API & MCP Development
For companies that already run a service— this is contract development. We take your SaaS, your internal systems and your member platform, and make themsomething AI can operate directly. “We are being asked to support MCP for our own service.” “AI agent support has become the difference against competitors.” We build both the connection point (the API) and the hand AI works with (MCP), from the design up, to the same pattern we run in production on two of our own SaaS products.

MCP is the “hand” you give an AI.
AI has become capable, but on its own itcannot touch your data. Pasting a screenshot to explain the situation, then copying the answer back by hand — that is what is happening in most workplaces right now.MCP (Model Context Protocol)is the common standard by which an AI operates an external system directly. If the API is “the entrance to the system,” MCP is “the hand the AI uses to open it.” Only with both in place does an AI stop being an adviser that merely looks and become a colleague that actually does the work.
API (the connection point)
A window that lets the outside world read and write in a defined form. Without it, no AI can reach further than the screen.
MCP (the AI’s hand)
The API translated into tools an AI can understand. It can be called as is from Claude, ChatGPT, Cursor and other supported clients.
Documentation (the manual for AI)
A reference for people, plus an llms.txt for an AI to read whole. The AI at the other end works out how to use it on its own.
What becomes possible once it is connected.
Every one of these is a use we actually run on our own CMS. There is no new app to learn.Just talk to the AI you already useand the system moves.
Tell the AI, and the data moves
“Draft an announcement with this content.” “List last week’s sign-ups.” The AI reads and writes your system directly, so the step of opening a screen and typing by hand disappears.
It connects to your other tools
With an API in place, tools other than AI can call it too. Integrations with core systems, spreadsheets and external services can be added without a fresh development project each time.
Anyone in the company can operate it, at the same quality
Input rules and required fields are validated on the API side. Work that only a specialist could touch can now be run safely by anyone, through the AI.
Every action leaves a record
When, which key and what it did — all recorded in the audit log. The more work you hand to an AI, the more it needs to be traceable afterwards.
Dangerous actions are stopped by design
“Nothing is published unless explicitly asked.” “A key holds the permissions of exactly one company.” We build defaults into the design so that accidents cannot happen. The protection is structural, not a matter of operational rules.
The AI learns how to use it by itself
Leave an llms.txt in place and the AI at the other end reads the spec and implements against it on its own. Documentation in the AI era is documentation that never stalls on “I don’t know how to use this.”
The example is the API and MCP of a CMS we built and published ourselves.
The CMS inside the site operations platform Webharu runs has a REST API (article CRUD, categories, images) and an MCP server (8 tools), with developer documentation and an llms.txt published alongside. You can look at a working example of the production-ready form — authentication, rate limiting, audit logs, self-issued keys and revocation included — exactly as it stands.
There are three ways in.
Where you start depends on the state of the system you already have. If you are unsure, we make the call for you in a free consultation.
MCP Starter
Start read-only on your existing API¥2,500,000(excl. tax)
No writes — an entry point that designs the risk of accidents out. Roughly 4–6 weeksAPI + MCP Full Pack
When the API has to be built too¥5,000,000(excl. tax)
Authentication, audit logs, two-stage safeguards against mis-operation and public documentation, all inFull Integration
Full write access, multiple AI clients, system by system¥10,000,000and up (excl. tax)
From requirements definition, quoted individually* All figures shown are approximate and exclude tax. For reference, outsourcing an API platform with authentication and audit logs runs to ¥6,000,000–¥10,000,000 and beyond at Japanese market rates (published rates from GXO Inc., a Japanese systems-development firm, as of 2026), and ¥1,500,000–¥2,000,000 per person-month with a major systems integrator. Because we have already implemented and run this same configuration in production on two of our own SaaS products,we pass the value of that established pattern back into the price. A formal quote is presented after the discovery call, andwe never change the figure once work has started. Large projects spanning multiple departments are taken on asLarge-Scale & Enterprise Development.
What is included, what is not
No exaggeration. We set out clearly what the Full Pack at¥5,000,000does and does not include.
Included.What this price includes
- One 60-minute discovery call(mapping out the work you want to hand to AI)
- REST API design and implementation(reads and writes on the target data, validation rules included)
- MCP server implementation(connectable from Claude Code, Claude Desktop, Cursor and others)
- Authentication and key management(shown only at issue, stored hashed, revoked the moment it is disabled)
- Rate limiting and permission scope design
- Audit logs(a record of when, which key and what it did)
- A full set of public documentation(a reference for people plus llms.txt)
- Connection testing (through to verifying connectivity from a real AI client)
- 30 days of bug fixes after launch (minor change requests up to twice as well)
Optional.What is not included (billed separately)
- Building the internal system you are connecting to, from scratch → ¥10,000,000and up
- Integration design with core systems and external SaaS
- Internal training and manuals
- Ongoing operation, monitoring and keeping up with API spec changes after launch → monthly maintenance¥150,000and up
- Pass-through costs such as servers and AI usage fees
What it means to hand an AI the keys.
Connecting a system to an AI brings convenience and, with it, the risk of things being deleted or published without anyone asking. Operational rules cannot hold that line, sowe stop it in the design. Here is the thinking we have implemented in our own CMS.
Defaults sit on the safe side
Nothing is published unless explicitly asked, and deletion is never exposed to the outside. The default state is one where an AI cannot do something irreversible in the flow of a conversation.
Permissions only as far as they are needed
A key holds one scope and nothing more; it never reaches other data or administrative functions. We narrow what each key can do from the outset.
Every action recorded, stoppable at any time
Every action stays in the audit log, and a key expires the instant it is disabled. We also record who issued each key, so the trail survives a change of staff.
How we get you connected.
Discovery Call
One 60-minute session. We ask what work you want to hand to AI, and what you never want it to touch.
Design
We decide the unit of each operation, the permissions and how to stop it. This is eighty percent of the quality.
Build and connection testing
We build the API and the MCP server, and verify connectivity from a real AI client.
Documentation published
We deliver a reference for people and an llms.txt. Later extensions can be driven by an AI reading them.
We’re a small company, so we keep our promises explicit.
- Team
- Our founder plus a contract team of about five people, splitting design, implementation and verification. The founder is always your point of contact and always owns quality.
- If anything happens
- Every delivery includes the code, a style guide and a manual for updating the site with AI. Even if something were to happen to our founder, you can hand the project to another company exactly as it stands.
- Pricing
- We present a formal quote after the initial hearing, andwe never change the price once work has begun.
- Proof
- The business was founded in May 2020 and incorporated in June 2026. Our work ispublished in full— and this site itself is one of the things we built.
Ending the “we adopted AI and still copy and paste” problem.
Most of the time, AI adoption fails not because of the AI’s capability but becausethe AI cannot touch your own data. Provide the connection point and the AI already in use inside your company can run real work as it is. Bring us just one thing to start with: which tasks you want to hand to AI. Whether it is technically possible is our call to make.
* This service isfor companies that already have a service or an internal system. For those who want to build one themselves as an individual developer, we are preparing a course on the implementation steps.
We publish the record of the build, too.
We write up the design decisions behind implementing an API and an MCP server on our own CMS, all the way to publishing the developer documentation.
Give your AI a hand to work with.
Consultations are free.
Even if all you want is a verdict on “can this be handed to AI?”, do get in touch.


