts start loading with the page.

improved

MCP docs get their own tab, with a page for every tool

The docs now have an MCP tab, where every MCP tool has its own page with the scope it needs, whether it changes anything, and every input it takes.

A tab of its own

The documentation opens on the product guides under Docs, and everything about connecting an AI client now lives under the new MCP tab, at modulify.ai/docs/mcp.

A page for every tool

Each MCP tool has its own page. The top of the page shows the scope a token needs before a client can see the tool, and whether the tool only reads, makes changes or is destructive. Below that, a table lists every input the tool takes, with its type, whether it is required and what it means.

The sidebar groups the tools by area, from workspaces and sites to emails, storage and analytics, and All tools lists every one of them on a single page. Wherever the docs name a tool, the name links to its page.

removed

MCP tools drop the model and effort arguments

create_site, send_message and edit_queued_message no longer take model or effort. Both were already ignored, because Modulify sizes every message for you.

Two arguments gone

The model and effort arguments on create_site, send_message and edit_queued_message had been accepted and ignored since Modulify started sizing every message itself. They are now gone from the tools.

  • An AI client that reads the tool list sees the current arguments and stops sending them.
  • A call that still sends either one is refused with The "model" argument is not accepted by this tool! (or the same for effort), so drop them from any script that calls these tools directly.

See MCP tools and Models and effort.

changedfixed

Pictures and clips cost less

Generated pictures and clips now cost about a quarter fewer credits, edits are priced for the picture they read, and the Seedream, FLUX.2, Ideogram, Seedance 1.5 Pro and LTX models render reliably.

About a quarter cheaper

Every generated picture and clip now costs about a quarter fewer credits than before, on every model and plan. The default picture, Gemini 3.1 Flash Image at 2K, is 0.61 credits on Starter and 0.31 on Pro, and the default clip, 4 seconds at 720p on Veo 3.1 Lite, is 1.20 and 0.60. Preferences lists every price.

Edits priced for what they read

Some models also charge for reading the picture you edit, so an edit on those now costs a little more than a new picture. The gap is biggest on FLUX.2 Pro, where an edit is 0.27 credits on Starter at 1K and 0.81 at 2K, and on GPT Image 1.5, where a wide edit is 1.57. Gemini 3.1 Flash Image and Seedream 4.5 still edit at the same price as they generate. The price line under Image model shows the edit price whenever it differs.

Ideogram 3 Turbo makes new pictures but cannot edit one, so a site set to it now makes its edits with Gemini 3.1 Flash Image, and the price line says so.

Models that now render

Pictures from Seedream 4.5, FLUX.2 Pro, FLUX.2 Klein and Ideogram 3 Turbo, and clips from Seedance 1.5 Pro and LTX 2.5 Fast, could fail and come back refunded. They now render. Seedance 1.5 Pro makes 720p clips only, so its resolution row offers 720p alone. A 21

request on FLUX.2 Pro or Ideogram 3 Turbo, which have no 21
, comes back at the nearest shape they offer.

added

Call every MCP tool over plain HTTP

Every tool of the MCP server is now also a plain HTTP method, so your own scripts and backends can work on your sites with the same access tokens, no MCP client needed.

One request per tool

Send POST https://api.modulify.ai/v1/<tool> with the tool's inputs as a JSON object and your token in the Authorization header as Bearer followed by the token. A token reaches exactly what it reaches over MCP: the same scopes, the same workspaces and the same permissions.

curl -X POST https://api.modulify.ai/v1/list_workspaces \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

Every answer is the same JSON envelope with success, message, data, code and version, plus count on tools that list things, and a refusal comes back with a real HTTP status code.

Built for scripts

  • GET /v1/tools lists the tools a token can use, with the inputs each one takes.
  • GET /v1/token tells you which token you are using, what it can do and when it expires.
  • GET /v1/openapi.json describes every method in OpenAPI, ready for Postman or a code generator. It needs no token.
  • Send an Idempotency-Key header, and retrying a request that already succeeded returns its first answer instead of running the tool again.
  • Every call answers with an X-Request-Id, and the X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers show how much of the token's per-minute budget is left. MCP and the API share that budget.

Where you see it

The Connecting a client panel on the Tokens page has a new HTTP API tab with a first call to copy. Calls made through the API are marked API in the deploy hook call log and under Sent by on an email, next to MCP.

See HTTP API.

improved

Redirects in the preview open in a new tab

A page that redirects to another site no longer takes over the preview. The other site opens in a new tab, and if the frame ever ends up elsewhere, one click brings it back.

The preview stays on your site

Links to other sites already opened in a new tab. Now everything else that sends the page somewhere else does too, and the frame stays where it was.

  • A button or script that redirects to another site straight after your click opens it in a new tab.
  • A form that sends its answers to another service sends them in a new tab.
  • A redirect the page starts on its own, for example while it loads, leaves the frame alone and shows This page tried to open example.com above it, with an Open button.
  • A route that redirects to another site from the server shows a small page with the status code, the route and the address, which opens in a new tab when you click it.
  • A redirect to localhost goes to the same path of your preview instead of a page that cannot load.

Getting back

If the frame still ends up on another site, the pill above it reads This page is outside the site. Back to site loads the last page of your site again, and Refresh now does the same instead of doing nothing.

See Links and redirects to other sites.

addedimproved

Tables and code blocks in rich text fields

Rich text fields in the CMS now hold tables you edit cell by cell and code blocks with a language. On your site they start plain, ready for you to style in chat or in code.

Tables

The new table button in a rich text field's toolbar inserts a table with a header row. Tab moves from cell to cell and adds a row from the last one, and a toolbar at the table's edge inserts and deletes rows and columns, turns the header row on or off and deletes the table.

Code blocks

The code block button now keeps your code in one block. Enter starts a new line, Tab and Shift + Tab indent and outdent the lines you select, pasted code keeps its line breaks and indentation, and a menu in the block's corner sets its language, from Bash to YAML. Code now shows in a monospace font while you edit.

Code saved with the old button, which split every line into its own block, now opens as a single block. Code blocks and tables never merge with the text around them when you press Backspace or Delete next to one.

Toolbar

Every toolbar button now shows its name when you hover it, and a button that is switched off says why, for example inside a code block or a table. Cmd / Ctrl + Z undoes every change in a rich text field, tables and code blocks included, and the redo keys bring it back.

On your site

Tables and code blocks show up plain, with no borders, backgrounds or syntax colors of their own, so they never clash with your design. Give them a look whenever you like: ask in chat, for example for dark code blocks with a copy button or striped tables, or change the one stylesheet all your rich text shares in your own code. The language you pick on a code block is saved with it, ready for syntax highlighting once you add it.

See How they look on your site.

improved

Storage files can now be up to 1 GB

A single file in a site's storage can now be up to 1 GB, up from 100 MB. The Storage panel sends a large file in parts on its own, while uploads sent in one request stay at 100 MB.

Files up to 1 GB

A single file in a site's storage can now be up to 1 GB. Until now every upload stopped at 100 MB.

  • Drop files on the Storage panel or pick them as before. A file over 32 MB now goes up in parts on its own, and its row shows the progress of the whole file.
  • A part that fails on a server error is tried again before the upload gives up, and cancelling a large upload clears away the parts already sent.
  • Chat follows the same 1 GB cap when it puts a file from the site into storage, such as a video it downloads from a link you give it.
  • A file over 1 GB is refused with File too large before anything is sent.

Uploads sent in one request stay at 100 MB

These send the whole file in a single request, so each is still capped at 100 MB:

  • /put on the storage HTTP API, and putObject in your site's storage helper, which calls it.
  • upload_storage_file for a connected AI client.
  • Files and images uploaded in the CMS.

See Storage.

addedchanged

Chat changes your site settings, and answers from the docs

Ask chat to hide the Modulify badge, move the server location, connect a domain, set up a webhook or take the site offline, with the same plan and permission checks as the editor.

Site settings from chat

Chat now changes the site's own settings when you ask, through the same checks the editor applies.

  • Hide or show the Modulify badge, on a paid plan.
  • Move the server location, on a paid plan.
  • Turn visitor analytics collection off or back on, check whether the live site carries the tracking script, and clear the data.
  • Connect a custom domain and its www variant, read you the DNS records or get a one-click setup link, and remove a domain.
  • Add, edit, turn on or off, test and delete webhooks, and clear their delivery log.
  • Take the site offline, stop a running publish, and read the publish history step by step.
  • Add, change and remove CMS items, empty a collection or clear the whole database.
  • Turn skills and connectors on or off for the project.
  • Rename a secret and keep its value.
  • Read, reply to, resolve and reopen comments.
  • Set the top level default for new storage files, read the CDN delivery stats and clear all of storage.
  • Clear the logs and delete all of the deploy hooks, crons and webhooks, and rotate the site's email key.
  • Ask before a publish replaces changes made on GitHub, like the Publish button.

A setting that needs a paid plan is refused on a Free workspace, and chat says so and points you to the Plans page. The badge, the server location and analytics collection reach your live site with the next publish, so chat offers to publish once the change is made. It asks you first before taking the site offline, removing a domain, deleting a webhook or clearing analytics.

Locked sites stay locked in chat

A site that is locked because the workspace is over its plan's site limit now refuses new chat messages, from the editor and from connected AI clients alike, and chat refuses to change its settings.

Answers from the docs

Ask chat how something in Modulify works, where a setting lives or what your plan includes, and it answers from these docs.

The badge toast says what happens next

Flipping Built with Modulify badge in Settings now reads Your next publish removes the Modulify badge from your live site., because the badge only leaves a live site with a publish. Upgrading to a paid plan does not switch it off by itself.

Connected AI clients follow the editor's rules

  • Delete all webhooks, Clear delivery log, Delete all crons, clearing the cron run history, deleting every deploy hook and clearing the deploy hook call log already needed the Delete projects permission in the editor. Connected AI clients now need it too.
  • Taking a site offline is refused while a publish is running or when the site is not published, the same cases in which the Unpublish button is disabled.
  • Connected AI clients gain rename_secret, list_site_skills, set_site_skill, list_site_connectors and set_site_connector.
  • update_site_webhook now changes only the fields you send, so leaving out the type or the name no longer resets them.
  • resolve_comment and reopen_comment leave a thread that is already resolved or open as it is, and refuse a reply or a deleted comment.

SQL that destroys data needs Delete projects

When chat runs SQL that drops a table or a column, truncates a table, deletes rows, or overwrites a column across every row, it now needs the Delete projects permission of the person chatting, the same one clearing a collection asks for. Data the same request saves first does not count, so changing a field's type, filling a new field, removing a language, changing the default language and removing a single CMS item still work for every member. Without it nothing runs and chat says who can do it. See Running SQL.

See Site settings from chat.

addedimproved

Check your email after asking for a sign in link

The sign in panel now waits on a Check your email view after sending the link, with the address, a resend countdown and a way back to fix a typo.

Check your email

Choosing Continue now turns the panel into Check your email, naming the address the link went to, instead of clearing the field.

  • Resend email counts down from 10 seconds after each email.
  • Use a different email goes back to the form with the address filled in.
  • Gmail, Outlook, Yahoo, iCloud and Proton addresses get a button that opens the mail service.
  • Reloading the page keeps the view for up to an hour.
  • The link takes you back to where you were when you asked for it, such as a private project or a workspace invitation, on any device.
  • A link that was already used or has expired says so, with your address ready for a new one.
  • The link works once, for an hour, and one address gets at most five sign in emails an hour.
  • Signing out, or signing in to another account, carries over to every Modulify tab open in that browser.

See Create an account.

addedfixed

Code fields in the CMS

A collection can now hold embed code or custom HTML, CSS and JavaScript in a code field with its own editor and preview, and your site runs it as written.

Code fields

Ask in chat for a code field when an item needs its own embed, such as a booking widget on each event or a video on each post.

  • The field opens in a code editor with HTML, CSS and JavaScript highlighting, line numbers, and undo and redo.
  • Preview runs the code in an isolated frame, without access to your account. YouTube videos and other embeds locked to your site's address only play on your live site.
  • Code that would break itself or your page, such as a <script> tag that is never closed or a <base> tag, is refused with the reason under the field.
  • Your site runs the code as written once the page has loaded, scripts in order, and again when a visitor comes back to the page. Handlers that wait for the page to load, document.write, and posts from X, Instagram and Facebook work on every visit.

See Code fields.

Fixes in the CMS

  • A value that starts with a <script>, an <iframe> or another embed in a field without metadata now opens in the code editor. The rich text editor used to drop those parts as soon as you clicked into the field and out again.
  • Clicking into a rich text field and out again no longer rewrites it, and a rich text field that holds an embed now warns that editing the text removes it.
  • The first letter typed into an empty rich text field no longer sends the cursor back to the start.
  • The rich text editor keeps tables, horizontal rules, subscript and superscript instead of removing them.
  • A field no longer switches to a different editor while you type in it, for example to the color picker when you type a hex value.
  • A value with a line break always gets a textarea, so saving no longer joins its lines.
  • Saving checks only the fields you changed, so an older value in another field no longer blocks the save.
  • Color fields refuse anything that is not a hex color, accept the 4 digit form, and the table shows a swatch next to each color.
  • Multi reference fields now show their linked items in the table. They were blank whenever the collection's ids were text, which every new site uses.
  • An inline SVG stored in an image field now shows as a thumbnail in the table, including one exported with a doctype or a comment at the top.
  • A <name>_alt field now hides only behind an image field that edits it, so it can always be edited.
  • A translated rich text, code, color, image, file or date field keeps its own editor in every language tab.
  • When the AI adds a timestamp field on the newer database, it now gives it a date and time picker instead of a date picker that dropped the time when you edited it.
changed

Credit packs on Free need a paid plan first

A Free workspace can buy credit packs only once its owner has been on a paid plan. Until then it shows its balance with no way to buy more, and subscribing to any plan unlocks packs for good.

Buying credits on Free

Credit packs used to be on sale on Free from the first day. Now a Free workspace can buy them only once its owner has been on a paid plan, on any of their workspaces and at any point.

  • Until then the balance shows on its own. Purchase credits on the Plans page, Top Up in the plan and credits window and Add credits above the chat box do not appear.
  • On your current workspace the plan and credits window reads You are on the free plan. Pick a plan to keep building and unlock credit top ups.
  • Subscribing to any plan unlocks packs, and they stay unlocked after the plan ends. An Enterprise plan counts too.
  • Out of credits messages that used to say top up now name what the workspace can actually do. The Out of AI credits notice in the chat reads No AI credits remaining. Pick a plan to continue. until packs are unlocked, and No AI credits remaining. Pick a plan or add credits to continue. after.
  • Paid plans buy packs exactly as before.

See Buy credits.

changed

Domains pause when a paid plan ends

Custom domains and email domains now need a paid plan to keep working, not only to be added. When the plan ends they are paused, and they come back on their own once the workspace is on a paid plan again.

Custom domains

A custom domain added on a paid plan used to keep serving the site after the plan ended. Now, when the workspace's plan ends and the workspace is on Free, the site's custom domains are paused.

  • The Domain panel shows Custom domains are paused, They stay offline until this workspace is on a paid plan again., with a See plans button. Every domain stays on its card and reads Not serving your site while paused., without its Connected and Primary badges or its records.
  • A visitor to a paused domain gets an error instead of the site. Your free .modulify.website address keeps working, and links to the live site use it instead.
  • Remove still works, and adding a domain again later needs a paid plan.
  • A payment that failed and is still being retried pauses nothing, and neither does a cancellation that is only scheduled.
  • A site moved into a workspace on Free has its custom domains paused the same way.

See When your plan ends.

Email domains

Email domains are paused at the same moment.

  • Email domains on the Settings tab of the Emails tab shows Email domains are paused, "They neither send nor receive until this workspace is on a paid plan again.", with a See plans button, and every domain carries a Paused badge.
  • Email goes out from the site's built-in address, so nothing your site sends is lost, and mail sent to the domains is not forwarded.
  • A paused domain cannot be chosen to send from or have its verification restarted. Remove domain still works.

See When your plan ends.

Back on a paid plan

Nothing is deleted, and no DNS record has to change. Once the workspace is on a paid plan again, both come back on their own: custom domains usually within a minute or two, and email goes out from the sending domain you chose again.

improved

A paused preview no longer covers the editor

When the preview pauses because you were away, a small note at the top of the preview replaces the dialog that covered the whole screen, and your first click or key press starts it again.

Coming back to a paused preview

The preview still pauses after 30 minutes out of sight, or 2 hours with no clicks, typing or scrolling, but the Preview paused dialog over the whole editor is gone.

  • The pill at the top of the preview reads Preview paused while you were away, with a Continue button next to it.
  • The chat and the rest of the editor stay in view. Click anywhere or type, for example in the chat, and the editor reconnects and the preview starts back up.
  • A chat message you send straight away goes out as soon as the editor is connected again.
  • Someone watching your live preview through a read-only link gets the same note.

See When you step away.

added

Today is back in every date picker

Every date picker now offers Today, from midnight UTC up to now, above Last day. The analytics HTTP API, the MCP tools and the site's analytics helper take it as day.

Today

The date pickers on the Analytics tab, the Insights and log tabs of Emails, Webhooks and Deploy hooks, the CDN numbers in Storage and the Usage tab of the Plans page now start their list with Today.

  • Today runs from midnight UTC up to now, and its charts draw one bar per hour.
  • Last day is still the default and still covers the last 24 hours.
  • The analytics HTTP API, the MCP tools and the @/lib/modulify/analytics helper take it as day.

See Analytics.

removedaddedchanged

Several custom domains on one site

A site can now have up to 10 custom domains, each with its own www variant and its own one-click setup, and links to the live site use the primary one.

Up to 10 domains on one site

The Custom Domain field in the Domain panel now stays at the top however many domains the site has, so a second domain connects exactly like the first. A site can have up to 10, and every connected one serves the same site. Each domain gets its own card headed Your custom domain, with its own records, its own Connected badge and its own Remove button.

  • At 10 domains the field, Connect and Verify & Connect are disabled, and adding one more is refused with A site can have up to 10 custom domains!
  • A hostname belongs to one site only. Adding one this site already has, as a domain or as a www variant, is refused with example.com is already connected to this site!, and one another site has with example.com is already connected to another site!
  • Site already has a custom domain! is gone. To move to a new domain, connect it next to the old one and remove the old one once the new one reads Connected.
  • Removing a domain never touches the others. When the site has other domains, the dialog reads Your site will stop working at example.com. Your other domains keep working.

The primary domain

The primary is the domain under Your custom domain on the first card, in the order you added them, where that domain is connected. While none of those is connected, the first connected hostname in a WWW variant or Root domain row is the primary instead. The primary carries a Primary badge. Under Your custom domain, the primary reads Links to your live site use this domain. and every other connected domain reads Your site also answers on this domain. Copy Published App Link, Open Published Project, the Custom Domain row of the publish popover, a template's preview link and the redirect hint on the free subdomain all use the primary.

www variants and one-click setup for each domain

Every root domain carries its own WWW variant row, with Add www or Add root, and its own Ask AI hint for picking one canonical address between the two. Removing a root that has a www variant keeps that domain's card with the www hostname in its place, and no other domain changes.

  • When a card's www variant or root already sits on another card of the site, its Add www or Add root button is disabled and the row reads, for example, www.example.com is already connected to this site.
  • On a free workspace Connect, Add www, Add root and Verify & Connect are disabled, with the tooltip A paid plan is required to add a custom domain.
  • One-click setup is now a Connect with button at the top of each domain's card, since each domain can sit with a different DNS provider. It writes the records of that domain and its www variant.
  • The panel checks every domain when you open it, then keeps re-checking each domain that is not fully connected, up to 120 checks per domain.

AI clients, webhooks and the rest of Modulify

  • The custom domain tools take a domainId, the _id that get_domain_status and add_custom_domain return. It is required by remove_custom_domain, add_www_domain, remove_www_domain and get_domain_connect_url, and get_domain_status checks one domain with it or every domain without it.
  • The domain tools return a domains list in place of the flat domain, isConnected, requiredDnsRecords, wwwDomain, wwwIsConnected and wwwRequiredDnsRecords fields, and the ones that change a domain return the site's full list. get_domain_status no longer returns the top-level isCloudflare and domainConnect: read each entry's IsCloudflare and DomainConnect in domains instead. get_publish_status returns domains too, with customDomain set to the primary domain, and its wwwDomain is gone: read each domain's WwwDomain in domains instead.
  • add_custom_domain and start_domain_verification now refuse a value with http:// or https://, a path, or fewer than 4 or more than 253 characters, with the same messages as the Custom Domain field.
  • A webhook's project.customDomain is now the primary domain, and null while no domain is connected. The new project.domains lists every connected hostname, primary first.
  • Email domains suggests the primary domain, and forwarding confirms an address at any of the site's connected domains straight away.
  • Project search matches every domain of a site and every www variant.

See Connect a custom domain and www and apex domains.

improved

Block a whole domain from your site's email

Blocked addresses now take a whole domain too, so your site never emails any address at it.

Block a domain

Blocked addresses on the Settings tab of the Emails tab now takes a domain such as example.com as well as an address. Your site skips every address at exactly that domain on every later email, and the domain shows in the list as *@example.com. Unblock in its menu lets the site email it again.

  • Chat and a connected AI client can block a domain too.

See Blocked addresses.

improved

Connect an email domain in place

Email domains now connect right in the Emails tab, the same way a custom domain does, with no dialog.

Connect a domain

Email domains on the Settings tab of the Emails tab now starts with Connect a domain. Type the domain, or keep the site's custom domain it starts with, and click Connect, or press Enter. Send from this domain once it is verified sits right under the field. The domain then joins the list below with its DNS records and, when your DNS host supports it, a Connect with button for one-click setup.

  • The Add domain button and its dialog are gone.

See Use your own domain.

removedaddedchanged

Forward a site's mail to several addresses

A site can now forward its mail to up to 5 confirmed addresses, chat and AI clients can manage them, and forwarding no longer pauses on its own.

Up to 5 forwarding addresses

Forwarding on the Settings tab of the Emails tab now lists the addresses a site's mail goes to, up to 5, and every verified address gets each forwarded email. Every site starts with the workspace owner's account email on the list, confirmed straight away when the owner's sign-in confirms that address. When the site changes workspace, its list starts over with the new owner's account email, so nobody from the previous workspace keeps getting its mail.

  • Add address sends a confirmation link to the new address straight away, and it shows Link sent until someone opens the link. The link works for 7 days, the address shows Link expired after that, and Send link again sends a new one.
  • Your own account email when your sign-in confirms it, through a verified email or a Google or GitHub sign-in, and an address at the site's connected custom domain or one of its verified email domains, is confirmed straight away.
  • The page the link opens has Stop forwarding to me, so a person who did not ask for the mail can stop it, and the site cannot add their address again.
  • Adding, removing and sending links again need the Delete projects permission.

No more pauses

Forwarding no longer pauses when forwards bounce or get marked as spam, and nothing emails you about it. An address whose forwards bounce for good, or that marks a forward as spam, is taken off the list on its own, and while no address is confirmed, mail sent to the site is dropped.

  • The forwarding limit that counted every forward to the workspace owner now counts each forwarding address, at 100 an hour and 500 a day across every site it gets mail from.
  • Confirmation links have limits of their own: 1 a minute to an address from the same site, 5 a day to one address, 20 a day for one site and 50 a day for one workspace. A workspace can try 30 adds an hour.

From chat and AI clients

Chat and a connected AI client can now turn forwarding on or off, add and remove forwarding addresses and send a link again, with the Delete projects permission. They ask you first before turning forwarding off or removing an address. See What the AI can do.

See Forwarding addresses.

added

Archive projects

Every workspace now has an Archive, where projects you are not working on wait off your lists without being deleted, still live and still on your plan, until you unarchive them.

Clear a project off your lists

Archive is a new item in a project's card menu, in its right click menu, in the project menu inside the editor and on the selection bar. An archived project leaves My projects on Home, the projects page and its search results, and every folder page. A project that is not published is archived at once.

The Archive

Open the caret next to Projects in the sidebar and Archive is the first entry in the folder list, with its own archive box icon. Drag it among your folders to move it. It opens /dashboard/archive, with its own search and sort that look only through archived projects. The Archive is not a folder: it never shows in the Move to Folder dialog and does not count toward the 50 folders. On the projects page it gets its own card among the folder cards, with thumbnails of what is inside. In the sidebar, hovering it or a folder swaps the icon for a drag handle when you can reorder.

Bring it back

Unarchive sits where Archive was, on the card, in the editor and on the selection bar. A project that was in a folder goes back into that folder when it still exists, and otherwise into your projects list. Moving an archived project into a folder, moving it to another workspace or transferring it also takes it out of the Archive, and a duplicate of one is never archived.

Unpublish in the same step

Archiving a published project asks first. The confirmation carries an unticked Also unpublish this site checkbox, or Also unpublish the N live sites for several, and ticking it takes the live address offline as well. Leave it unticked and the site stays live.

Still on your plan

An archived project still counts toward your site limit, is billed the same and still takes part in locking. It keeps running, and you can still open, edit, publish, duplicate, transfer, move or delete it. Archiving does not free a slot.

From MCP

archive_sites and unarchive_sites archive and bring back up to 200 sites at a time with the sites:write scope, and list_sites takes archived to list the archived ones. Archiving over MCP never unpublishes a site; unpublish_site still needs publish:write. A connected AI client gets 2 new tools, bringing the server to 215.

See Archive projects.

addedchanged

Bigger email allowances and a credit usage tab

Starter now includes 10,000 emails per site a month, Pro 30,000 and Enterprise 50,000, extra emails cost credits per 2,000, sending pauses cleanly when credits run out, and a new Usage tab shows exactly where your credits went.

Included emails per plan

Each site's included emails cost no credits, and the allowance now follows the plan: 50 a month on Free, 10,000 on Starter, 30,000 on Pro and 50,000 on Enterprise. The plan cards list it as a feature, for example 10,000 emails a month per site.

Past the included emails, a paid plan keeps sending and each further block of 2,000 costs 8 credits on Starter and Enterprise and 4 credits on Pro. Free still stops at its limit. See Emails.

  • Sends left over from a block you bought carry over to the next month instead of expiring.
  • Moving to a smaller plan during the month keeps the bigger allowance until the month ends, so emails already sent never turn into a charge.

When credits run out

When a site needs a new block and the workspace does not have the credits, sending pauses for that site instead of failing quietly. The Emails tab says so, counts the emails refused since then and offers Add credits, the workspace owner gets an email, and sending picks up again on its own with the next email once credits are added. While a site is close to that point, the tab warns you first with Sending will pause soon. See When the workspace runs out of credits.

Credits spent on email

The Insights and History tabs of a site's Emails tab now both switch between Sending, Opens and clicks and Credits, with the same date picker as the Analytics tab, starting at Last day. Insights draws each one over the period you pick, including the credits spent and the extra emails they bought. History lists each one in full with its own filters: every email the site sent, the tracked emails sorted by newest, most opens or most clicks and searchable by recipient or clicked link, and every block of extra emails the site unlocked, by type. See Credits spent on email.

No more Refresh buttons

Lists and insights across the editor now keep themselves up to date while they are open, so the Refresh buttons are gone.

One date picker everywhere

The Insights and log tabs of Webhooks and Deploy hooks, the CDN numbers in Storage and the new Usage tab all use the date picker from the Analytics tab, starting at Last day, and their charts draw hours, days or months to fit the period. The delivery and call logs follow the period you pick too.

Every picker offers the same choices: Last day, Last week, Last month, Last 3 months, Last year, All time and Custom range, and each one covers the same window wherever you pick it. Last day is the last 24 hours and replaces Today, Last week, Last month and Last 3 months count today, and Last year is this month and the 11 before it, on the Analytics tab too. Last 3 months is new, and Month to date and Last 6 months are gone. The Analytics HTTP API takes the matching periods, 24h, 7d, 30d, 90d, 12mo and all, and so do get_site_email_stats, get_webhook_delivery_stats, get_deploy_hook_call_stats, get_workspace_credit_usage and get_storage_info, which now take period, from and to in place of a number of days.

History kept until you clear it

Email history, webhook deliveries, deploy hook calls and credit charges are no longer deleted after 30 days, 90 days or two years. They stay until you remove them or clear the log, and anything removed or cleared is erased for good 30 days later. See Limits and quotas.

See where your credits went

The Plans page has a new Usage tab. It splits what the workspace spent in the period you pick into building, images, videos and emails, draws it over time, ranks the sites that spent the most, and lists every charge and refund with its site and time. Every member of the workspace can open it. See See where your credits went.

A connected AI client reads the same figures through get_workspace_credit_usage and the individual charges through the new list_workspace_credit_activity.

added

Email from your own domain

On a paid plan, a site can now send its email from a domain you own, such as [email protected], and receive the mail sent to that domain, with every DNS record to add shown in the Emails tab.

Your domain on every email

The Settings tab of the Emails tab gains Email domains, right under Sender. Add a domain you own, or a subdomain such as mail.example.com, and once it is verified your site's email goes out from it, for example [email protected] instead of [email protected]. A site can have up to 3 email domains, and the built-in address keeps working the whole time. Adding one needs a paid plan and the Manage domains permission, and a domain added on a paid plan keeps working after a downgrade.

Add it, then add the records

Add domain opens Add email domain, filled in with the site's custom domain when it has one. The domain then lists the records to add at its DNS host, with names relative to the zone: an ownership TXT record at _modulify-email that stays in place, three CNAME records for sending, and a recommended DMARC record, which a subdomain can inherit from its parent domain. Each record shows whether it was found. Modulify keeps checking on its own, every 15 seconds while the tab is open, and the domain turns Verified once the mail provider confirms it, which can take up to 72 hours.

  • With Send from this domain once it is verified ticked, the site switches to the domain on its own the first time it is verified, unless another of your domains is chosen as the sending domain by then.
  • Once a domain is verified, Sending address in Sender becomes a menu of the built-in domain and every verified domain, and switching saves at once.
  • A reply to an address on your domain reaches that domain's own mailboxes unless you set a reply-to or turn on receiving.

Receive mail at your domain

A verified domain has a Receive mail switch. With it on and the domain's MX record pointed where the tab shows, mail to any address at that domain is forwarded to the workspace owner exactly like mail to the built-in address, with the same switch, limits and checks. Turning it on needs the Delete projects permission and asks first, because pointing the MX record here moves all of that domain's mail away from the mailboxes that get it today. A subdomain leaves those mailboxes alone.

  • Receiving cannot be turned on for the domain the workspace owner's own address is at, since forwarding to it would loop, and Forwarding warns when such a loop exists.

When something breaks

A domain whose records stop working reads Not working, and until it is verified again the site's email goes out from its built-in address instead, so nothing is lost, while the Emails tab says so. An email the mail provider refuses because the domain is no longer verified is sent again from the built-in address straight away. Restart verification sets a domain up again when its sending records failed to verify, and Remove domain takes a domain off the site, which goes back to its built-in address if it sent from that domain.

One site per domain

A domain sends and receives for one site at a time. Adding it to another site moves it there once that site's own ownership record is found: the first site stops sending from it and receiving its mail, and receiving starts off on the new site. A site moved or transferred to another workspace loses its email domains, and the new workspace adds them again.

From chat and MCP

Chat reads each domain's status, which one the site sends from, which ones receive mail and where replies go, and points you to Email domains to make changes. A connected AI client gets 6 new tools, bringing the server to 222: add_site_email_domain, check_site_email_domain, remove_site_email_domain, set_site_email_sending_domain, set_site_email_domain_receiving and restart_site_email_domain_verification.

See Use your own domain.

improved

Suggestions written for each run

The chips above the chat box are now written for the run that just finished, proposing a security check, the missing piece, an improvement or the next feature, in the language you write in.

Written for what was just built

The Suggestions row above the chat box used to pick from a short fixed list of Modulify steps, such as Publish your site. It now reads what you asked for, what the AI says it did, the files it changed and your recent messages, and writes up to 3 chips for that work:

  • A security check of the exact feature when the run built or changed sign-in, accounts, an admin or private page, a form, payments, stored data, file uploads, API keys, emails or webhooks, asking for anything it finds to be fixed.
  • The missing piece, such as password reset after a sign-in form, or somewhere a contact form's messages end up.
  • An improvement to what was just built, such as how it works on phones.
  • The next feature, with the step the AI offered at the end of its reply put first.

These chips come in the language you write in, leave out what the AI already did or could not do, and never repeat the previous run's chips word for word. When the AI ends by asking you for something, the row stays empty so the answer is yours to type.

Modulify steps are still checked

One more chip can still be a step in Modulify itself, such as publishing your latest changes or using an app you connected, and it is checked against your project before it shows. Clicking any chip only writes it into the chat box, so nothing is sent or charged until you press send.

See Site chat.

added

Email forwarding

Mail sent to any address at your site's email domain is now forwarded to the workspace owner, with spam and viruses kept out.

Mail to your site reaches its owner

Every address at your site's sending domain now accepts mail. That includes the sending address, so a reply to one of your site's emails is forwarded when no reply-to is set, and any other name in front of the @, such as hello or bookings, with nothing to set up. Modulify forwards each email to the workspace owner's account email and to nobody else. Forwarding is on for every site, and it keeps running while sending is off.

What a forward looks like

A forward comes from a Modulify forwarding address, with the sender shown as, for example, Jane Doe via Lisbon Pottery. Its reply-to is the original email's reply-to, or the original sender when it had none, so replying answers the right person, from the owner's own mailbox and address.

  • Every original sender gets a forwarding address of their own, so blocking one in your mail app blocks only that sender, while Forward incoming mail still stops all of the site's forwarded mail.
  • A forward keeps a link to the original message, so replies thread with the original conversation, and a reply sent to the forwarding address itself is not delivered anywhere.

Kept out, held back

Viruses, spam, forged senders, automatic replies, bounce reports and loops are dropped and never forwarded, and so are emails over 25 MB and emails the mail provider refuses. Past 10 forwards an hour from one sender domain to one site, 30 an hour or 200 a day for one site, or 100 an hour or 500 a day for one owner, mail waits and is tried again every 10 minutes, oldest first, for up to 6 days.

  • At large shared mail providers such as Gmail and Outlook, the sender limit counts each address on its own, and mail from the site's own sending address, such as a contact form notification, has no sender limit.
  • Modulify also caps how many emails it forwards across the whole platform each hour and each day.
  • Mail that arrives while Modulify is briefly unreachable is picked up and forwarded once it is back, as long as that is within 6 days of its arrival.

Turn it off and on

The Settings tab of the Emails tab gains Forwarding, with its Forward incoming mail switch. Turning forwarding on or off needs the Delete projects permission. Forwarding pauses on its own when the owner's address does not exist or is on the mail provider's suppression list, or when forwards keep bouncing or the owner marks one as spam, until someone turns it back on. While forwarding is off or paused, mail that arrives and mail still waiting to be forwarded are dropped and never forwarded later.

  • A paused site shows Forwarding paused since on the Emails tab too, with Turn forwarding back on.
  • Turning forwarding off also stops a forward that is being processed but not sent yet.

From chat and MCP

Chat and a connected AI client can tell you whether forwarding is on, off, paused or not set up. Turning it on or off stays in the Emails tab.

See Forwarding.

added

Inspect any element in your preview

A new Inspect tool shows the fonts, colors, spacing and images of anything in your preview, checks the page for common problems, and hands the fixes to chat.

Hover to read any element

The toolbar at the bottom of the preview has a new button with four corner brackets. Turn it on and the chat column becomes the inspector. Hovering outlines an element in blue with its name, as selecting does, shades its margin, border, padding and content, and shows a card with its font, colors, spacing, radius and layout. Gaps between children are hatched, and a gap that differs from the rest turns orange. The arrow keys, Tab, Space and Enter move, freeze and select the highlight. See Inspect a page.

Every detail, ready to copy

Click an element to see its typography with a contrast rating, every color it uses, a box model diagram, its image details, layout, effects, classes and CSS. Click any value to copy it. Hover a second element to measure the distance between them in red.

Colors, fonts and assets on the page

The Colors tab lists every color on the page with where it is used, plus your color variables, and an eyedropper, Pick a color from the screen, adds any pixel on the screen in Chrome and Edge. Fonts lists each family and text style, and Assets collects every image, icon, background and video with Download and Copy URL. Click any of them to outline where it appears.

Check the page and fix it with AI

The Checks tab finds low contrast text, images much larger than they are shown, images with no alt attribute, and uneven spacing in rows of items. Each issue has Fix with AI, which opens chat with a prompt describing the problem and the affected elements attached, ready for you to send. See Check the page.

Compare two elements

Pin to compare on one element, then select another, and a Compare section lists only the properties that differ, side by side. See Compare two elements.

On tablets

Tap an element to select it, and tap Measure to measure the distance to the next element you tap. Inspect is not offered on phones, and opening a link to it on a phone shows Inspect needs a wider screen.

added

Emails

Every site can now send transactional email from its own address, with a monthly allowance, delivery status for every recipient, a full history with each email's content, open and click tracking, and full control from chat and MCP, including sending an email you ask for.

Your site can send email

A contact form notification, an order receipt, a password reset link: your site calls a helper and Modulify hands the message to a mail provider. There is no mail service to sign up for, no API key to paste in and nothing to set up in DNS. Every site sends from its own address on its own subdomain, such as [email protected], and the part in front of the @ is yours to change. This is outbound only: the address has no inbox, so set a reply-to that points at a mailbox somebody reads.

Where to find it

The new Emails tab sits behind More, right after Crons, with Emails, Insights, History and Settings tabs. Sending is on from the start: the preview can send the next time it starts, and the live site once you publish again, which the tab reminds you of until you have. The switch turns it off for the whole site. Settings holds the sender name, the sending address, the reply-to, open and click tracking, the email key, the blocked addresses, and exporting or clearing the history.

Every recipient, every email

A message has a status, and so does every recipient on it, so one email to three people can read Partly delivered when one address bounced. Click any row in History to open the email: who it went to and how each recipient fared, a timeline of every delivery event with its own time, its tags, attachment names and header names, and a preview of its HTML and text, with scripts switched off. The first 200,000 characters of each body are kept for the 30 days the history lasts. History filters by status and searches by recipient, and refreshes itself as delivery news arrives.

Opens and clicks

Track opens and clicks on the Settings tab is on from the start: every new email gets an invisible tracking image, and its links go through a tracking address, so History shows each email's opens and clicks, the email itself lists every clicked link, and Insights adds an open rate, a click rate, a daily chart and the most clicked links. Turn it off there and emails sent from then on go out untracked. Opens are approximate, because some mail apps load images automatically and others block them, and both count for the whole email rather than for one recipient. Add ses:no-track to a link to leave it out, and tell your recipients about tracking, for example in your privacy policy. See Track opens and clicks.

From your site's code

Sites built from the Modulify starter ship with a server only helper at src/lib/modulify/email, and EMAIL_URL and EMAIL_PRIVATE_KEY join the managed secrets your site already carries. sendEmail takes to, cc, bcc, a subject, HTML and text, a reply-to and a sender name for one message, up to 10 attachments totalling 7 MB, custom X- headers including List-Unsubscribe, tags, and an idempotency key that makes a retry safe. getEmail reads a sent email back with every recipient's status, listEmails pages through the history and getEmailQuota returns the allowance and every limit. A refusal throws an EmailError with a machine readable code and a retryable flag. The same four endpoints answer a plain POST with an X-Email-Key header, so anything that can call a URL can send. See Email HTTP API.

What it costs

A recipient is a send, so one message to five people uses five. A free workspace gets 100 sends per site per calendar month. A paid plan gets 1,000 included, and past that every further block of 1,000 sends costs 10 AI credits, charged automatically the moment a send needs the block; with no credits left, sending stops until the 1st. A message carries at most 50 recipients, and a site sends to at most 60 recipients a minute.

Bounces and spam reports

An address that hard bounces, or whose owner marks the email as spam, is added to the site's blocked list and skipped on every later message, and you can block an address by hand too. A message whose recipients are all blocked is refused outright. Once a site has sent to 50 recipients in a month, at least 5 hard bounces making up more than 10% of them, or at least 3 spam reports making up more than 0.5%, turns sending off on its own, and the tab says which it was. Only the tab can turn it back on, after you confirm.

From chat and MCP

Chat reads the setup, this month's usage and the history, opens any email to say who got it and why not, turns sending on and off, changes the sender, turns open and click tracking on or off when you ask, blocks and unblocks addresses, and sends a test email to your own account address. When you ask it to send a specific email to people you name, it sends that one email from the site's address, counted like any other send. It writes the sending code for your site with the current helper, and it is never handed the email key. A connected AI client gets 12 new tools, bringing the server to 211, including send_site_email and get_site_email.

See Emails.

changed

Large storage backups

A storage backup now archives up to 4 TB of files and 100,000 files and folders instead of 100 MB and 20,000, shows its progress on the row while it is being built, and keeps the reason it failed under an info icon.

Backups of any size

A storage backup used to be refused once the files in your storage passed 100 MB, or 20,000 files and folders. The archive is now written out in pieces while the files are read, never assembled whole first, so a large storage backs up the way a small one does. The limits are now 4 TB of files and 100,000 files and folders per archive. Over either, the row reads Failed with Your storage holds more than 4 TB of files, more than one backup archive can hold! or Your storage holds more than 100000 files and folders, more than one backup archive can hold!, and restoring a whole backup is refused when your current storage holds more than 100,000 files and folders with Your storage holds more than 100000 files and folders, too many to restore over in one go!

A restore no longer reads the whole archive first either. Files are copied back one at a time straight out of the archive, and a file's checksum is checked against the one recorded in the zip whenever the whole file is read, so on a restore and on a download of that one file. A text preview that stops at the first part of a large file is not checked, because only part of the file was read. The daily run keeps its fifteen minutes: a site whose archive is still being written when the time is up keeps archiving in the background and is not started again the next day while it is still running.

Progress on the row

While an archive is being built, the Archiving row shows how far it has got: a percentage and the bytes written so far out of the total, for example 42% · 1.2 GB of 2.9 GB, moving on its own for everyone with the editor open. A backup that sends no progress for 30 minutes is marked Failed with The backup stopped before it finished!, so a large archive that keeps reporting is left to finish.

A failed storage or database backup now keeps its reason under a small info icon right after Failed. Hover or focus the icon to read it. The reason is no longer written out in red along the row.

The archive itself

The zip stores your files without compressing them. One over 4 GB, or with about 65,000 files, uses the ZIP64 form of the format, which the archive tools built into current macOS, Windows and Linux open, while a very old unzip from before ZIP64 cannot open one of those. The index counts as one entry, so the switch happens at 65,535 entries in total. Database backups are unchanged and keep their 100 MB limit.

See Storage backups and Limits and quotas.

addedimproved

More image and video models

Eight new models to pick from in Preferences, four for pictures and four for clips, with every row named after the model and its maker and the list grouped by maker.

Models named, and grouped by maker

The Image model and Video model pickers in Preferences now show every model by its real name, with the maker at the start of the line beneath it, and the rows sit under a heading for each maker. Recommended still sits at the top and still follows whatever Modulify recommends, so a site left on it changes nothing.

Four new image models

Credits are per picture at 1K, Starter first and Pro second, because a Pro credit is worth twice a Starter credit.

  • Seedream 4.5, from ByteDance. Rich heroes and products, cheap. 0.32 credits on Starter and 0.16 on Pro.
  • FLUX.2 Pro, from Black Forest Labs. Photoreal, and cheap. 0.24 credits on Starter and 0.12 on Pro, and 0.60 and 0.30 at 2K.
  • FLUX.2 Klein, from Black Forest Labs. Near free, for drafts. 0.01 credits on either plan, and 0.03 and 0.02 at 2K.
  • Ideogram 3 Turbo, from Ideogram. Best lettering, for logos. 0.24 credits on Starter and 0.12 on Pro.

Seedream 4.5 and Ideogram 3 Turbo come in one size, so the size row greys out for them. The two FLUX.2 models go up to 2K, so a site with a 4K ceiling gets 2K from them. All four follow the aspect ratio exactly, as the two Gemini models do. The two GPT Image models are still the only ones that round to a square, landscape or portrait shape.

Four new video models

Credits are for a 4 second clip at 720p, Starter first and Pro second. Kling 2.5 Turbo comes in 5 or 10 second lengths only, so its price is for a 5 second clip.

  • Seedance 1.5 Pro, from ByteDance. Smooth motion at half the price. 0.83 credits on Starter and 0.42 on Pro.
  • Seedance 1.0 Pro Fast, from ByteDance. The cheapest clips, no sound. 0.69 credits on Starter and 0.35 on Pro.
  • LTX 2.5 Fast, from Lightricks. Loops with sound, cheaply. 0.96 credits on Starter and 0.48 on Pro.
  • Kling 2.5 Turbo, from Kuaishou. Natural motion, no sound. 1.68 credits on Starter and 0.84 on Pro.

Seedance 1.5 Pro goes up to 12 seconds and LTX 2.5 Fast up to 20, where the two Veo models stop at 8. Kling 2.5 Turbo renders 720p only, so the resolution row offers nothing else for it.

Sound changes the price of Seedance 1.5 Pro

On Veo 3.1 Lite, Veo 3.1 and LTX 2.5 Fast the price already includes sound, so Allow sound costs nothing either way. Seedance 1.5 Pro charges twice as much per second with Allow sound on, so the same 4 second 720p clip is 1.66 credits on Starter and 0.83 on Pro. The price beside the model updates the moment you flip the switch. Seedance 1.0 Pro Fast and Kling 2.5 Turbo make silent clips, so the switch greys out on them and the row says so.

See Preferences.

addedimproved

Webhook insights and one look for every chart

Webhooks get an Insights tab with daily delivery counts, deploy hooks split their numbers from their log, and every chart and stat card in the editor now shares one design.

Webhook insights

The Webhooks tab has a new Insights tab, between Webhooks and Deliveries. Four cards count the last 30 days across every endpoint on the site, Deliveries, Delivered, In progress and Failed, above a Deliveries per day chart with one bar per day. In progress is a delivery that is still pending or still being retried, and Failed is one that used up its attempts. A connected AI client gets the same numbers through get_webhook_delivery_stats, bringing the server to 199 tools, and the editor chat now reads them too, so "how many webhooks fired last week?" is answered in chat. See Webhooks.

Deploy hooks, split in two

The cards and the Calls per day chart moved out of the deploy hooks Calls tab into their own Insights tab, so the log is only the log. Chat reads those counts too, alongside the call log it already had. A new hook's URL now starts masked like every other, the reveal and copy buttons sit right after it, and rotating lives in the row's menu. See Deploy hooks.

One look for every chart

The stat cards and chart cards in Analytics, Storage, Deploy hooks and Webhooks are now the same components, so loading, empty and error states read the same everywhere, and a chart that cannot load always offers Try again.

addedimproved

A much bigger connector catalogue

Over a thousand more services to connect, a Setup filter and badge for how each one connects, a quicker route for every database query, and daily storage and database backups.

Connectors

The Connectors catalogue now holds over a thousand services, including Ahrefs, Semrush, Shopify, GitLab, Instagram, QuickBooks, Typeform, Google Search Console, Cloudflare, PostHog and Klaviyo.

Each card carries a One-click or Own key badge, and a Setup filter in the toolbar narrows the list to either. Chat can search the catalogue too, so asking "can you connect Ahrefs?" gets a real answer.

See Connectors.

Databases

Queries from your site to its database now take a faster route. Busy sites no longer slow each other down, and a site under heavy traffic is far less likely to see a query fail. Nothing changes in how you write queries or use the CMS, and no site needs moving.

Backups

Sites on a paid plan keep daily backups of both their storage and their database, alongside the code backups they always had. Back up now takes one on demand, and every backup is downloadable from the Backups tab. See Backups.

addedchanged

Browse and restore storage backups

Open a storage backup to look through and preview its files without downloading it, then restore the whole backup or only the files you pick, with a backup of your current storage taken first whenever something would be overwritten or deleted.

Browse a backup

Browse files on a finished row of the Storage tab of Backups, or a click on the row, opens the backup in a file browser laid out like the Storage panel, with folders, breadcrumbs, the public and private locks and a search across the whole backup. Nothing in it changes your storage, and the backup and folder you are in are part of the page address, so a refresh or the back button keeps your place.

Each file in a folder is checked against your storage as it is now, reading Changed when the file there has a different size and Missing when it is not there at all. View file previews images, video, audio, PDFs and text files, and Download file saves one file without downloading the whole archive. Browsing, previewing and downloading work for every member of the workspace, on every plan.

Restore all of it or part of it

Restore backup makes your storage match the backup exactly: every file in it comes back as public or private the way it was, and files added since are deleted. Restore file, Restore folder and Restore selected put back only what you chose and delete nothing else. Before you confirm, the dialog says how many files will be added back, overwritten and deleted. Files are always written back before anything is deleted, and your live site serves the restored files straight away, with nothing to publish.

Restoring needs a paid plan and the Delete projects permission. It runs in the background, one restore per site, with its progress in the Storage tab of Backups.

A Before restore backup first

Whenever a restore would overwrite or delete a file, Modulify first takes a backup of your whole storage as it stands, listed with a Before restore badge. It does not use one of your ten manual backups, it is kept like a backup you made yourself, and restoring it reverses the restore. If that backup fails, nothing is restored.

While a restore runs

Changes to your storage from the Storage panel, the CMS, chat or a connected AI client are refused until the restore finishes, and so are new storage backups and deleting the backups the restore uses. Your site's own storage calls are not paused. Restored files get a content type worked out from their extension and show the restore as their modified time, and a backup taken in an older format can still only be downloaded.

Chat and a connected AI client can browse and restore a backup as well, in two steps and never on their own initiative, as Browse and restore a storage backup from chat and MCP describes. Database backups are unchanged and still cannot be restored.

A preview in the Storage panel too

View file in the Storage panel now opens the same preview instead of sending the file to a new tab. Images, video, audio, PDFs and text files are shown in the dialog, with Copy link on a public file, Open in new tab and Download file under the preview. A text file shows its first 256 KB and says so, and one larger than 5 MB reads No preview instead. See Previewing a file.

See Restore a storage backup.

added

Browse and restore a storage backup from chat and MCP

Chat and a connected AI client can now look inside a storage backup, say which of its files are missing or changed, read a text file out of it and restore it whole or in part, always showing you the plan and waiting for your yes first.

Chat can look inside a backup

Ask chat what a backup holds and it walks the archive a folder at a time, or searches it by name, and checks every file in it against your storage as it stands now: same, changed when the file is there at a different size, and missing when it is not there at all, the same answers the Changed and Missing badges give in Browse files. It compares sizes rather than contents or visibility, so a file edited to exactly the same length reads same, and so does one that has only been made public or private since. Browsing needs only membership of the workspace and works on every plan.

Ask what a file held and chat reads it out of the archive as text, up to the first 32 KB of one file, and says so when the file is longer instead of reading on. An image, a video, an audio file or a PDF is not read at all: chat names it, gives its size and type, and sends you to Browse files to preview or download it. None of this touches your live storage, and chat still never downloads a backup, or a file out of one, and never hands you a link to one.

Restoring takes two steps, and the first one changes nothing

Ask for a restore and chat reads the plan back to you first: how many files come back, how many of them are already there with different bytes or visibility, how many files are deleted, how many bytes move, and whether a Before restore backup of your current storage is taken first. Nothing is written while it shows you that, and the restore starts only once you say yes in your own words.

If your storage changes between the plan and your yes, the restore is refused with The storage changed since this plan was made, so this confirmation no longer matches. Check the new plan and confirm again! and chat has to put the new numbers in front of you and ask again. A plan left sitting can never restore something other than what you read.

What runs afterwards is the same job the Restore backup button starts. It needs a paid plan and the Delete projects permission, without which chat answers Restoring a storage backup requires a paid plan! or tells you that someone holding the permission has to do it. Only one restore runs per site, so asking for a second is refused with A restore of this storage is already running!, and because the job runs in the background chat follows it and only says your files are back once it reports completed.

Four new MCP tools

A connected AI client gets browse_storage_backup, read_storage_backup_file, restore_storage_backup and get_storage_restore_status, which brings the server to 198 tools. Browsing a backup, reading a file out of one and reading how a restore is going need the data:read scope, while starting a restore needs data:write, which is unticked by default, so a client restores only when you deliberately ticked it. restore_storage_backup is the same two step tool chat uses: the first call answers the plan with started false and changes nothing, and only a second call carrying that plan's confirm value starts the restore.

Database backups are unchanged. They still cannot be browsed or restored by anyone, and downloading a backup of either kind stays yours alone, from Download on its row.

See Backups from chat and MCP and MCP tools.

added

Deploy hooks

Every site can now have secret URLs that start a publish when something calls them, with a call log, a daily chart, and full control from chat and MCP.

Publish from anywhere

A deploy hook is a secret URL that publishes your site when something calls it with a plain GET request, no header or body needed. Point a CI pipeline, a script or a scheduled job at it, and every call builds the latest saved version of the site, exactly like pressing Publish. A hook can make a site's first publish too.

Where to find them

The new Deploy hooks tab sits behind More, right after Webhooks, with Hooks, Calls and Settings tabs, joined by Insights on 18 September. Add deploy hook asks for a name, and when this shipped the new row showed the full URL straight away, with buttons to reveal, copy and rotate it. Since 18 September a new row starts masked like every other, the reveal and copy buttons sit right after the URL, and rotating lives in the row's menu only. A site can hold 10 hooks.

Each row has a switch to turn the hook off without deleting it, and a menu with Trigger now, View calls, Rename, Rotate URL and Delete.

One build at a time

Only one build runs per site. A call that arrives while a build is running starts nothing, queues nothing, and answers 200 with This site is already building, so this call did not start another build., so a scheduled job calling the hook does not count it as a failure. A started build answers 202, a turned off hook 403, an unknown URL 404, a POST, PUT or DELETE request 405, a site that cannot publish 422 with the reason, and more than 10 calls a minute 429 with a Retry-After header.

The call log

The Calls tab counted the last 30 days in four cards, Calls, Builds started, Already building and Rejected, above a Calls per day chart. Since 18 September those sit on their own Insights tab, between Hooks and Calls, and cover every hook on the site. Each call row shows the outcome, the hook, where the call came from, who or what made it, and the state of the build it started. Calls are kept for 30 days, and one can be removed from the log with the trash icon.

A publish a hook started reads by <hook name> in the Publishes tab, or by <first name> via <hook name> when a member started it, and your webhooks receive it with "trigger": "deploy-hook".

From chat and MCP

Chat can list, create, rename, turn on or off, delete and trigger hooks, rotate a URL and read the call log, and asks you before deleting, rotating or triggering. It never shows a hook's URL. A connected AI client gets 14 new tools, bringing the server to 194, with the URL itself behind credentials:reveal and trigger_deploy_hook behind publish:write.

Transferring a project to another person deletes its deploy hooks, because their URLs belong to the previous owner.

See Deploy hooks.

addedchanged

The newer database for every new site

Every site created from now on runs on the newer database, existing databases stay where they are, and sites on the newer database can now be cloned and duplicated with their content.

New sites run on the newer database

Every site created from now on runs on the newer database, the SQLite based engine that database backups cover. A site gets its database the first time it needs one, when you ask chat for something that stores data or a connected AI client calls create_site_database, and it is ready straight away, with no wait for it to start.

Your site reads it with two locked secrets, DATABASE_URL for its address and DATABASE_TOKEN for the token sent with each request. Copy secrets and Download secrets leave both out, and a connected AI client reads them only through get_secret.

Existing databases stay where they are

A site that already has a database on the older database keeps it, along with all of its data, and nothing about how it works changes. A site that never created a database gets the newer database the first time it asks for one, however old it is and however it was made. A clone or duplicate of a site with a database stays on the database the original runs on.

Clone and duplicate sites on the newer database

Sites on the newer database can now be cloned, duplicated and cloned from Templates, and the copy takes the database content with it whenever the copy includes it. Copying the content starts with a snapshot, so the original database pauses for a moment, as it does for a backup.

A copy is refused, with the reason, while the database has a full text search table, and a copy with content is also refused while the database is larger than 25 MB, while it is being backed up, and while another copy is still being made after a minute of waiting. A refused copy leaves no new project behind.

See Site databases and Copying a database.

addedimprovedchanged

Daily backup switches, and backups from chat and MCP

Turn daily storage or database backups off for one site, see who took each backup, and let chat or an AI client list, take, delete and schedule backups.

Turn daily backups off for a site

Storage configuration and CMS settings each have a Daily backups switch in their Backups section. Off stops only the daily backup of that kind for that site: Back up now keeps working and every backup already taken stays, still downloadable and still ageing out as before. The switch is on for every site, including existing ones. While it is off, the matching tab of Backups shows Daily backups are off for this site. with a link back to the switch. On the free plan the switch is disabled with a Paid badge. See Turn daily storage backups off.

Back up now moved into the tab strip

Back up now now sits at the right end of the Code, Storage and Database tabs while Storage or Database is open, with a Paid badge beside it on the free plan. It asks you to confirm first, and the dialog says how many of your ten manual backups will be left.

Rows show who took a backup

A backup someone took by hand starts with their avatar and reads Backup by Sam. A daily one starts with a calendar icon and reads Daily Backup. Every row keeps its Manual or Daily badge, and Archiving, Exporting or Failed now appears as a second badge beside it instead of replacing it.

Delete all moved to the Danger zone

The delete all button under each backups list is gone. Delete all storage backups is now a row in the Danger zone of Storage configuration, and Delete all database backups a row in the Danger zone of CMS settings. Deleting one backup still happens from its row.

Backups from chat and MCP

Chat can now list your storage and database backups, take one, delete one or all of them after asking you, and turn daily backups on or off, except on a site on the older database, where the database switch is refused because there is no daily backup to stop. A connected AI client can do the same through ten new tools, from list_storage_backups to set_database_backup_schedule. Neither can download a backup, and neither could restore one at the time. Restoring a storage backup arrived on 17 September, while a database backup still cannot be restored. See Backups from chat and MCP.

Empty sites are passed over

The daily run passes over a site whose storage holds no files or whose database has no tables without adding a row to its list, and picks the site up once there is something to back up. Back up now on an empty site still leaves a Failed row with the reason.

added

Database backups

Paid plans now back up the database of every site on the newer database once a day, with Back up now for a backup on demand, each one a zip you can download.

Daily backups of your database

On any paid plan, the database of a site on the newer database is now backed up once a day, every table and every row along with its indexes, triggers and views. A day where nothing in the database changed is skipped, so a quiet site does not collect identical copies. Backups are kept outside your storage, so they never count against it. Sites on the older database are not backed up.

Where to find them

The Backups tab behind More now holds three tabs, Code, Storage and a new Database tab. The CMS opens it too: its Settings sub-tab has a Backups section with a View backups button.

Each row reads Exporting while the backup is made, then shows how many tables and rows it holds and how big it is, or Failed with the reason.

Back up now

Back up now takes a backup on demand, up to ten per site in any twenty four hours, separate from your storage backups. Your database pauses for a moment while it is copied, so take one of a busy site at a quiet time. A database larger than 100 MB, or one with a full text search table, is refused with the reason.

Download and delete

Download hands you a .zip holding database.sql, a plain text SQL file written for SQLite that opens in any text editor or loads into a SQLite tool. Delete on a row removes one backup, and Delete all database backups in the Danger zone of CMS settings clears the history, skipping any still exporting. Both need the Delete projects permission.

Backups are thinned as they age, keeping every daily one for a week, one a week for eight weeks and one a month for a year, while manual backups stay the full year and the newest finished backup of a site is always kept.

No restore

Database backups cannot be restored. To get rows back, download a backup that holds them and add the rows again from the CMS or through chat. On the free plan new backups stop, but backups taken while on a paid plan stay listed and downloadable.

See Backups.

added

Storage backups

Paid plans now archive every site's storage once a day, with Back up now for an archive on demand, each one a zip you can download.

Daily archives of your storage

On any paid plan, the files in a site's storage are now archived once a day into a single .zip, public and private files alike. A day where nothing in storage changed is skipped, so a quiet site does not collect identical copies. Archives are kept outside your bucket, so they never count against your storage.

Where to find them

The Backups tab behind More gains a Storage tab beside Code, the code backup history it always showed, with Restore. Storage lists the new archives, and a Database tab for database backups arrived the same day. The Storage panel opens it too: its Configuration sub-tab has a Backups section with a View backups button.

Each row reads Archiving while it is built, then shows how many files it holds and how big it is, or Failed with the reason.

Back up now

Back up now takes an archive on demand, up to ten per site in any twenty four hours. Deleting a manual backup does not give its slot back until twenty four hours after it was taken. One archive held at most 100 MB of files and 20,000 files and folders when this shipped, and a bucket over either was refused with the reason. Since 18 September the limits are 4 TB and 100,000 files and folders.

Download and delete

Download hands you the .zip, with your files split into public/ and private/ folders. Delete on a row removes one archive, and Delete all storage backups in the Danger zone of Storage configuration clears the history, skipping any still being archived. Both need the Delete projects permission.

Archives are thinned as they age, keeping every daily one for a week, one a week for eight weeks and one a month for a year, while manual backups stay the full year and the newest finished archive of a site is always kept.

No restore yet

Storage backups could not be restored when they shipped. To get files back, download an archive that holds them and upload what you need again in the Storage panel. Browsing and restoring one arrived on 17 September, whole or in part, with a Before restore backup taken first. On the free plan the controls carry a Paid badge and new archives stop, but archives taken while on a paid plan stay listed and downloadable.

See Backups.

addedimproved

Import from GitHub, instant toggles and settings polish

Bring a repository in as reference for the AI, ask chat to change your subdomain, and switches that flip instantly everywhere.

Import from GitHub

Import from GitHub is a new entry in the + menu, both on the prompt that starts a new site and inside an existing project's chat. Pick a connected repository or paste a public one, and the AI reads it as reference for whatever you ask it to build next, going back to list or read more of the repository itself whenever it needs to. See Import from GitHub.

Ask chat to change your subdomain

Chat can now rename your free .modulify.website address itself, in plain words, the same way it already renamed the project. It picks one automatically on the first build, and taking a name that is already used just gets a short suffix instead of failing. See Your web address.

Secrets, faster to manage

Add secret opens as a dialog that stays open between saves, so adding several keys in a row no longer means reopening it each time. Once a project holds 8 or more secrets, a search box and a sort dropdown appear above the list. See Secrets.

Instant switches

Every on and off switch in the product now flips the moment you click it and never locks while it saves. That covers crons, webhooks, connectors, the Modulify badge and analytics collection.

Settings pages, tidied

Account and workspace settings now show a short title and description on every section, the same way the Danger zone always has. A site's project category, server location and thumbnail moved into a collapsible Advanced settings section, so the General tab leads with what you actually change day to day.

Connect domain

The button to add a custom domain from the editor now reads Connect domain instead of Upgrade to connect.

removedchanged

Webflow is gone from the dashboard

The Webflow builder, its editor and everything branded around it are removed. Legacy projects stay, and converting them into a Modulify site is the one thing left to do with them.

The Webflow builder is removed

The composer under the prompt no longer offers a second builder. There is one way to start a project and it makes a Modulify site. The Use legacy Webflow builder button, the design system picker and the language picker that came with it are all gone, along with the retired editor route.

Nothing about creating a site changed. The prompt, attachments, voice input and Create blank site all behave exactly as they did.

Legacy projects keep their one job

A project made with the old builder still appears on your dashboard, now marked with a Legacy badge instead of a Webflow one. Its card menu still leads with Convert to Modulify, which rebuilds it as a real Modulify site from the original prompt plus a copy of every page and image as they look today.

Converting still deletes the legacy project once the new site exists, along with its pages, images, backups and publish history. That has not changed and it still cannot be undone.

Copy to Webflow and the old exports are gone

Copying a page or a component into Webflow, the Webflow app authorization dialog and the Figma export that lived beside them are all removed. Publishing, custom domains, code export and the site editor are untouched.

Plans no longer list legacy features

Plan cards dropped the Show legacy Webflow features toggle and the second feature list behind it. Every plan now shows one list, describing what the plan does for sites. No plan changed price, limit or entitlement.

addedchanged

Share and Earn, image animation and suggested next steps

An invite link that pays you in credits, a picture on your site turned into a short looping video, chips proposing what to do next, and legacy Webflow projects rebuilt as real Modulify sites.

Share and Earn

Every account now has an invite link that pays in credits. It is the Modulify address with /invite/ and your code on the end, and it opens from a new Spread the word card at the bottom of the sidebar, reading 5 now, 50 when they pay.

https://modulify.ai/invite/YOURCODE

Your code is created with your account, so there is nothing to apply for. It is 7 characters of uppercase letters and digits, with I, O, 0 and 1 left out of the alphabet entirely so no code is ever misread out loud.

When someone creates an account through your link, their new workspace is given 5 credits and 5 land in your default workspace at the same moment. The first time that person is actually charged, whether that is a new subscription, a renewal or a credit pack, another 50 credits land in your default workspace.

The 50 is paid once per person, not once per payment. Whichever payment they make first earns it and everything after that earns nothing, so inviting more people is the only way to earn more. A plan a discount code takes all the way to $0.00 bills nothing, so it earns nothing, and it does not use up the one reward that person can earn you.

Rewards arrive as top up credits, the same pool a credit pack lands in, so the monthly reset never clears them. They always go to your default workspace, the one carrying the filled star in the switcher, and they are never split across the workspaces you own. You cannot invite yourself, and a person can only ever be invited once.

The window shows the link with a QR code beside it and a Copy link button. Once at least one person has signed up it also reports Signed up, Paid and Credits earned.

The name moved. Share and Earn used to be the sidebar link for the cash affiliate program. That program has not changed, still a 20 percent commission paid to your PayPal address on a referred paid subscription, and it is now reached as Affiliates in the user menu. The two are separate systems with separate codes, and being in one changes nothing about the other.

See Share and Earn and Affiliates.

Turn a picture on your site into a short video

Chat can now animate an image that is already in your site into a 4 second, 720p, silent video that loops. It costs 2 credits.

It is image to video, so there is always a source picture. Point it at a file in the project or a public image URL, and describe the motion rather than the scene, since the still already says what the scene is. Name what should stay still in the same breath.

Animate this hero image. Slow push in, mist drifting across the treeline,
everything else still.

It is off unless you ask for it by name. It spends money and it is rarely the right answer, so it is never suggested and never folded into a broader request. "Make this section feel more alive" gets you design work, not a video. Aspect ratio is 16:9 or 9:16 only, so a square slot wants 16:9 cropped in CSS.

The clip is stored on the CDN rather than in the project, so it does not appear in the File Explorer beside your images. It goes onto the page as a muted looping <video> with the original picture as its poster frame, because browsers refuse to autoplay video with sound. Generation is usually under a minute and can take several. If it fails, nothing is charged.

Most motion on a website should still be CSS. A fade, a slide, a parallax scroll or a hover state is free, stays sharp at any size and adds no page weight. Reach for this when the content of the picture itself needs to move, like drifting mist, rippling water or a flickering flame.

See Images.

Suggestions after a run

When a run finishes, a Suggestions row can now appear above the chat box holding up to 3 short chips proposing something worth doing next.

They are built from the state of your own site rather than from a fixed menu. Add project details when the project has no description, Publish your site when there is a version that is not live yet, Add a database when the site has none, Add another language when it only has one, Schedule a task when it is live with no scheduled jobs, Review your analytics when it is live with analytics installed, Add custom images, and one chip for a connector you have already connected. A turn that stopped before finishing offers Continue where it stopped on its own.

Anything the run just did is dropped before the rest are ranked, and the check runs again every time the panel loads, so a chip you have since acted on is gone when you come back. A chip is never offered for something unavailable on your project, and a connector chip only reaches the person whose account is connected.

Clicking a chip writes that request into the chat box and puts the cursor there. Nothing is sent and no credits are spent until you press send yourself, so you are free to reword it or clear it first.

The row is occasional rather than constant. It stays hidden while a run is going, while a message is waiting in the queue, while a question is waiting on your answer, while a version is being restored, while the preview is still syncing, after a run that failed or was stopped, and when the workspace is out of credits. It clears the moment you send your next message.

See Site chat.

Legacy Webflow projects convert into a Modulify site

A legacy Webflow project can no longer be opened. Its editor route now reads Webflow projects are retired, and clicking the card on the dashboard offers the conversion instead. The card menu leads with Convert to Modulify and drops Open Project, Copy Project Link and Settings, because none of them apply any more.

Converting renders every page that still has components exactly as it looks today, downloads the images those pages reference and rewrites the markup to point at the local copies, packages that as an archive, and starts a brand new AI site from your original prompt plus that archive. So you get real editable components rather than a copy of the old markup. Image copying takes the first 400 distinct URLs and skips any image over 15MB or slower than 20 seconds.

The new site takes a site slot and spends AI credits like any other build, so the conversion is refused when you are already at your site limit or out of credits, and nothing is deleted when it is refused. Once the new site exists the old project, its pages, images and backups are permanently deleted. That is why the confirmation is titled Convert "<name>" to Modulify? and its button reads Convert and delete.

See Projects overview.

addedimproved

Everything in Modulify, from an AI client

The MCP server now reaches the whole product, from the editor and storage to workspaces, your account, direct file writes, SQL, publish diagnostics and exports.

Everything in the editor is now reachable over MCP

A connected AI client could already read your sites, send prompts and publish. It could not create a scheduled job, edit a webhook, read a comment or see a single line of your server logs. That is fixed across the whole editor.

Scheduled jobs. create_site_cron, update_site_cron, delete_site_cron and delete_all_site_crons manage the jobs, and preview_cron_schedule checks a schedule before it is saved so a job cannot be committed firing more often than intended. delete_site_cron_run and clear_site_cron_runs clean the history, and export_site_crons copies a set of jobs between sites.

Webhooks. create_site_webhook, update_site_webhook, delete_site_webhook and delete_all_site_webhooks, plus delete_webhook_delivery and clear_webhook_deliveries for the log.

Environment variables. set_secrets applies a whole .env in one call, creating, replacing and deleting together. set_secret gained the public/plaintext option for NEXT_PUBLIC_ style variables.

Visitor analytics. query_site_analytics answers anything the fixed reports do not: top pages, sources, countries, browsers, operating systems, devices, or a series over time. set_analytics_enabled and clear_site_analytics cover the settings and the danger zone.

The database. create_site_database gives a site a database, list_reference_options and list_enum_options mean a value written to a reference or enum column is no longer a guess, and clear_site_database empties every collection.

Folders. The whole feature, from nothing: create, list, rename, change the slug, reorder, delete, move sites in and out, and move a folder to another workspace.

Comments. Also from nothing. A client can read what reviewers asked for, reply to say it is done, resolve a thread, react, and read the screenshots attached to a request. It can only edit or delete comments it wrote itself.

Server logs. get_site_logs returns the same lines the Logs panel shows, for the preview machine or the published site. This is the one an agent debugging a site needed most: it could read your code and change your code, but never see what the server actually printed.

Site settings. The project category and server location joined rename_site, check_subdomain_available tests a free subdomain before it is taken, set_site_thumbnail and clear_site_thumbnail handle the dashboard card, and clear_site_chat covers the Delete chat action in the danger zone.

Storage over MCP is no longer read-only

A connected AI client could already browse your storage, organise it and delete from it, but it could never put a file in. That is fixed, along with the rest of the Storage panel.

Five tools are new:

  • upload_storage_file puts a file into the bucket and returns its permanent CDN address when the file is public, ready to embed in a page, or a null address when it is private. Up to 100MB, sent base64 encoded.
  • read_storage_file returns the contents of a stored file, so a client can read back a JSON, CSV or SVG it placed there. Files over 5MB are refused, since a tool result is capped.
  • clear_storage empties the whole bucket, 20,000 objects per call with complete saying when more remain, the same action as Clear all storage in the Configuration sub-tab.
  • get_storage_key reveals the private storage key in plain text.
  • rotate_storage_key replaces it with a new one and pushes it to the preview. The published site keeps the old key until it is published again, and anything outside the site that used the key needs the new one pasted in.

Workspaces, members and roles

A connected client could see your workspaces but nothing inside them. Now list_workspace_members reads the people and the pending invitations, invite_workspace_member, resend_workspace_invite, cancel_workspace_invite and remove_workspace_member manage them, and assign_member_role moves someone between roles. Custom roles can be created, changed and deleted, with the grantable permissions listed for you so a role cannot be built out of names that do not exist.

create_workspace, rename_workspace, set_default_workspace and leave_workspace cover the workspace itself. get_workspace_credits and get_workspace_credit_usage answer where your AI credits went rather than only how many are left.

Deleting a workspace is deliberately not available to a client, because it cancels the subscription.

Your account and referrals

get_account and update_account read and change your name, phone, avatar and notification preferences. get_site_usage reports how close you are to your plan's site limit, and list_pending_invitations shows what is waiting for you. list_referrals, list_payouts, check_affiliate_code and update_affiliate cover the referral programme.

Changing your email address still needs the confirmation link and can only be done in the product.

Writing files directly

write_file replaces source files straight in the running preview, without going through the AI. It is the fast path for a mechanical edit, a typo, a colour token, a config line, where asking the AI would spend credits and run a whole generation for one line.

Each file is confirmed individually by the preview, so the response tells you which paths were written and which failed and why, rather than reporting a blanket success.

It is deliberately blunt. It replaces the whole file rather than patching it, it needs the preview to be running, and the change is not captured in version history, so it cannot be undone by restoring a version. Take a backup first for anything substantial, and keep using the chat when you want a change described rather than dictated.

Run SQL against your database

execute_sql runs a statement against a site's database and returns the rows. It covers everything the collection tools cannot express: a join, an aggregate, a migration, a bulk update, adding a column, creating an index.

It runs whatever it is given. There is no read-only mode and nothing blocks DROP, TRUNCATE or a DELETE without a WHERE. It therefore sits behind its own data:sql permission, and needs the same role permission as deleting a site, so an ordinary member cannot use it.

Values go through params as $1, $2 rather than being pasted into the statement. Statements are capped at 20,000 characters and time out after 15 seconds, and at most 200 rows come back, so put your own LIMIT in the query.

Find out why a publish failed

get_publish_status told you a publish failed and nothing more. get_publish_logs returns the actual build output, paged, with the error alongside it.

get_publish_timeline returns the publish step by step, from provisioning through compiling and uploading to the health check and the switch, with how long each step took. Those per-step durations were recorded but had never been shown anywhere.

stop_publish stops a publish that is still running. The build is abandoned and its machines are torn down; whatever was already live stays up untouched. A publish that has passed the point of switching over is refused rather than half-cancelled.

Exports

export_collection reads a whole collection in one call with its column types, where list_rows pages 50 at a time. export_site_analytics returns the all-time breakdowns in one response. export_site_webhooks returns your whole webhook setup, with signing secrets excluded and destinations shown as hosts, matching how webhooks are already listed.

The storage and code archives stay browser downloads. A connected client receives structured data rather than files, and it can already reach the same content through list_storage_files with get_storage_file_url, or list_files with read_file.

Ten new permissions

comments:read, logs:read and account:read are ticked by default, being ordinary reads of your own site and account.

comments:write is not, because it can delete a comment. workspaces:write, members:write, account:write and code:write are not either, and members:write is worth its own thought before you grant it: it sends real email to real colleagues and can remove someone's access to every site in a workspace.

data:sql is unticked because the statement it runs is not inspected. credentials:reveal is unticked because it is the only permission that hands a client a live credential in plain text, covering environment variable values, the private storage key and webhook signing secrets.

Two existing labels were widened to match what they always did. data:read now reads Read CMS collections and stored files and data:write reads Change CMS rows and stored files.

A safer default on every call

Every tool now has to resolve to a workspace before it runs. A call that names neither a site nor a workspace, or names one that does not exist, is refused before it reaches the endpoint behind it rather than being left to that endpoint to catch. list_workspaces and list_templates are the only exceptions, because neither belongs to a workspace.

See MCP tools and Tokens and scopes.

addedimproved

Documentation, MCP beta and a message queue

Full product documentation, an MCP server in beta, queued chat messages, and reworked inputs across the product.

Documentation

There is now a documentation site covering the product end to end, at modulify.ai/docs.

It opens with a getting-started path that takes you from signing up to a published site, then goes feature by feature: building with AI, the editor, projects, data, publishing and domains, automations, analytics, plans and credits.

Every page can be copied as Markdown for an AI assistant, or opened as its raw source.

MCP, in beta

Modulify now exposes an MCP server. Connect an AI client such as Claude Code, Claude Desktop or Cursor and it can list your sites, send prompts to them, read their code and publish them, limited to the permissions you grant.

Access is controlled by tokens you create yourself. A token acts as you, so by default it reaches every workspace you are a member of, and you can narrow it to specific workspaces when you create it. You pick its permissions, and you can revoke it at any time.

See What is MCP and Connect a client.

Queue messages while the AI is working

You no longer have to wait for a generation to finish before sending your next instruction.

Send a message while the AI is still working and it queues rather than being rejected. Queued messages run in order once the current generation finishes, and you can reorder them, edit one before it runs, or remove it entirely.

Improved inputs

Inputs across the product were reworked so they look and behave the same wherever they appear. That covers the prompt box, form fields, search boxes and pickers. Focus, validation and disabled states are now consistent, and the layouts hold together at narrow widths.