Everyone can generate an interface now. Nobody can generate a backend they would put customer data in. AppEngine is the half that has to be right — identity, permissions, files, money, audit — already built, already running, and already callable by your agent. You go to market on the part people actually pay for.
You will have a beautiful interface by lunchtime. Then comes the half nobody demos — permissions, tenancy, audit, payments, uploads, retries — where a confident guess is a data breach rather than a broken button. That is where AI-built projects stall.
An afternoon’s work, and genuinely good.
Months of it. None of it is what your customers are paying you for.
Every business object you were going to model — staff, payroll, invoices, orders, tickets, leads, shifts — already exists, with permissions, history, search and an audit trail on it. You are not choosing a database. You are skipping the eighteen months that come after one.
Add your own and it behaves exactly like the built-in ones — same permissions, same search, same history, same admin screens. There is no scaffolding step.
Every one of these is a project on its own, and each is the kind of thing that looks finished long before it is safe.
Email and password, Google, Apple and Facebook, magic links, invitations, blocklists, two-factor and device management — with sessions and refresh handled for you.
Most teams bolt an agent onto a finished API and spend months writing tool definitions by hand, then discover the model can claim to be anybody. Here, marking a method callable is enough — the platform publishes it, describes it, and injects the identity itself.
list_services → 41 callable methodsget_schema("lead") → 22 fields, 4 requiredcreate("lead", { … }) → lead_9f2aorgId + user ← injected by registryOne endpoint speaks MCP, so Claude, Cursor or anything else that talks the protocol can read your services and act on them — with the same permission model your staff sign in under, not a second set of keys.
list_servicesWhat this organisation exposes — the same manifest the in-process agent reads.
describe_serviceThe shape of one service: its methods, their arguments, what is required.
call_serviceRun it for real. Org and user come from the headers, never from the model.
http://localhost:3300/mcpYour machinehttps://appengine.appmint.io/mcpLive{
"mcpServers": {
"appengine": {
"url": "https://appengine.appmint.io/mcp",
"headers": {
"orgid": "<org>",
"Authorization": "Bearer <token>"
}
}
}
}Drop this into your client’s MCP settings. Requests without a bearer token are refused.
A gateway in front of everything your business runs on — authenticated, rate-limited, monitored and audited in one place. Swap a vendor and the calls your app makes do not change. No drawer full of credentials, no per-tool SDK to learn.
POST /v1/payments/charge{ "contact": "amara", "amount": 1840000 }↓ 200 OK · 41ms{ "status": "succeeded", "id": "ch_3PdQ…" }It writes plausible backend code, which is a different thing. A hallucinated permission check does not throw an error — it silently returns another customer’s record. The bottleneck was never typing the code; it is knowing that identity, tenancy, audit and money are correct, and staying certain of that after a hundred more changes.