To use the Lovable MCP server in Claude Code, run claude mcp add --transport http lovable "https://mcp.lovable.dev" in your terminal, then complete the Lovable login in the browser window that opens on the first tool call. Cursor, ChatGPT, VS Code and Claude Desktop take the same URL. Authentication is OAuth, and the server is available on every plan.
That command is the easy part. The part worth slowing down for is what the connection can reach once it exists: not one project, but every project in every workspace your Lovable login touches, with live SQL included. If any of those projects holds real financial data, the setup order matters more than the setup command.
Verified in the browser on 10 October 2026: the Lovable MCP server documentation, the Lovable changelog, the privacy and security settings reference, the Lovable marketplace listing in Claude, the official lovablelabs/mcp repository, and the Lovable pricing page read logged out.
What the Lovable MCP Server Actually Is
Lovable publishes itself as a Model Context Protocol server at mcp.lovable.dev. An AI client that speaks MCP connects to that one endpoint, signs in with your Lovable account, and then sees a set of named tools it can call: create a project, send a message to the Lovable agent, read a file, run a query, publish the app. The documentation describes the direction plainly, and it is the opposite of the feature most people land on first.
Only the first row is this article. The last row points the other way: it turns an app you shipped into something ChatGPT or Claude can operate on a user's behalf, and it carries a different set of plan gates. If that is what you were looking for, the companion piece on building an MCP server with Lovable covers it end to end.
A few numbers from the day of writing. The documentation lists 41 tools across nine groups, plus two that only appear in certain clients. The Claude marketplace entry, published by Lovable itself, shows 35. The machine-readable reference at mcp.lovable.dev/skill.md carries a tool the documentation table leaves out entirely. More on that gap further down, because it changes how you should audit the connection.
Availability, and how it got here
The server started as a research preview for Pro and Business on 18 May 2026 and moved to all plans, Free included, on 3 June 2026. Plenty of pages still describe it as a preview. It is not, and the changelog entry is dated.
Lovable MCP Claude Code Setup, and Every Other Client
Claude Code has the shortest path of any client, because Lovable ships an official plugin alongside the raw server. Either route works, and the plugin adds slash commands for the common tasks.
claude mcp add --transport http lovable "https://mcp.lovable.dev"
/plugin install lovable@claude-plugins-official
The first time a Lovable tool runs, Claude Code opens a browser window to log in. Verify with /mcp and look for the lovable server, or simply ask it to list your Lovable workspaces. Cursor has its own Lovable plugin with the slash commands /lovable-new, /lovable-iterate, /lovable-db and /lovable-deploy, and a manual JSON route if you prefer to edit mcp.json yourself.
The dates below come from the Lovable changelog, not from third-party guides, several of which still list clients that were added months after the post was written.
That last row catches people out. A client running on your own machine, finishing login at localhost or 127.0.0.1, registers itself automatically. A client that lives in a browser or on somebody's server cannot connect until Lovable has approved its redirect address, and the fix is a support request rather than a config change.
Official server, unofficial copies
Search results for this topic mix the two. The official server is the hosted endpoint at mcp.lovable.dev, with its setup guides, Claude Code plugin and MCP registry entry open sourced under Apache 2.0 in the lovablelabs/mcp repository. The Claude marketplace listing carries a verified publisher badge and names Lovable as the maker. Community repositories and third-party skills with similar names are not maintained by Lovable, do not inherit its security review, and should be read as somebody's personal project. Anthropic prints its own version of this warning on the listing page: only use connectors from developers you trust.
The Scope Problem to Read Before You Connect
Lovable publishes a warning box above the setup steps. It is short, it is unusually candid for vendor documentation, and almost no ranking page quotes it. Four lines matter.
- Scope is your full account, not one project. Whatever client you connect can list, read and edit every project you have access to in Lovable.
- Calls run live on your account. Tool calls use real credits and edit real projects. There is no sandbox and no dry-run flag.
- deploy_project deploys the app and returns a live URL. On Free and Pro, anyone with that link can reach the app. On Business and Enterprise, the URL follows the workspace default and can be restricted to members.
- query_database runs SQL with your full database permissions: reads, writes and schema changes.
Put those together and the risk is not that an agent writes bad React. It is that a vaguely worded instruction in a long session reaches a table it was never meant to see, or publishes a half-finished build to a public URL. The documentation says the server inherits your user permissions exactly, with no additional surface area, which is accurate and is also the whole problem: your permissions are usually broad.
For anything holding client money data, the general safety work on Lovable builds applies before the MCP work does, and the article on whether Lovable is safe for financial data walks through row-level security, keys and the trust posture in detail.
Which Tools Spend Credits and Which Are Free
The documentation answers this in one line, and it is the single most useful cost fact in the whole integration: standard Lovable credits apply to create_project and send_message. Other tools are free.
So an agent that lists your projects, reads files, pulls diffs, checks edit history, inspects connectors and reads analytics costs nothing. The moment it creates a project or sends a message to the Lovable agent, you are paying the same build rates you pay in the editor. Published example costs for a build message run from 0.50 to 1.70 credits depending on what the prompt asks for, and the arithmetic on a full MVP is covered in the credits breakdown.
One detail that only appears in the machine-readable reference: create_project and send_message detect identical retries from the same caller with the same arguments inside roughly two minutes, and reuse the original result rather than creating a duplicate project or a second agent run. The response comes back flagged as deduplicated. That protects you from the classic agent failure where a timeout triggers a retry and you pay twice. It is a two-minute window, not a guarantee, so an agent that retries slowly can still double-charge you.
A practical note for anyone running an agent unattended: query_database is free, but it is also the tool with write and schema permissions. Free does not mean harmless.
What Changes on Business and Enterprise
The server itself is on every plan. The controls around it are not, and the asymmetry runs the opposite way to what most people assume.
Read that table again if you are on Pro. On Free and Pro the ability of an external MCP client to reach your workspace is always on and cannot be configured. There is no kill switch. The switch itself is a Business feature, found under Workspace settings, Security, Privacy and security, as Third-party MCP clients. For a team that wants the option of saying no, that is a concrete reason to be on Business rather than Pro, and it is a different reason from the usual seats-and-SSO pitch.
Three more gates worth knowing before you let an agent drive:
- set_project_visibility can set a project to private, workspace_view or draft. The second and third both require Business or Enterprise. On Free and Pro the tool can only do one of the three.
- deploy_project on Free and Pro produces a link anyone can open. Workspace-only visibility for a published app is the Internal publish feature on the Business card, visible in the pricing screenshot above.
- Enterprise workspaces that enforce SSO with a session duration of 24 hours, 48 hours or 7 days will see the server return a 401 once the window elapses. Compliant clients, including Claude Desktop, Cursor and Claude Code, restart the OAuth flow by themselves and open a browser window.
The wider Business and Enterprise comparison for finance teams, including where SCIM and audit logs actually sit, is set out separately, and the plan-by-plan pricing walkthrough covers the credit ladders.
Three Official Pages, Three Different Tool Lists
This is the finding that should change how you audit the connection. On 10 October 2026 the three official descriptions of the same server did not agree.
None of this is sinister. A hosted server changes faster than the pages describing it, and Lovable says as much: the skill file is maintained alongside the server so it always matches what the server currently exposes. The practical consequence is simple. What your client can do is whatever the server answers to a tools list call, not whatever any single page says. If you are writing down a tool inventory for a review, run the call and read the response.
respond_to_approval is worth a line of its own, because it is the tool that handles a paused agent run waiting on a human decision. The reference is explicit that you show the human the pending tool and its parameters and pass their answer through, rather than deciding for them. An agent configured to auto-approve everything removes the one checkpoint that exists.
A Safe Setup Checklist for Financial Data
None of this is exotic. It is the ordinary discipline that full-account scope demands, written in the order you should do it.
- Create a separate workspace for agent experiments and connect from there first. Scope follows your account, so the only real boundary is which workspace your experimenting login belongs to.
- Never point a connected client at a workspace that holds live client financial records while you are still learning what the agent does unprompted. query_database can change schema.
- Start read-only in practice: ask for list_projects, list_files, read_file and get_diff, and watch how the client sequences calls before you allow create_project or send_message.
- Set workspace knowledge with your standards before the first build, not after. The agent reads it on every run, and it is cheaper than correcting output.
- Check deploy behaviour before you deploy anything real. On Free and Pro the resulting URL is public. Confirm the plan and the workspace default first.
- Know the revoke path. Removing the Lovable entry from your client's connector settings ends that client's access, and on Business or Enterprise an admin can switch Third-party MCP clients off for the whole workspace.
- Expect deploy_project to refuse a publish while a project has unresolved critical security findings. It returns a 400 naming the findings that blocked it, and the fix is in the project's Security view, not in the agent.
Teams running this across more than one person should also read how workspace roles and membership behave, because the connection is personal to each member even when the workspace is shared.
When This Is Worth Setting Up, and When It Is Not
The honest case for it is narrow and real. If you already live in Claude Code or Cursor, the server removes the context switch: you can scaffold a Lovable project, read the diff it produced, and deploy it without leaving the editor, and you can run several variants of the same brief in parallel and compare the live URLs. For anyone who builds client front ends repeatedly, that is a genuine time saving.
The case against is equally real. It is a build-time convenience, not a runtime. It does not make your deployed app smarter, it does not watch anything for you, and it does not replace the editor for the visual work. If your main complaint is build errors rather than context switching, the troubleshooting guide will do more for you than a new connection.
If you are weighing the platform itself rather than this one feature, the full Lovable review collects the pricing, security and export findings from this series in one place. If you want the workspace controls described above, you can start a plan at Lovable or ask me directly through my Lovable Expert profile.
Frequently Asked Questions
Can I connect MCP to Claude Code?
Yes. Claude Code supports remote MCP servers over HTTP, and Lovable publishes one. Run claude mcp add --transport http lovable "https://mcp.lovable.dev", then sign in to Lovable in the browser window that opens on the first tool call. Lovable also ships an official Claude Code plugin that installs the same server and adds slash commands.
How do you connect Claude Code to Lovable?
Two routes, both official. The command above adds the server directly. Alternatively, run /plugin install lovable@claude-plugins-official inside Claude Code. Either way, authentication is OAuth, so there is no API key to paste or rotate. Verify the connection with /mcp and look for the lovable entry.
Is the Lovable MCP server free?
The server is available on every plan including Free, and connecting costs nothing. Tool calls are a different question: create_project and send_message consume your normal Lovable credits, and every other tool is free. There is no separate subscription for MCP access.
Can I connect with an API key instead of OAuth?
Not to the MCP server. The documentation states that API key authentication is not currently available and OAuth is the only supported method. If you need key-based access for a script or a CI job, that is the Lovable API rather than the MCP server, and API keys require a Business or Enterprise workspace plus an owner or admin role.
Why are the Lovable tools not showing after I connect?
Run a tools list call first to confirm the connection is live. If you connected through the client's own interface, remove the Lovable entry and add it again to re-run the OAuth flow. If you connected with a config file, check the JSON is valid and that the lovable entry sits inside the existing mcpServers object rather than in a second block, then restart the client. On an Enterprise workspace, confirm an admin has enabled third-party MCP clients.
What should I look for in any MCP server before connecting it?
Who publishes it, what scope it takes, and whether you can revoke it. A server published by the vendor whose account it touches, listed in a marketplace with a verified publisher badge, with its scope written down and a documented way to disconnect, is a different proposition from a community repository with the same name. Read the scope statement before the feature list.
Related Reading in This Series
References
- Lovable documentation, Lovable MCP server, read 10 October 2026
- Lovable changelog, entries dated 18 May, 3 June, 17 June, 22 June, 22 July, 31 July, 10 September and 11 September 2026
- Lovable documentation, privacy and security settings, Third-party MCP clients
- Lovable MCP skill reference, mcp.lovable.dev/skill.md, read 10 October 2026
- lovablelabs/mcp on GitHub, Apache 2.0, read 10 October 2026
- Lovable connector listing in the Claude marketplace, read 10 October 2026
- Lovable pricing, read logged out on 10 October 2026
- Lovable MCP landing page, read 10 October 2026
About the Author
TJ Alam is a certified Lovable Expert on the Website Builder track and the founder of Digi Flock Enterprises. He has built tjalam.com and cyberdance.in with Lovable and writes about the platform for MoneyFlock. You can find his Expert profile in the Lovable partner directory, or start a plan at Lovable.
MoneyFlock may earn a commission if you subscribe to a Lovable Business plan through links in this article, at no extra cost to you. TJ Alam is a certified Lovable Expert.