AppEngine

Ship the product. Not the plumbing.

Everyone can generate an interface now. Nobody can generate a backend they would put customer data in. AppEngine is the half that has to be right — identity, permissions, files, money, audit — already built, already running, and already callable by your agent. You go to market on the part people actually pay for.

The wall

AI can build your screens. It cannot build your backend.

You will have a beautiful interface by lunchtime. Then comes the half nobody demos — permissions, tenancy, audit, payments, uploads, retries — where a confident guess is a data breach rather than a broken button. That is where AI-built projects stall.

What the AI gets right
  • Login screenThe form. Not what happens behind it
  • Dashboard layoutGrid, cards, spacing, hierarchy
  • Data tableSorting, paging, empty and loading states
  • Filter barChips, dropdowns, clear-all
  • Create formFields, labels, inline validation messages
  • ChartsAxes, tooltips, legends, responsive sizing
  • ResponsivePhone, tablet and desktop from one pass
  • Dark modeTokens flipped, contrast held

An afternoon’s work, and genuinely good.

What it stalls on
  • Real authenticationSessions, refresh, OAuth, magic links, 2FA
  • Row-level permissionsWho may see which record, enforced server-side
  • Multi-tenancyOne customer never seeing another’s data
  • Audit trailWho changed what, when, and what it was before
  • PaymentsCheckout, refunds, webhooks, reconciliation
  • File storageUploads, virus scanning, signed URLs, quotas
  • Background jobsRetries, dead letters, scheduling
  • Search across everythingNot a LIKE query on one table

Months of it. None of it is what your customers are paying you for.

What you are not building

Your first day starts on year three.

Every business object you were going to model — staff, payroll, invoices, orders, tickets, leads, shifts — already exists, with permissions, history, search and an audit trail on it. You are not choosing a database. You are skipping the eighteen months that come after one.

238business objects, live before you write anything
  • People & payroll41
    EmployeePayroll RunPay StubLeave RequestBenefit PlanJob PostingInterviewOfferOrg ChartPerformance Goaland more
  • Money & banking33
    Bank AccountBank TransferBank CardLoanInvoiceBill PaymentPayoutWalletBudgetand more
  • Selling38
    ProductOrderCartDiscountGift CardReturnRentalInventoryPrice ListTax Ruleand more
  • Customers29
    CustomerLeadCampaignAudienceSupport TicketReservationSigned DocumentPromotionand more
  • Events18
    EventEvent TicketSessionParticipantAccess CardBadgeTrackZoneand more
  • Community21
    PostStoryPageConnectionGroup ChatBookmarkAnnouncementand more
  • Operations26
    Work OrderTimesheetShiftService PointDelivery JobDelivery ZoneDeviceand more
  • Growth17
    AffiliateAffiliate ProgramAffiliate ReferralAutomationWorkflowAI Assistantand more
  • Content15
    PagePostCategoryTagDocumentMessage TemplateSite Noticeand more

Add your own and it behaves exactly like the built-in ones — same permissions, same search, same history, same admin screens. There is no scaffolding step.

The parts nobody demos

The unglamorous half, done properly.

Every one of these is a project on its own, and each is the kind of thing that looks finished long before it is safe.

Sign-in that will survive an audit.

Email and password, Google, Apple and Facebook, magic links, invitations, blocklists, two-factor and device management — with sessions and refresh handled for you.

  • Passwordverified
  • Magic linksent
  • Two-factorconfirmed
  • Session issuedrefresh handled
Built to be driven by AI

Your backend is a set of tools before you write a prompt.

Most teams bolt an agent onto a finished API and spend months writing tool definitions by hand, then discover the model can claim to be anybody. Here, marking a method callable is enough — the platform publishes it, describes it, and injects the identity itself.

agent · your organisationscoped
  • list_services → 41 callable methods
  • get_schema("lead") → 22 fields, 4 required
  • create("lead", { … }) → lead_9f2a
  • orgId + user ← injected by registry
The agent never sets the organisation or the user. It cannot reach another tenant’s data even if it is asked to.
Model Context Protocol

Point your own agent at your own business.

One endpoint speaks MCP, so Claude, Cursor or anything else that talks the protocol can read your services and act on them — with the same permission model your staff sign in under, not a second set of keys.

  1. 01list_services

    What this organisation exposes — the same manifest the in-process agent reads.

  2. 02describe_service

    The shape of one service: its methods, their arguments, what is required.

  3. 03call_service

    Run it for real. Org and user come from the headers, never from the model.

  • Localhttp://localhost:3300/mcpYour machine
  • Productionhttps://appengine.appmint.io/mcpLive
{
  "mcpServers": {
    "appengine": {
      "url": "https://appengine.appmint.io/mcp",
      "headers": {
        "orgid": "<org>",
        "Authorization": "Bearer <token>"
      }
    }
  }
}

Drop this into your client’s MCP settings. Requests without a bearer token are refused.

One API

Two hundred services.
One key.

A gateway in front of everything your business runs on — authenticated, rate-limited, monitored and audited in one place. Swap a vendor and the calls your app makes do not change. No drawer full of credentials, no per-tool SDK to learn.

StripeAuthorization: Bearer appmint_live_•••
POST /v1/payments/charge{ "contact": "amara", "amount": 1840000 }↓ 200 OK · 41ms{ "status": "succeeded", "id": "ch_3PdQ…" }
1
Key to rotate
99.99%
Gateway uptime
<50ms
Added latency
One API keyAppEngine
Before you ask

The questions founders ask.

  • It writes plausible backend code, which is a different thing. A hallucinated permission check does not throw an error — it silently returns another customer’s record. The bottleneck was never typing the code; it is knowing that identity, tenancy, audit and money are correct, and staying certain of that after a hundred more changes.

Get started

Bring a real number and a real calendar.
We’ll show you the first booking inside twenty minutes.

Book a demoNo credit card · cancel any time · your data stays yours