BlinkBox
Open-source automation platform (Zapier / Make / n8n alternative) with a native MCP server β connect Claude Code, Cursor or ChatGPT and let the agent build, run and debug your workflows.
Free hosted tier at blinkbox.net (no card) Β· self-host with Node 22 + MongoDB + Redis Β· MIT.
What it does
- MCP server β the whole platform is exposed over the Model Context Protocol (Streamable HTTP). Your coding agent lists, creates, runs, activates and debugs workflows with tool calls β see Use it from Claude Code
- Agent skill β a
SKILL.md that teaches the agent node fields, expression syntax and execution rules, so a working flow takes ~4 tool calls instead of ~12 of guessing
- Drag-and-drop canvas β everything the agent builds is a normal workflow you can open and edit visually
- AI Agents β LLM nodes that reason over data and output structured results
- Headless scraping β full Chromium pool, defeats anti-bot, renders JavaScript
- Code sandbox β write JavaScript in an isolated V8 sandbox with memory limits
- 250+ integrations β Gmail, Slack, Stripe, GitHub, Notion, Airtable, Shopify, and more
- Encrypted credential vault β AES-256-GCM; secrets never leave the server decrypted
Use it from Claude Code, Cursor or ChatGPT (60 seconds)
-
Sign up at blinkbox.net β Dashboard β MCP β create an API key.
-
Add the server to your client:
claude mcp add --transport http blinkbox https://mcp.blinkbox.net/mcp \
--header "Authorization: Bearer <your key>"
{
"mcpServers": {
"blinkbox": {
"url": "https://mcp.blinkbox.net/mcp",
"headers": { "Authorization": "Bearer <your key>" }
}
}
}
Clients that can't send headers can pass the key in the URL instead: https://mcp.blinkbox.net/mcp?key=<your key>.
-
(Recommended) install the skill so the agent knows the node catalog and expression syntax:
mkdir -p ~/.claude/skills/blinkbox && curl -fsSL \
https://raw.githubusercontent.com/blinkboxhq/Blinkbox/main/.claude/skills/blinkbox/SKILL.md \
-o ~/.claude/skills/blinkbox/SKILL.md
-
Ask for what you want:
"Every morning at 8, find dentists in Berlin on OpenStreetMap that list a website, email and phone, dedupe against my Google Sheet and append the new ones."
The agent calls create_automation, runs it with run_automation, reads get_execution_logs when something fails, and activate_automation when it's green. OAuth apps (Google, Slack, Notionβ¦) are connected once by you in the dashboard β the agent never sees your tokens.
Tools: list_automations Β· get_automation Β· create_automation Β· run_automation Β· activate_automation Β· deactivate_automation Β· rename_automation Β· delete_automation Β· list_executions Β· get_execution Β· get_execution_logs Β· list_nodes Β· get_node Β· list_node_actions Β· list_credentials Β· create_credential Β· blinkbox_api_get Β· blinkbox_api
Self-hosting? The same server is at <your backend>/api/mcp β create keys in your own dashboard.
Stack
| Layer | Tech |
|---|
| Frontend | React 18 + Vite + Tailwind CSS + ReactFlow |
| Backend | Node.js + Express + MongoDB Atlas + Redis |
| AI | Anthropic Claude (primary) β Groq β Gemini (fallback) |
| Scraping | Puppeteer + Chromium |
| Execution | Cursor-based distributed engine, 4 worker cells |
| Deployment | Railway (nixpacks) |
Local setup
Prerequisites
- Node.js β₯ 22
- MongoDB Atlas cluster (or local MongoDB)
- Redis (local or Upstash)
1. Clone
git clone https://github.com/blinkboxhq/Blinkbox.git
cd Blinkbox
npm install
cp apps/backend/.env.example apps/backend/.env
Edit apps/backend/.env β at minimum you need:
MONGODB_URI=mongodb+srv://...
REDIS_URL=redis://localhost:6379
JWT_SECRET=your-32-char-secret
ENCRYPTION_KEY=your-exactly-32-char-key
ANTHROPIC_API_KEY=sk-ant-... # enables the AI workflow builder behind create_automation
3. Run
cd apps/backend && npm run dev
cd apps/frontend && npm run dev
Open http://localhost:5174.
Environment variables
Required
| Variable | Description |
|---|
MONGODB_URI | MongoDB connection string |
REDIS_URL | Redis connection string |
JWT_SECRET | β₯ 32 chars, any random string |
ENCRYPTION_KEY | Exactly 32 chars β used for credential vault AES encryption |
AI (at least one recommended)
| Variable | Description |
|---|
ANTHROPIC_API_KEY | Enables the AI workflow builder (Claude) used by the create_automation MCP tool |
GROQ_API_KEY | Fallback LLM (Llama 3.3 70B) |
GOOGLE_AI_KEY | Fallback LLM (Gemini 2.0 Flash) |
OAuth integrations (optional)
| Variable | Description |
|---|
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET | Gmail, Drive, Calendar OAuth |
SLACK_CLIENT_ID / SLACK_CLIENT_SECRET | Slack OAuth |
GITHUB_CLIENT_ID / GITHUB_CLIENT_SECRET | GitHub OAuth |
MICROSOFT_CLIENT_ID / MICROSOFT_CLIENT_SECRET | Microsoft 365 OAuth |
NOTION_CLIENT_ID / NOTION_CLIENT_SECRET | Notion OAuth |
AIRTABLE_CLIENT_ID / AIRTABLE_CLIENT_SECRET | Airtable OAuth |
Deployment
| Variable | Description |
|---|
BACKEND_PUBLIC_URL | Public-facing backend URL (e.g. https://api.blinkbox.net) β required for OAuth callbacks |
FRONTEND_URL | Frontend URL for CORS allowlist |
PORT | Backend port (default: 3000) |
Architecture
βββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Frontend (Vite) β
β Dashboard Β· Workspace Canvas Β· MCP keys β
βββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββ
β REST API
βββββββββββββββββββββββββΌββββββββββββββββββββββββββββββ
β Backend (Express) β
β Auth Β· Automations Β· Executions Β· Credentials β
β MCP server Β· AI builder Β· OAuth Β· Webhooks β
ββββββββββββ¬βββββββββββββββββββ¬ββββββββββββββββββββββββ
β β
ββββββββΌβββββββ ββββββββΌβββββββ
β MongoDB β β Redis β
β Atlas β β Queues β
βββββββββββββββ ββββββββ¬βββββββ
β
βββββββββββΌββββββββββββ
β Execution Workers β
β (4 cursor cells) β
β Chromium pool β
βββββββββββββββββββββββ
Execution engine
Workflows run as cursor-based state machines. Each execution is a MongoDB document with a cursor array. Workers claim cursors atomically via arrayFilters, run the node handler, advance the cursor, and release. Redis queues decouple trigger fan-out from execution. A resumer process recovers crashed executions every 5 seconds.
Node system
Every integration is a node with two halves:
- Frontend (
nodeRegistry.js) β config panel, icon, label, category
- Backend (
nodes/) β stateless handler async (config, context) => result
The same backendType key connects both sides. 250+ nodes are registered.
AI workflow builder
create_automation (the MCP tool) hands your description to a server-side builder:
"When a new Stripe payment comes in, look up the customer in HubSpot, and send a Slack alert to #revenue"
The builder calls Claude with the node knowledge base and forced tool use, and returns a fully configured, canvas-correct workflow β real field values, variable chaining ({{trigger.data.from}}), node positions β as a draft you can run, inspect and activate from the agent or the UI.
Provider fallback chain: Anthropic β Groq β Gemini
Security
- JWT auth on all API routes, workspace-scoped queries
- AES-256-GCM credential encryption (key never stored in DB)
- SSRF guard on all outbound HTTP requests
- Code sandbox: isolated V8 with memory/time limits (
isolated-vm)
- Shell tool nodes gated behind
ENABLE_SHELL_TOOLS=true (off by default)
- OAuth state tokens (CSRF protection), postMessage to explicit origins only
- Rate limiting on webhook triggers (Redis-backed, survives restarts)
Deployment on Railway
- Create a Railway project, add the repo
- Set all required env vars in Railway dashboard
- Set
BACKEND_PUBLIC_URL to your Railway backend URL
- Register that URL as an OAuth redirect URI in Google Cloud Console (if using Gmail)
The nixpacks.toml in apps/backend/ installs Chromium and all native deps automatically.
License
MIT