# Appsmith > Appsmith is an open source (Apache-2.0) low-code platform for building internal tools, admin panels > and workflow applications on top of 25+ databases and any REST/GraphQL API. It runs as a self-hosted > Docker/Kubernetes deployment or as Appsmith Cloud at app.appsmith.com. Generated by API Evangelist on 2026-09-04 from probed and searched sources. This file is NOT published by Appsmith — probes of https://docs.appsmith.com/llms.txt, https://www.appsmith.com/llms.txt and https://community.appsmith.com/llms.txt all returned HTTP 404 on 2026-09-04. ## What an agent can actually call Appsmith's agent surface is its **MCP server**, not a REST API. - The platform REST API at `https://app.appsmith.com/api/v1` (self-hosted: `https:///api/v1`) is live but **undocumented** — it is the editor's own traffic. It authenticates with the browser session cookie and wraps every response in a `responseMeta` envelope. - The springdoc OpenAPI surface (`/v3/docs`, `/v3/swagger`) is **disabled by default** (`springdoc.api-docs.enabled=false`) and returns **401** when enabled (GHSA-v6jh-fx3m-7xhw). There is no published OpenAPI document. - The **MCP server** is bundled in the Appsmith image, fronted by Caddy at `/mcp`, and exposes 61 tools for building and editing applications. It is **off by default** (`APPSMITH_MCP_ENABLED`) and requires a per-user `mcp_` bearer token. Appsmith Cloud does not expose it (POST /mcp -> 403 CloudFront). ## Core docs - [Documentation](https://docs.appsmith.com): product documentation. - [Getting started](https://docs.appsmith.com/getting-started): first app, setup and deployment. - [Reference](https://docs.appsmith.com/reference): widget, function and framework reference. - [Connect data — REST API](https://docs.appsmith.com/connect-data/reference/rest-api): querying an API from an app. - [Authenticated API](https://docs.appsmith.com/connect-data/reference/authenticated-api): API key, bearer, basic and OAuth 2.0 datasources. - [Embed Appsmith](https://docs.appsmith.com/advanced-concepts/embed-appsmith-into-existing-application): iframe embed URL + postMessage. - [SCIM provisioning](https://docs.appsmith.com/advanced-concepts/user-provisioning-group-sync): SCIM 2.0 at `https:///scim`. - [appsmithctl](https://docs.appsmith.com/getting-started/setup/instance-management/appsmithctl): instance CLI (backup, restore, export_db, import_db, enable-form-login). ## Operations - [Releases / changelog](https://github.com/appsmithorg/appsmith/releases): current v2.3 (2026-08-13); docs.appsmith.com/changelog 308s here. - [Status page](https://status.appsmith.com): Appsmith Cloud only. - [Security policy](https://github.com/appsmithorg/appsmith/blob/release/SECURITY.md): GitHub private vulnerability reporting; no bug bounty. - [Security advisories](https://github.com/appsmithorg/appsmith/security/advisories) - [Trust center](https://security.appsmith.com/): SOC 2 and pentest report under NDA. - [Pricing](https://www.appsmith.com/pricing): Free / Business $15 per user per month / Enterprise from $2,500 per month. ## Runtime semantics an agent needs - **Errors**: `{"responseMeta":{"status":400,"success":false,"error":{"code":"AE-APP-4000","title":"ARGUMENT_ERROR","message":"..."}}}`. 126 stable `AE--` codes are published in the Apache-2.0 server source. - **Rate limits**: no `RateLimit-*` or `Retry-After` headers. HTTP 429 with `AE-TMR-4029` is the only signal. Caddy edge default 100 req/s per client IP; login 5/day per email (then a 24h suspension); MCP auth 5/min; test-datasource 3/5s; Ask AI 20/min. - **Idempotency**: none. No `Idempotency-Key` support anywhere in the product. - **Reversibility**: MCP `prepare_rollback`/`confirm_rollback` and `appsmithctl restore` exist; no retention window is published for either. MCP destructive tools use a prepare/confirm handshake with a 5-minute one-time confirmation token — that is an approval window, not an undo window. - **Git**: every mutating MCP tool on a git-connected app requires a matching `branch`; agent commits are confined to the reserved `mcp/` namespace and always push to the customer's remote. ## Source - [GitHub organization](https://github.com/appsmithorg) - [Main repository](https://github.com/appsmithorg/appsmith) (Apache-2.0) - [Documentation repository](https://github.com/appsmithorg/appsmith-docs) - [Community portal](https://community.appsmith.com)