626Labs · Claude Code plugin

Give agents pipelines into your app.

vibe-access scans your routes and auth model, maps every callable surface into a schema-versioned agent-access.json manifest with dev and prod-safe tiers, scaffolds the affordances your app is missing behind hard env gates, then proves the layer with a cold-agent verify — deep on Firebase Cloud Functions, honest about the rest.

v0.2.0·8 commands·Firebase Functions·MIT

Includes8 commands · 13 skills

vibe-access ~
$ /vibe-access:scan
[vibe-access] Walking routes, classifying auth... done
→ auth per route: none / session / token
→ unmapped entries flagged as findings, read-only, nothing changed
 
$ /vibe-access:map
[vibe-access] Writing agent-access.json...
→ tiers: dev · prod-safe · seed/reset/capture never prod-safe
 
$ /vibe-access:verify
[vibe-access] Cold agent, manifest only... stamping pass/fail
01 · What it does

Eight commands from route scan to proven manifest.

Scan and map are read-only against your source. Scaffold is the only step that writes, and it is backup-wrapped, dev-gated, and shows every patch before it lands.

/vibe-access:scan

Inventory routes and auth.

Walks your routes, classifies auth as none, session, or token, and mines the input shape out of each handler. Every unmapped entry becomes a first-class finding. Read-only.

Reach for it before you let an agent near the app, to see what is actually callable.

/vibe-access:map

Build the manifest.

Turns the scan into agent-access.json: each affordance carries a tier, a kind, an auth class, and a verified stamp. Re-runnable; overrides and verify stamps survive a re-map.

Reach for it once the scan looks right and you want a contract an agent can read cold.

/vibe-access:scaffold

Fill the gaps you pick.

Adds the affordances your app is missing: seed, reset, read-state, capture, discovery. Backup-wrapped and dev-gated; patches are shown and applied via Edit, never blind.

Reach for it when the manifest shows what an agent needs but the app does not expose.

/vibe-access:verify

Prove it with a cold agent.

Works from the manifest alone, with no reading of your source to work out a call. Local-only unless you force it. Stamps each affordance pass or fail. Never auto-probes anything marked destructive.

Reach for it before anything counts as done.

/vibe-access:visualize

See what the agent sees.

Renders the agent-facing surface as one self-contained HTML page, from the manifest or a live MCP tools/list payload. Tool count is never graded.

Reach for it when you want to read the surface the way an agent reads it.

/vibe-access:describe

Write descriptions an agent can choose from.

Reads the handler behind every affordance still carrying a machine-template description and drafts a real one. You approve per group before anything is written. Nothing lands unreviewed.

Reach for it when the manifest is correct but the descriptions are not good enough to choose from.

/vibe-access:vitals

Self-test the install.

Structural health check of the plugin itself, not your app. Eight checks, banner report.

Reach for it after an install or update, or when something behaves oddly.

/vibe-access

State-aware router.

Reads your .vibe-access/ state and agent-access.json, then names the one next command and why. Never runs a mutating step on its own.

Reach for it when you are not sure where in the sequence you are.

02 · How it's built

Map, gate, prove. Refuse where it matters.

The access work runs in three stages: agent affordances → agent-facing API → MCP server. vibe-access owns the middle. It maps what your app already exposes, scaffolds what is missing, and writes it into a manifest an agent can read cold. The manifest is the embryo of your eventual MCP server, not the server itself; graduating it stays a deliberate, manual step.

Affordances are dev (env-gated, never ships) or prod-safe (runs under the caller's own auth, no elevated access). seed, reset, and capture can never be tagged prod-safe, and that is a refusal enforced at three layers: the manifest schema rejects it, the engine throws if you route around it, and the scaffolder will not apply a dev-tier file missing the vibe-access:dev-gate marker. There is no flag that lets a seed endpoint into production.

It is deep on Firebase Cloud Functions: hosting-rewrite route detection and ID-token auth mapping. Next.js and Express report not-yet-implemented instead of guessing, and the agnostic path writes what you learned to an adapter-notes file that seeds the next real adapter. Dogfooded on WeSeeYouAtTheMovies: 84 routes scanned, 85 affordances, verify 76/85 with all 9 fails classified, and 7 plugin bugs surfaced and fixed in the same session with regression tests.

Seed, reset, and capture can never be prod-safe. A refusal, not a warning, enforced in the schema, the engine, and the scaffolder.
03 · Get it

Install.

Stable marketplace

Tagged releases, promoted via the Vibe Plugins marketplace.

/plugin marketplace add estevanhernandez-stack-ed/vibe-plugins
/plugin install vibe-access@vibe-plugins

Scan and map are read-only against your source. Scaffold is backup-wrapped and dev-gated; verify is local-only unless you force it. Deep on Firebase Cloud Functions; honest not-yet-implemented for other stacks.