The Scorezilla MCP server lets Claude, Cursor, and any other MCP-aware AI assistant read your leaderboard data and generate ready-to-paste integration code — including a one-shot bootstrap_leaderboard that provisions a game + board + keys and hands you back working code in a single tool call.
MCP — Model Context Protocol — is an open standard that lets AI assistants connect to data sources and tools. The Scorezilla MCP server exposes your leaderboards as something Claude can read and reason about. Ask "what's on my high-scores board?" — Claude actually knows.
It's a small Node binary you install once. From then on, any MCP-compatible client (Claude Desktop, Cursor, Continue.dev, custom integrations) can use it to query your Scorezilla data on your behalf.
Nine tools live today, gated behind a closed-beta flag. Five read: list_games, list_boards, get_keys, get_board_top_n, get_sdk_snippet. Four create-only: bootstrap_leaderboard (one-shot new game + board + keys + code), plus create_game, create_board, and mint_key for provisioning against an existing game. Ask for beta access via the early-access form.
Three real scenarios. Each one would be tedious — read the docs, paste keys, write a script, run it, debug. With MCP installed, it's a sentence.
high-scores today. Let me check the top entries to see if any look suspicious.swiftpaw_xx is sitting at 12.8 million — about 26× higher than your previous #1. The score is already flagged by anomaly detection. Three options:BattleScene's game-over event. Show top 10 on the game-over screen.battle-of-glyphs with the existing high-scores board.main.ts, hook the game-over event in BattleScene.ts, and add a LeaderboardOverlay component for the game-over screen. Confirm and I'll proceed.
The MCP server is read-only. It surfaces information — your games, your boards, your scores. Cursor or Claude does the file editing. This separation means you can install the MCP server safely without granting an AI agent write access to your repo.
hostingPattern: "client_with_server" and I'll wire server-signed submissions so scores can't be forged. Want the widget snippet in your index.html?
Two minutes. One config file. The server runs locally; your secret key never leaves your machine.
Open ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or the equivalent on your OS, and add:
Quit and re-open Claude Desktop (or your MCP client). You should see scorezilla appear in the available tools list.
Ask: "What Scorezilla games do I have?"
If you get back a list, you're done. If you get an error, check that the API key has read access (most do by default) and that your network can reach api.scorezilla.dev.
Use a scoped read-only key. In the dashboard, generate an MCP-specific key with read-only permissions. Even though the server itself can't write, scoping the key adds a second layer of safety.
Once the server is connected, paste this into Claude or Cursor. It scaffolds a tamper-proof board end-to-end — game, board, keys, and server-signed integration code — in a single turn:
The MCP returns the secure scorezilla/server snippet (HMAC-signed via
createScoreSubmitHandler) plus the keys baked in. For a casual game jam where
cheating doesn't matter, drop the "tamper-proof / server-signed" line and you'll get the
simpler no-backend (public-key) path instead.
The MCP server exposes these tools to AI clients. Five read-only, four create-only — all require a valid API key. Destructive ops (edit, archive, delete, key revocation) stay in the dashboard.
bootstrap_leaderboard uses internally.More tools (player rank lookup, submission audit, validation) are on the roadmap — call them out in early-access feedback if you need a specific shape and we'll prioritize.
The MCP server is intentionally narrow. Strong opinions about what an AI-facing tool should and shouldn't do — these are the things this server will never let an AI do, no matter how the request is phrased.
api.scorezilla.dev. No telemetry, no third-party analytics. Audit the source — it's open. The temptation with MCP servers is to make them do everything. Let Claude submit scores. Let Cursor delete leaderboards. Let an AI rotate your keys.
We think that's a mistake. A good MCP server is a window, not a remote control. It surfaces context — accurately, safely, in real time — and trusts the human and their AI client to decide what to do with it.
Every "won't do" on that list above is a thing some users will eventually ask for. We'll keep saying no. The boring answer ("install the SDK and write three lines yourself") is almost always the right one.
What's coming, in order. Subject to change based on what early-access folks actually need.