The short answer
Owners increasingly run their game with an AI assistant. NetCraftGames is designed so that assistant can do real work without being handed the keys to the business. An owner creates a scoped API key; the key can do only what its scopes allow; risky actions can require the owner's approval in the dashboard; and some things no key can ever do. The API exists in the product source and is tested locally. It is not live, because NetCraftGames is pre-launch.
The API can also turn on the public share page for a game, set its title and website link, and replace the link. Setting the website link or replacing the link asks the owner first under the default key settings.
What a key can be allowed to do
Keys carry one or more of six scopes:
| Scope | What it allows |
|---|---|
read:games | Read games, releases, runtime status, connection configuration, build inventory and the service-level view |
write:releases | Create games, upload builds, submit releases, run release checks, publish, archive and prepare configuration changes |
runtime:control | Wake and sleep games (this spends prepaid hours) and manage the server admin credential where enabled |
read:usage | Read plan, prepaid balance, reservations and the usage ledger |
read:incidents | Read incidents, player reports, activity and notification history; request AI analysis of an incident |
manage:settings | Change notification and automation preferences, allowed client origins, report triage and webhooks |
What no key can do
There is no route for these, so no scope can reach them:
- Buy capacity or boosts, or start a checkout or billing portal session.
- Change the account email, password or multi-factor settings.
- Delete the account or a game.
- Create, edit or list API keys.
- Read session cookies or any agent, provider or encryption secret.
- Download builds or saved game data.
Safety rails around every key
- Shown once, stored hashed. A key is displayed a single time when created. Keys start with
ncg_live_so secret scanners can recognise them. - Narrowed on purpose. A key can be limited to chosen games and to an IP allowlist, and it expires.
- Limits. Per-minute rate limits, a daily cap on counted actions, and a daily cap on how much prepaid time the key can spend.
- Human approval. For irreversible, high-risk or time-spending calls, the API answers that approval is required instead of acting. The owner opens the dashboard, reads a plain-language summary and approves or denies. On approval the server runs exactly the parameters stored at request time, so the AI cannot change them afterwards.
- Idempotency. Every mutating request needs an idempotency key, so a retry cannot buy or wake twice.
- Audit. Calls are recorded in an audit log the owner can read.
- Untrusted text is labelled. Incident titles, player reports and similar free text are marked untrusted in the API description, so an AI client does not follow instructions hidden in them.
- Signed webhooks. Events such as release checks passing or failing, servers going online or stopping, incidents and service-level warnings can be delivered to the owner's endpoint, signed with a timestamp tolerance.
How an AI finds and learns the API
| Mechanism | Status |
|---|---|
llms.txt and per-page Markdown on this site | Available now: llms.txt |
| Machine-readable fact sheet | Available now: fact sheet and facts.json |
| OpenAPI 3.1 description, generated from the same route table the server uses | Built; will be served by the application at launch, not published here |
| MCP server | Built as a local stdio server that runs on the owner's own machine with their key; not yet published |
| Typed client | In the repository; not yet published as a package |
The MCP server in plain words
The MCP server lets an assistant such as Claude Desktop, Claude Code or Codex work with an owner's account through the same API and the same key limits. It has read tools (games, status, connection config, usage, incidents, activity, audit), write tools (create a game, upload a build, create and check a release, publish, wake and sleep, propose and apply configuration changes, set allowed origins) and two admin tools that are off by default. It can be started in read-only mode. Third-party text such as player reports is labelled as data the assistant must not obey, and an "owner approval required" answer is passed to the human and never retried.
Because it is a local program and not a hosted service, it has no network address, so there is no remote MCP endpoint and no /.well-known discovery file on this site. We will publish a discovery file only if a remote MCP endpoint ever exists.
What it means for you
Give an assistant a key with the narrowest scopes it needs, set approvals to cover anything that spends hours, and keep the owner dashboard as the place where money and account decisions are made. See what the AI reads and never does for the platform-side boundaries.
Frequently asked questions
Can my AI assistant buy more server hours with an API key?
No. There is no API route that buys capacity or boosts, or that starts a checkout, so no scope can reach it. A key can wake and sleep servers, which spends prepaid hours already in your plan, and those calls have daily caps and can require your approval in the dashboard.
Does NetCraftGames have an MCP server?
Yes, in the product source: a local stdio MCP server that an owner runs on their own machine with an API key, exposing the same operations and limits as the owner API. It is not published yet and the API is not live, because NetCraftGames is pre-launch. There is no remote MCP endpoint.