Connect

Add the MCP. Log in once. Your agent does the rest.

Open your website’s repository in Claude Code, Codex, Cursor or any tool that speaks MCP. Three things to do, then ask. When the agent reports back that the site is live, invite the client.

Three steps

1. Add the Tusk MCP server to your tool’s MCP config. It is on npm; there is nothing to install.

{ "mcpServers": { "tusk": { "command": "npx", "args": ["-y", "@tuskcms/mcp"] } } }

2. Log in once. Run this in the site’s repository, with your site’s slug from the Tusk dashboard. It prints a link; open it where you are signed in to Tusk and press Approve. The screen names the one site and the exact actions you are granting. The token is saved on your machine and never shown to you or the agent.

npx @tuskcms/mcp login --site <your-site-slug> --scopes scan,fields,content,publish,deploy,invite

3. Ask.

Connect this site to Tusk CMS.

Not in Tusk yet? Add the site in the dashboard first: a name and its address, one minute. That gives you the slug for step 2.

What the agent does

StepWhat happens
It registers the siteUnder the slug you logged in with. Nothing is created or changed on your website.
It marks your HTMLOne data-tusk attribute per editable thing, in your own files. Attributes only. No layout, styles, markup order or wording change.
It wires your buildTwo shipped scripts pull the published content and photos and write them into the built, marked HTML, so a deploy serves your own files and never calls Tusk at runtime.
It wires your hostIt sets up a deploy hook in your own host and records it in Tusk, so a Publish rebuilds the site: on Netlify or Cloudflare it can create the hook itself, on Vercel you create it and paste the link. Tusk never hosts the site, and with a deploy hook that link is all it holds of your host.
It proves it went liveIt publishes once and checks that the publish reached the site before it reports back.

Expect a few minutes for a small site, most of it your host’s first build. It will still stop for the things only you can do: signing in to your host, and setting TUSK_TOKEN in your host’s environment if it cannot reach your host’s CLI. It cannot create a Tusk account and cannot pay for anything.

Then invite the client

Open the site in Tusk: Manage › People › Give a client access. They get an email with a link, continue with Google or Microsoft, and land in the editor on their site, seeing only the fields that were marked. No training call. If you granted invite at login, you can ask the agent to do this for you once the site is live.

What the token can and cannot do

It can
  • Act on the one site you named at login, and no other.
  • Do only the actions on the approval screen: scan, mark fields, edit content, publish, record the deploy hook, invite.
  • Expire by itself after 30 days (up to 90 with --ttl). Your site and your client are unaffected; only the agent needs a fresh Approve.
  • Be revoked earlier in the dashboard, under Studio settings > Connected tools & devices. You get an email the moment it is approved.
It cannot
  • Reach your other Tusk sites, or mint another token.
  • Touch your code or hosting on its own. Tusk never hosts the site, and with a deploy hook that link is all it holds of your host.
  • Show your agent the build token: the MCP writes it straight into a git-ignored .env and hands back only a masked preview. It lets a build read published content and nothing else, and lives in .env and your host’s environment variables only.

Without an MCP

If your tool cannot use MCP servers, paste this line instead. The agent reads the public guide and does the same steps by hand, driving your browser as well as your repository. Budget 30–40 minutes for a small site, and expect it to stop a few times for a click only you can make: your host’s sign-in, the build token, the domain.

Connect this site to Tusk CMS. Read https://tuskcms.com/llms-full.txt first and follow it exactly.

Everything the agent reads is public and contains no token, key or account identifier: the guide, the same at GET /api/connect, the index, a marked-up example page, and the two build scripts tusk-pull.mjs and tusk-apply.mjs. Prefer to do it by hand? The developer docs cover the same four steps for a human reader.