Every edit a Dokly-connected agent makes to a page you've already published has always waited for a human to say yes — that part isn't new. What's new is where you say it. Until this week, "review" meant opening the Dokly dashboard, reading the diff, and clicking Approve. Now your agent can show you that same diff, ask you directly, and — if you say yes — approve it itself, all inside the same terminal conversation where you asked for the change in the first place.

What actually shipped#
Three new tools on the MCP server: list_pending_changes, approve_change, and reject_change. They talk to the exact same page_revisions table the dashboard's review banner already used — a proposal an agent creates by editing a published page is now visible and actionable from both places, not just the dashboard.
A session with an agent that has permission now looks like this:
- You ask your agent to update a page that's already live.
- It calls
update_page. Because the page is published, Dokly doesn't touch the live content — it saves a proposal and hands back a change summary (+12 −3, a short diff). - You ask "what's pending?" — the agent calls
list_pending_changesand shows you the same diff. - You say "yes, ship it" — the agent calls
approve_change, and the live page updates.
Say no instead, and reject_change discards the proposal. Either way, nothing you didn't explicitly approve reaches a visitor.
Why this needed its own permission, not just "write access"#
Being able to read drafts and being able to make a page go live are different trust levels, so they're gated separately. list_pending_changes only needs read access — any connected agent can show you what's waiting. reject_change needs write access. approve_change needs the publish scope specifically, the same one that gates direct publishing everywhere else in the MCP server.
That scope comes from one of two places:
- An API key created in Settings → Agent access, with the
publishscope ticked. - Browser sign-in (
claude mcp add --transport http dokly https://mcp.dokly.co/mcp, no key to copy), where it comes from the "Allow publishing directly" box on the one-time consent screen — off unless you tick it, and listed per-agent under Connected apps so you can take it back from one agent without touching the others.
On the Free plan, the publish scope is never granted no matter what's ticked — agents read and propose on every plan, but only a paid plan lets one actually flip the switch on a live page. Browser sign-in works the same way whether you're connecting from a terminal agent like Claude Code or pasting the server URL into claude.ai as a custom connector; both go through the identical consent screen and the identical scope check.
Why this is the shape, not a shortcut#
It would be simpler to let a trusted agent just publish directly and skip the review step entirely — and for agents you've explicitly allowed to, that option still exists (update_page with publish: true, if the key or sign-in allows it). But the default, and the thing worth building well, is the version where nothing goes live silently. Giving the agent the same tool surface for reviewing as it has for writing means you don't need a second app open to supervise the first one. You stay in one conversation, see the real diff, and the agent only acts on an explicit yes.
What this doesn't do yet#
Approval is still one proposal at a time — there's no "approve everything pending" tool, on purpose, since batch-approving a page editing on your live site is exactly the kind of blind trust this feature exists to avoid. And the Connected apps screen where you tick "Allow publishing directly" is dashboard-only; we don't have a screenshot of it in this post because it needs a signed-in session, and this run only had access to Dokly's public pages, not a logged-in dashboard. If you want to see it, it's under Settings → Agent access on any Dokly account.
Try it#
If you already have Dokly connected to Claude Code or Cursor, ask it what's pending on one of your sites — list_pending_changes is read-only, so it costs you nothing to look. Approving still needs the publish scope turned on for that agent, which you control from Settings → Agent access.
Not connected yet? claude mcp add --transport http dokly https://mcp.dokly.co/mcp works with no key — Dokly opens in your browser to sign you in.
Something not working the way this post describes? Reply to this post or use the contact page — it reaches me directly.
Changelog entries#
Review pending changes from the terminal · Added · New MCP tools list_pending_changes, approve_change, and reject_change let a connected agent show you — and, with your permission, act on — the same page-approval queue the dashboard's review banner uses.