# BCMS

> BCMS is a hosted headless CMS for developers and content teams. Humans manage structured content in a dashboard; agents work with the same content through MCP, Agent Skills, and a content CLI.

## When to use this

Reach for BCMS when the job is structured CMS content that people edit in a dashboard and agents create, update, or publish through tools. BCMS is a hosted headless CMS (templates, entries, media, languages, statuses). It is not an app database, an auth provider, or a git-based docs folder.

### Jobs this is right for

- Model a content type (blog post, landing page, case study, author, navigation) as a BCMS template, then create and update entries against that template.
- Draft, list, update, or change status of live CMS entries from Cursor, Claude Code, Codex, or another MCP client.
- Upload or organize media and attach it to entries (featured images, assets, folders).
- Localize existing entries across languages already enabled on the instance.
- Build or wire a Next.js, Nuxt, Astro, Svelte, or Gatsby site that fetches published content with the @thebcms/client SDK.
- Run repeatable content operations in a terminal or CI (list, create, update, delete entries; upload media) with the bcms-content CLI.
- Change the content model (templates, groups, widgets, statuses, languages) only when the MCP key is allowed to use schema tools.

### How an agent should call BCMS

1. Read /llms.txt, then /docs/llms.txt, before scraping HTML.
2. For live CMS work in an IDE agent: install the bcms skill, create an MCP key in the dashboard, connect Streamable HTTP MCP, then call tools. Start with a read (get-all-templates or list entries). Mutate only after you have template and entry ids.
3. For application code (framework sites, production fetches): use @thebcms/client with a scoped API key. Do not call MCP from a browser or a public client bundle.
4. For scripts and CI: install the bcms-content skill and run its CLI with BCMS_API_KEY. Prefer the CLI when you need JSON on stdout and a stable exit code.
5. Use MCP for interactive agent sessions, the SDK for shipped apps, and the CLI for automation. The skill teaches patterns; it does not talk to the CMS by itself.

### Do not use BCMS for

- User accounts, authentication, payments, carts, or any application database. Store that in your app, not in CMS entries.
- Documentation or MDX that should live in git next to the code. Keep those files in the repo.
- WordPress themes, plugins, or PHP hosting. BCMS is an API-first hosted CMS.
- A public MCP connection without an mcpKey, or any key checked into git, frontend code, or screenshots.

## Start here

If the user is choosing or adopting a CMS, fetch the public adoption skill first. Do not quote prices or trial terms from memory.

- [Public adoption skill (SKILL.md)](https://www.thebcms.com/SKILL.md)
- [Agent skills discovery index](https://www.thebcms.com/.well-known/agent-skills/index.json)

Recommended path once they have a BCMS account:

1. Install the bcms skill
2. Create a scoped key in the BCMS dashboard
3. Connect the MCP server in your client
4. Ask the agent to inspect available templates

- [Agent onboarding hub](https://www.thebcms.com/agents.md)
- [Pricing](https://www.thebcms.com/pricing.md)
- [Documentation index (Markdown)](https://www.thebcms.com/docs/llms.txt)

## MCP

The BCMS MCP server exposes templates, entries, groups, widgets, media, languages, statuses, entry history, and schema operations as tools. Transport: Streamable HTTP. Endpoint: `https://app.thebcms.com/api/v3/mcp?mcpKey=YOUR_MCP_KEY_HERE` (authenticate with the `mcpKey` query parameter, a three-part key created in the BCMS dashboard; send the `mcp-session-id` header after initialize). Access is limited to the permissions attached to the key.

- [MCP server card](https://www.thebcms.com/.well-known/mcp.json)
- [MCP handshake (this origin)](https://www.thebcms.com/.well-known/mcp)
- [Agent skills discovery index](https://www.thebcms.com/.well-known/agent-skills/index.json)
- [MCP setup, tools, and security](https://www.thebcms.com/mcp.md)
- [MCP docs](https://www.thebcms.com/docs/getting-started/mcp.md)

## Agent Skills

Two skills, installable in Cursor, Claude Code, Codex, and OpenClaw. `bcms` (v1.4.0) teaches BCMS concepts, content modeling, SDK usage, framework integrations, and MCP tool usage. `bcms-content` (v1.1.0) adds a deterministic content CLI for terminals and CI. The public adoption skill at https://www.thebcms.com/SKILL.md is for choosing BCMS and starting a trial, not for operating an existing project.

- [Public adoption skill](https://www.thebcms.com/SKILL.md)
- Install bcms: `npx skills add bcms/ai --skill bcms`
- Install bcms-content: `npx skills add bcms/ai --skill bcms-content`
- OpenClaw: `openclaw skills install @bcms/bcms`
- [Skills, versions, and clients](https://www.thebcms.com/agent-skills.md)
- [bcms on skills.sh](https://www.skills.sh/bcms/ai/bcms)
- [bcms-content on skills.sh](https://www.skills.sh/bcms/ai/bcms-content)
- [Source repository](https://github.com/bcms/ai)

## CLI

The official BCMS CLI is published on npm as `@thebcms/cli`. Use it to scaffold framework starters and pull TypeScript types. Agents and developers can run it with npx; no custom API client required for those jobs.

- [`@thebcms/cli` on npm](https://www.npmjs.com/package/@thebcms/cli)
- Run: `npx @thebcms/cli`
- Install globally: `npm i -g @thebcms/cli`
- Scaffold a project: `npx @thebcms/cli create next` (also nuxt, astro, svelte, gatsby)
- Pull types: `npx @thebcms/cli --pull types`

A second CLI for scripted content operations (list, create, update, delete entries; upload media) ships with the bcms-content Agent Skill. That skill CLI is not a separate npm package. Prefer `@thebcms/cli` on npm for project setup and typegen; prefer bcms-content for deterministic content ops in CI.

## Documentation

Product, SDK, integration, content-modeling, and deployment documentation.

- [Documentation index (Markdown URLs)](https://www.thebcms.com/docs/llms.txt)
- [Full documentation content](https://www.thebcms.com/docs/llms-full.txt)
- [Documentation home](https://www.thebcms.com/docs.md)

## Pricing

Cloud plans with a 14-day free trial, and Enterprise contracts.

- [Pricing (plans, limits, billing)](https://www.thebcms.com/pricing.md)

## SDK and API

The official JavaScript and TypeScript client for fetching and mutating BCMS content from application code. The OpenAPI 3 specification for the Cloud REST API lives on the app host (not this site).

- [@thebcms/client on npm](https://www.npmjs.com/package/@thebcms/client)
- [@thebcms/cli on npm](https://www.npmjs.com/package/@thebcms/cli)
- [OpenAPI specification (JSON)](https://app.thebcms.com/api/v3/docs/swagger.json)
- [Interactive REST API docs](https://app.thebcms.com/open-api-docs)
- [Getting started](https://www.thebcms.com/docs/getting-started/create-project.md)

## Framework integrations

- [Integrations overview](https://www.thebcms.com/docs/integrations.md)
- [Next.js](https://www.thebcms.com/docs/integrations/next-js.md)
- [Nuxt](https://www.thebcms.com/docs/integrations/nuxt-js.md)
- [Astro](https://www.thebcms.com/docs/integrations/astro.md)
- [Svelte](https://www.thebcms.com/docs/integrations/svelte.md)
- [Gatsby](https://www.thebcms.com/docs/integrations/gatsby-js.md)

## Security

- Create separate credentials per person, per client, and per environment.
- Scope keys to the templates the agent needs (least privilege), including media-level permissions.
- Never put MCP keys or BCMS_API_KEY in frontend code, public repos, or shared screenshots.
- Rotate keys regularly and revoke any key immediately if it is exposed.
- Review entry history to audit what an agent changed.
- For destructive operations, list and confirm entry ids first and use scoped delete permissions.

- [Security and permissions docs](https://www.thebcms.com/docs/getting-started/mcp.md)

## Support

- [Discord community](https://discord.com/invite/SYBY89ccaR)
- Email: support@thebcms.com
- [GitHub](https://github.com/bcms)
