Run it · MCP
One endpoint, and the install snippet is a bare URL
Everything else is negotiated: the client discovers the authorization server from a 401, registers itself, and authorises with PKCE. Fifteen tools cover workspace state, contacts, conversations, agents, signals, integrations and the prospect database.

HubSpot
Connected

Slack
Connected

Google Calendar
Connected

Attio
Connected

Zapier
Not connected
Webhooks
Connected

Pipedrive
Not connected

Cal.com
Not connected
What is actually going on
Every claim below is followed by the mechanism under it, because a claim without a mechanism is a slide.
A token carries the authorising person's scopes, not the workspace's
A viewer who connects an assistant gets an assistant that can read. Membership is re-read on every call, so a demotion takes effect immediately rather than when the token expires.
Nothing in the set sends a message to a prospect
Outbound carries a compliance verdict and a platform-injected footer produced by the launcher. An assistant able to send would be a way around the one gate treated as architectural.
The advertised list is a convenience; the second check is the boundary
A tool declares its scope and level, the list is filtered, and the call is checked again at execution.
Some tools spend, and they say so
Revealing prospect details and importing them both cost credits. That spend is governed by the ledger like everywhere else, and by the permission your membership already carries.
Step by step
How mcp & api runs
- 1
Point
Give your client the endpoint URL. Nothing else.
- 2
Discover
A 401 carries the authorization server. The client registers itself.
- 3
Authorise
PKCE, on our own sign-in, with your scopes, not the workspace's.
- 4
Work
Read state, manage agents, suppress an address, announce a meeting, search the corpus.
The numbers
Facts, not adjectives
Every figure here is a real value from the running product. A cadence from the scheduler, a price from the credit table, a limit from the ramp. A marketing page that invents a limit is a support ticket with a delay on it.
- Transport
- Stateless streamable HTTP, no SSE
- Discovery
- RFC 9728 + RFC 8414
- Registration
- RFC 7591
- Auth
- PKCE S256
- Tools
- 15. None of them send
MCP & API, honestly
Is there a per-tool consent screen?
No. A token is read, or read and write, and write unlocks every manage-level tool your role already permits. That is the decision, stated plainly, rather than an accident.
Can it delete my organisation?
No. Destruction at account level is out of every belt, on every surface.
Run it
The team that does all of the above
Keep reading
All featuresMCP & API is one part of it. The rest runs too.
Sourcing, enrichment, intent, copy, sending, replies and reporting are one product with one bill and one gate. Connect a channel and the whole motion starts.
Start with sales. $2,000 or $5,000 onboarding, then at least $250 monthly credit funding.