Deploy, migrate, and sync with Staticbot skills and MCP
Connect ChatGPT to Staticbot's hosted OAuth MCP, or use focused skills with an API key in Codex CLI, Claude Code, and other coding agents: deploy, migrate, sync, and now move a live app with a planned cutover.
Ravel works on Staticbot’s migration platform, moving apps built with Lovable and Base44 onto Supabase and hosting their owners control.
Staticbot MCP is now hosted at https://mcp.staticbot.dev/mcp. ChatGPT users can authorize a personal plugin with the public staticbot-openai OAuth client. For Codex CLI and Claude Code, focused skills plus STATICBOT_API_KEY are the recommended setup; MCP is optional.
What the focused skills add
A capable agent could construct REST calls from scratch. The risky part is not the HTTP request — it is remembering the workflow around it. A migration must pause after discovery. A destructive sync needs review. A rollback must target an exact pinned version. DNS records must be shown without casually suggesting a nameserver change that could break mail.
Repository-aware deployment
Staticbot analyzes the repository and returns the workload, AWS or Cloudflare target, and customer-owned or Staticbot-managed ownership model.
Credential-safe fallback
When MCP is unavailable, the REST helper keeps the bearer token in STATICBOT_API_KEY, refuses absolute URLs, and does not follow redirects.
Self-navigating migrations
The agent follows pendingAction and failureBanner instead of hard-coding a brittle phase sequence.
Decisions you make
Discovery, destructive SQL, retry/skip, rollback, switchover, and deployment choices remain explicit decisions.
The skills
Analyzes the repository, reports the workload, AWS or Cloudflare target, and ownership model, then deploys. Handles DNS records, redeploys, and rollback to an exact version.
Moves a Lovable, Base44, Bolt, or Firebase backend to a Supabase project you own. Pauses after discovery, presents every choice, and builds a working preview.
Operates Continuous Sync: inspects runs, explains failures, and stops for your review before destructive database changes.
Moves a live Lovable or Base44 app with a planned maintenance window: test migration, cutover plan, maintenance page, write freeze with checks, fresh final copy, verification, and the domain switch. Stops for your go or no-go at every phase.
Lovable steps for a live move: freeze SQL with a before-and-after check, a fresh Cloud Data export, and removing the freeze from the new database.
Base44 steps for a live move: dashboard write freeze, the order that keeps your security rules intact, and sign-in changes to announce.
Direct REST API fallback for agents without MCP, using a credential-safe helper.
The live-migration skills work together: install all three. What a live cutover with your agent looks like.
Which migration skill should I use?
Both skills use the same Staticbot migration. The difference is everything around it.
- Use
migrate-vibe-coded-appwhen you only want the migration: a copy of your backend on your own Supabase and a preview to try. Your live app keeps running as it is unless you choose to switch it over, and how and when you switch is up to you. - Use
live-migrate-ai-built-appwhen people already use the app and you want the move managed: the maintenance window, user notices, stopping writes to the old app, the final copy, checks before reopening, and the domain switch.
migrate-vibe-coded-app | live-migrate-ai-built-app | |
|---|---|---|
| Best for | A prototype, a test copy, or an app nobody depends on yet. Also Bolt, Firebase, and self-hosted Supabase packages. | A Lovable or Base44 app that already has users, data people rely on, or a place in someone’s daily work. |
| What it does | Copies schema, data, accounts, files, and functions into a Supabase project you own, and builds a working preview. | Everything the migration skill does, twice: a test migration first, then a fresh final copy. Plus the process around it. |
| Maintenance window and user notices | Not handled. | Plans the window from measured timings and drafts the advance, maintenance, delay, and completion messages. |
| Stopping writes to the old app | Not handled. Anything users change after the copy is not in the new database. | Prepares the freeze for your builder, with checks that prove writes fail before the final copy is taken. |
| Domain switch | Not handled. You point your domain yourself when you are ready. | Deploys your production site with Staticbot days ahead. Staticbot issues and renews the certificate; you only add the DNS records it shows you, or it writes them for you if your DNS is on a connected Cloudflare account. Then it shows a maintenance page and reopens on your domain. |
| If something goes wrong | Until you switch over, your live app keeps running as before; delete the copy and try again. | A written recovery plan, with a rule for before and after the first real write reaches the new database. |
| How long you are involved | About as long as the migration and a look at the preview. | A rehearsal, a planning session, and the maintenance window itself, with a go or no-go from you at every step. |
Not sure yet? Start with migrate-vibe-coded-app. A migration that stopped at the preview can serve as the test run the live skill begins with, so nothing is wasted if you later decide to move production with live-migrate-ai-built-app. And if you can’t accept any downtime at all, neither skill is the right fit; talk to us about an enterprise blue-green migration.
Get the Staticbot plugin and skills
The public staticbot-mcp repository contains all the focused skills, the optional local MCP transport, and a direct-API fallback. It also serves as its own plugin marketplace, so Codex CLI (codex plugin marketplace add bitfiction/staticbot-mcp) and Claude Code (/plugin marketplace add bitfiction/staticbot-mcp) can install everything in one step. The hosted MCP connection is available now for ChatGPT. The public ChatGPT Plugins Directory listing is pending review, so it has to be added manually — the four steps below take about a minute.
Connect ChatGPT
- In ChatGPT, open Settings → Security and login and turn on Developer mode. On Team and Enterprise plans a workspace owner may need to allow it.
- Open Plugins, select the plus button, name the connection Staticbot, and enter
https://mcp.staticbot.dev/mcp. - Choose User-Defined OAuth Client and set
client_id=staticbot-openai, token endpoint authenticationnone, PKCE on. Staticbot does not offer dynamic client registration, so a connection made without this exact client ID will fail to authorize. - Sign in to Staticbot, approve the scopes (
staticbot:readalone for read-only), then pick Staticbot from the tools menu in a new chat.
Codex Desktop with browser control can drive this setup for you in your signed-in ChatGPT account.
Codex CLI and Claude Code
Create an organization-scoped API key at app.staticbot.dev/developer, store it as STATICBOT_API_KEY in the agent's environment, and install the Staticbot skills as personal skills. The direct REST fallback means MCP is not required.
Load the API key without putting it in shell history
printf 'Staticbot API key: ' IFS= read -rs STATICBOT_API_KEY printf '\n' export STATICBOT_API_KEY
Run this in the terminal that will launch Codex CLI or Claude Code. The key lasts for that terminal session and is inherited by the agent.
Paste into Codex CLI
Use $skill-installer to install these seven Staticbot skills as personal skills from https://github.com/bitfiction/staticbot-mcp/tree/main/skills: - deploy-web-app-with-staticbot - migrate-vibe-coded-app - sync-vibe-coded-app - live-migrate-ai-built-app - live-migrate-lovable-app - live-migrate-base44-app - staticbot Do not install or configure the Staticbot MCP server. Confirm the installed paths and list all seven installed skills.
Paste into Claude Code
Install these seven directories from https://github.com/bitfiction/staticbot-mcp/tree/main/skills as personal Claude Code skills under ~/.claude/skills: - deploy-web-app-with-staticbot - migrate-vibe-coded-app - sync-vibe-coded-app - live-migrate-ai-built-app - live-migrate-lovable-app - live-migrate-base44-app - staticbot Copy each complete skill directory, including its scripts and references. Do not install the Staticbot plugin or configure MCP. Validate the result with "claude plugin validate ~/.claude/skills" and report the installed paths and validation result.
Installing the plugin brings all seven skills at once. The general staticbot skill is the direct-API fallback.
OAuth for hosted chat; API keys for coding agents
Hosted ChatGPT and Claude connections open Staticbot's authorization screen, so there is no key to paste. For a read-only ChatGPT connection, select only staticbot:read; select staticbot:write during setup only for intended changes. Codex CLI, Claude Code, and optional local stdio clients use an organization-scoped key from app.staticbot.dev/developer exposed as STATICBOT_API_KEY. Never paste that key into chat or commit it.
The included helper sends the key only to the configured Staticbot origin. Hosted users need no URL configuration; local and self-hosted users can set STATICBOT_API_URL.
Try these prompts
“Use $deploy-web-app-with-staticbot to deploy this repository. Show me the detected workload, target, and ownership before starting production.”
“Use $migrate-vibe-coded-app to migrate this Firebase project to Supabase. Stop after discovery and show me exactly what will move.”
“Use $migrate-vibe-coded-app to preview this Base44 migration before switching the backend.”
“Use $live-migrate-ai-built-app to plan the live cutover of my Lovable app. Start with a test migration and stop for my approval at every phase.”
“Use $sync-vibe-coded-app to inspect the latest sync run and explain every failed job. Do not retry or skip anything yet.”
“Use $deploy-web-app-with-staticbot to list safe rollback targets for my website and show the commit details.”
How skills and MCP work together
The skills are the workflow layer; MCP is an optional typed action layer. Skill-capable clients get repository-aware routing, safe sequences, and steps that need your approval. MCP-compatible clients also get discoverable typed tools. Without MCP, the bundled fallback skill uses the same REST API contract through a credential-safe helper.
| Focused skills | Staticbot MCP |
|---|---|
| Goal recognition and repeatable workflow | Live authenticated actions |
| Decision points and output requirements | Typed tools and input schemas |
| Direct REST fallback when needed | Production-hosted OAuth MCP plus local npm transport |
See the combined Staticbot plugin, skills, and MCP documentation for the current setup paths.
Deploy from the agent already in your repository
Install the focused skills, connect Staticbot MCP, and ask your coding agent to handle the workflow.
