Reference · v2.0.0 · 163 tools

MCP reference

The ReachOut MCP server exposes contacts, campaigns, segments, and analytics as tools your agent can call directly. It speaks JSON-RPC 2.0 over HTTP and SSE. Delegated control-plane calls name their organization and, when applicable, project explicitly.

Endpoint

POST https://api.usereachout.com/mcp
Content-Type: application/json
Authorization: Bearer <api_key>

Transports: http (single request/response) and sse (streaming). Server version is advertised in the initialize response under serverInfo.

Delegated OAuth

Control-plane tools use OAuth 2.1 Authorization Code with PKCE S256. Discover authorization metadata from the MCP endpoint, send the exact MCP audience, and obtain browser consent from the acting user. Request mcp:read for reads, both mcp:write and mcp:governancefor governance writes, and offline_access only when refresh is required.

Access tokens are short-lived and refresh tokens rotate. Every delegated call supplies an explicitorganizationId or projectId; there is no stored organization or project context. Organization API keys remain for legacy organization-scoped data tools and are limited to their explicit project grants for get_organization_overview. Governance tools require a delegated user and otherwise return the stable MCP_USER_DELEGATION_REQUIRED error.

Get an API key

Sign in to the Studio and go to Organization settings → API keys. Click Generate API key, give the key a label (e.g.Claude Desktop), and copy the rok_live_… plaintext from the modal — it is shown exactly once. The server stores only the SHA-256 hash and a 12-char visible prefix, so a key cannot be recovered if you lose it.

The same panel lists every active key with its prefix, label, and last-used time. Revoking a key invalidates the server-side context cache immediately, so any client using it stops authenticating on the next request. Owner/admin role required.

Filtering analytics by website

Analytics tools require a stable projectId. Discover accessible projects withlist_projects; MCP does not persist or switch an active project. An optionalclientId further restricts results to a tracking client owned by that project.

Discover the IDs first with list_tracking_clients, then pass one in:

# 1. list projects
{"method":"tools/call","params":{"name":"list_projects","arguments":{"organizationId":"org_example"}}}

# 2. query one concrete project
{"method":"tools/call","params":{
  "name":"get_analytics_overview",
  "arguments":{
    "projectId":"project_01J6Y0N8V4J5Q2M7K3R9T6W1XA",
    "range":"30d",
    "clientId":"cl_example"
  }
}}

get_organization_overview is a read-only aggregate over the caller's currently authorized project grants. It is not an all-project data mode and never accepts caller-supplied project IDs.

Client setup

Use the same endpoint and bearer token in every MCP client. Keep the key out of committed project files unless you reference it through an environment variable.

Claude CLI / Claude Code

claude mcp add --transport http reachout https://api.usereachout.com/mcp \
  --header "Authorization: Bearer YOUR_API_KEY"

claude mcp list

Codex

# ~/.codex/config.toml
[mcp_servers."reachout"]
url = "https://api.usereachout.com/mcp"
[mcp_servers."ReachOut".headers]
Authorization = "Bearer YOUR_API_KEY"

# Then verify:
codex mcp list

Claude Desktop

{
  "mcpServers": {
    "reachout": {
      "type": "http",
      "url": "https://api.usereachout.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

Cursor, LM Studio, and other MCP clients

{
  "mcpServers": {
    "reachout": {
      "transport": "http",
      "url": "https://api.usereachout.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

Some clients call the key transport; others call ittype. Use HTTP / Streamable HTTP when the client asks for the transport.

Authentication

Every tools/call requires a bearer token. Three token shapes are accepted:

TokenScope
Per-user API key
Studio → Settings → API Keys
Delegated OAuth calls name the organization or project explicitly.
Legacy org-scoped key
Created before user-linking was added
Legacy data tools use the single organization the key was issued for.
Master key (REACHOUT_API_KEY)
Server-level secret, self-hosted only
Self-hosted server access; not part of delegated OAuth.

Unauthenticated methods: initialize, tools/list, ping.

Key format: the server stores a SHA-256 hash of the raw key. Keys never appear in logs. Revoking a key sets revokedAt; subsequent requests with that key return -32002 Invalid API key.

Organization scoping

Delegated control-plane tools include an organizationId or projectIdparameter. Authorization is resolved per request:

  1. Delegated user — the OAuth token identifies the consenting user and granted scopes.
  2. Explicit target — organizationId or a project resolved from projectId.
  3. Legacy key — legacy data tools use only the organization issued to that key.

Membership and project permissions are checked live on every delegated call.

Response envelope

Every successful tool response is a single text block. The first two lines are a human-readable header showing the organization addressed by the call; the rest is JSON.

[organization] Acme Inc (id: org_abc123)
--------------------------------------------------------------
{
  "organization": { "id": "org_abc123", "name": "Acme Inc", "slug": "acme" },
  "result": { /* tool-specific payload */ }
}

The header is part of the text content the model sees, so any well-behaved client will surface the addressed organization to the user on every tool call. For programmatic parsing, strip the header and decode the JSON body — result holds the tool payload, organizationis always present.

Errors are emitted with isError: true and the same header prefix where possible.

Tools — organization management

These tools require delegated OAuth and explicit organization targets.

There is no session-level organization selector. Delegated control-plane calls pass the target identifier on every request; legacy data tools remain scoped to the organization issued to the API key.

Tools — domain surface

Legacy data tools are explicitly organization-scoped to their API key. Control-plane tools require delegated OAuth and explicit targets.

ToolCategoryMode
list_organization_campaigns
List campaigns across accessible active projects.
CampaignsRead
get_organization_campaign_overview
Read campaign results across accessible active projects.
CampaignsRead
list_organization_templates
List templates across accessible active projects.
CampaignsRead
list_organization_assets
List assets across accessible active projects.
CampaignsRead
get_organization_realtime_analytics
Read live analytics across accessible active projects.
AnalyticsRead
list_organization_segments
Read segments and counts across accessible active projects.
ContactsRead
search_organization_contacts
Search contacts across accessible active projects with global pagination.
ContactsRead
get_organization_contact_stats
Read contact counts across accessible active projects.
ContactsRead
list_organization_insights
Read the latest persisted insights across accessible active projects.
InsightsRead
get_organization_analytics_overview
Read scoped overview with period, filters and coverage.
AnalyticsRead
get_organization_analytics_contributions
Read scoped contributions with period, filters and coverage.
AnalyticsRead
get_organization_analytics_pages
Read scoped pages with period, filters and coverage.
AnalyticsRead
get_organization_analytics_refs
Read scoped refs with period, filters and coverage.
AnalyticsRead
get_organization_analytics_devices
Read scoped devices with period, filters and coverage.
AnalyticsRead
get_organization_analytics_events
Read scoped events with period, filters and coverage.
AnalyticsRead
get_organization_analytics_geo
Read scoped geo with period, filters and coverage.
AnalyticsRead
get_organization_analytics_engaged_users
Read scoped engaged-users with period, filters and coverage.
AnalyticsRead
get_organization_analytics_identification_diagnostic
Read scoped identification-diagnostic with period, filters and coverage.
AnalyticsRead
get_project_analytics_contributions
Read scoped contributions with period, filters and coverage.
AnalyticsRead
get_project_analytics_refs
Read scoped refs with period, filters and coverage.
AnalyticsRead
get_project_analytics_devices
Read scoped devices with period, filters and coverage.
AnalyticsRead
get_project_analytics_events
Read scoped events with period, filters and coverage.
AnalyticsRead
get_project_analytics_geo
Read scoped geo with period, filters and coverage.
AnalyticsRead
get_project_analytics_engaged_users
Read scoped engaged-users with period, filters and coverage.
AnalyticsRead
get_project_analytics_identification_diagnostic
Read scoped identification-diagnostic with period, filters and coverage.
AnalyticsRead
create_organization
Create a ReachOut organization and its default project.
OrganizationWrite
get_organization_provisioning
Return the provisioning snapshot of one organization.
OrganizationRead
retry_organization_provisioning
Retry terminal provisioning for one organization.
OrganizationWrite
get_organization_dashboard_stats
Dashboard for active authorized projects, including explicit data availability.
OrganizationRead
billing_usage_get
Organization usage in the current billing period: emails, MCP calls, insights.
OrganizationRead
billing_plans_list
Current plan with its caps and entitlements, and the available plans.
OrganizationRead
get_organization_overview
Aggregate analytics across only the projects authorized for the caller.
OrganizationRead
list_transport_safety_blocks
List active and reviewed transport safety blocks for one organization.
OrganizationRead
remove_transport_safety_block
Remove one transport safety block after live Postal evidence verification.
OrganizationWrite
get_legacy_removal_readiness
Evaluate runtime-local readiness for immutable legacy surface removal.
PlatformRead
approve_legacy_surface_removal
Approve or reject legacy removal for the exact current evidence digest.
PlatformWrite
request_legacy_surface_removal
Disable every legacy wrapper after exact evidence confirmation.
PlatformWrite
get_project_activation_readiness
Evaluate runtime-local readiness for one multi-project activation cohort.
PlatformRead
activate_project_cohort
Activate one ready multi-project cohort with matching evidence.
PlatformWrite
record_runtime_compatibility_floor
Record one attested runtime compatibility floor.
PlatformWrite
list_bot_rules
List canonical global bot rules as a root user.
PlatformRead
create_bot_rule
Create one canonical global bot rule as a root user.
PlatformWrite
replace_bot_rules
Replace the canonical global bot-rule set as a root user.
PlatformWrite
delete_bot_rule
Delete one canonical global bot rule as a root user.
PlatformDelete
list_projects
List the projects the delegated user can access in one organization.
ProjectsRead
get_project
Return one project the delegated user can access.
ProjectsRead
create_project
Create an additional project in one organization.
ProjectsWrite
update_project
Rename one active project.
ProjectsWrite
archive_project
Archive one non-default project.
ProjectsWrite
restore_project
Restore one archived project.
ProjectsWrite
set_default_project
Make one active project the organization default.
ProjectsWrite
get_project_provisioning
Return the provisioning snapshot of one project.
ProjectsRead
retry_project_provisioning
Retry terminal provisioning for one project.
ProjectsWrite
list_project_members
List the member grants of one project.
ProjectsRead
grant_project_member
Grant one organization member a role on one project.
ProjectsWrite
update_project_member_role
Change the project role of one existing member grant.
ProjectsWrite
revoke_project_member
Revoke one member grant from one project.
ProjectsDelete
list_api_key_project_grants
List the explicit project grants of one organization API key.
ProjectsRead
grant_api_key_project
Grant one organization API key a role on one explicit project.
ProjectsWrite
update_api_key_project_role
Change the project role of one existing API-key grant.
ProjectsWrite
revoke_api_key_project
Revoke one API-key grant from one project.
ProjectsDelete
get_current_organization
Return the organization fixed to this legacy MCP API key.
OrganizationRead
list_organizations
Return only the organization fixed to this legacy MCP API key.
OrganizationRead
list_timezones
List supported IANA timezone names.
OrganizationRead
list_contacts
Query contacts with search, filters, sort, and pagination.
ContactsRead
search_contacts
Search and filter contacts in one authorized project.
ContactsRead
list_contact_fields
List custom contact fields available for filters and edits.
ContactsRead
create_contact_field
Register a new custom contact field.
ContactsWrite
update_contact_field
Update or rename a custom contact field.
ContactsWrite
delete_contact_field
Delete a custom contact field and strip stored values.
ContactsDelete
list_duplicate_contacts
Find duplicate-email contact groups.
ContactsRead
deduplicate_contacts
Bulk merge or delete duplicate contact groups.
ContactsWrite
resolve_duplicate_contacts
Resolve one duplicate contact group with an explicit keeper.
ContactsWrite
get_contact
Get a single contact by ID.
ContactsRead
create_contact
Create a contact in the API key's organization.
ContactsWrite
list_campaigns
List campaigns, optionally filtered by status.
CampaignsRead
get_campaign_stats
Fetch delivery and engagement stats for one campaign.
CampaignsRead
list_segments
List segments in the API key's organization.
CampaignsRead
send_campaign
Trigger a campaign send for its assigned segment.
CampaignsWrite
get_analytics
Read daily, weekly, or monthly analytics summaries. Optional clientId to filter to one website.
AnalyticsRead
list_tracking_clients
List website tracking clients and embed credentials.
AnalyticsRead
create_tracking_client
Create a website tracking client and optional secret.
AnalyticsWrite
delete_tracking_client
Delete a website tracking client.
AnalyticsDelete
list_domains
List email sender domains for the API key's organization.
CampaignsRead
get_domain
Get one email domain including its DNS verification records and status.
CampaignsRead
verify_domain
Re-check DNS for an email domain against Postal and refresh its status.
CampaignsWrite
add_domain
Add a custom email sender domain by hostname; returns the DNS records to publish.
CampaignsWrite
delete_domain
Delete an email sender domain (blocked when MCP deletions are disabled, default, or in use).
CampaignsDelete
get_analytics_overview
Aggregate visitors, sessions, pageviews, bounce, and duration. Optional clientId to filter to one website.
AnalyticsRead
get_top_pages
List top pages with pageviews, uniques, and visible time. Optional clientId to filter to one website.
AnalyticsRead
get_top_referrers
List top referrer hosts. Optional clientId to filter to one website.
AnalyticsRead
get_realtime_analytics
Return realtime visitors and optional details for one project.
AnalyticsRead
list_insights
List generated insight reports.
InsightsRead
get_insight_report
Get one insight report with evidence rows.
InsightsRead
run_insights
Run all active insight definitions now.
InsightsWrite
run_insight
Run one insight definition now.
InsightsWrite
archive_insight
Archive one custom insight; its past reports stay available.
InsightsWrite
create_custom_insight
Create and run a custom insight from a natural-language prompt.
InsightsWrite
update_contact
update contact in one authorized project.
ContactsWrite
delete_contact
delete contact in one authorized project.
ContactsDelete
bulk_update_contacts
bulk update contacts in one authorized project.
ContactsWrite
bulk_delete_contacts
bulk delete contacts in one authorized project.
ContactsWrite
list_contact_lists
list contact lists in one authorized project.
ContactsRead
create_contact_list
create contact list in one authorized project.
ContactsWrite
get_contact_list
get contact list in one authorized project.
ContactsRead
update_contact_list
update contact list in one authorized project.
ContactsWrite
delete_contact_list
delete contact list in one authorized project.
ContactsDelete
list_contact_list_members
list contact list members in one authorized project.
ContactsRead
add_contact_list_members
add contact list members in one authorized project.
ContactsWrite
remove_contact_list_member
remove contact list member in one authorized project.
ContactsDelete
create_contact_import
create contact import in one authorized project.
ContactsWrite
get_contact_import
get contact import in one authorized project.
ContactsRead
delete_contact_import
delete contact import in one authorized project.
ContactsDelete
get_campaigns_overview
get campaigns overview in one authorized project.
CampaignsRead
create_campaign
create campaign in one authorized project.
CampaignsWrite
get_campaign
get campaign in one authorized project.
CampaignsRead
update_campaign
update campaign in one authorized project.
CampaignsWrite
get_campaign_progress
get campaign progress in one authorized project.
CampaignsRead
estimate_segment_rules
estimate segment rules in one authorized project.
ContactsWrite
get_segment
get segment in one authorized project.
ContactsRead
create_segment
create segment in one authorized project.
ContactsWrite
update_segment
update segment in one authorized project.
ContactsWrite
estimate_segment
estimate segment in one authorized project.
ContactsWrite
list_segment_contacts
list segment contacts in one authorized project.
ContactsRead
delete_segment
delete segment in one authorized project.
ContactsDelete
get_recipient_list_binding
get recipient list binding in one authorized project.
ContactsRead
upsert_recipient_list_binding
upsert recipient list binding in one authorized project.
ContactsWrite
lock_recipient_list_binding
lock recipient list binding in one authorized project.
ContactsWrite
unlock_recipient_list_binding
unlock recipient list binding in one authorized project.
ContactsWrite
validate_recipient_list_binding
validate recipient list binding in one authorized project.
ContactsWrite
cancel_campaign
cancel campaign in one authorized project.
CampaignsWrite
preview_campaign_email
preview campaign email in one authorized project.
CampaignsWrite
send_campaign_test
send campaign test in one authorized project.
CampaignsWrite
delete_campaign
delete campaign in one authorized project.
CampaignsDelete
list_templates
list templates in one authorized project.
CampaignsRead
create_template
create template in one authorized project.
CampaignsWrite
get_template
get template in one authorized project.
CampaignsRead
update_template
update template in one authorized project.
CampaignsWrite
delete_template
delete template in one authorized project.
CampaignsDelete
preview_template
preview template in one authorized project.
CampaignsWrite
list_assets
list assets in one authorized project.
ProjectsRead
create_asset
create asset in one authorized project.
ProjectsWrite
get_asset
get asset in one authorized project.
ProjectsRead
update_asset
update asset in one authorized project.
ProjectsWrite
delete_asset
delete asset in one authorized project.
ProjectsDelete
list_data_sources
list data sources in one authorized project.
ProjectsRead
create_data_source
create data source in one authorized project.
ProjectsWrite
get_data_source
get data source in one authorized project.
ProjectsRead
update_data_source
update data source in one authorized project.
ProjectsWrite
delete_data_source
delete data source in one authorized project.
ProjectsDelete
list_data_source_tables
list data source tables in one authorized project.
ProjectsRead
list_data_source_fields
list data source fields in one authorized project.
ProjectsRead
list_data_source_rows
list data source rows in one authorized project.
ProjectsRead
update_tracking_client
update tracking client in one authorized project.
ProjectsWrite
rotate_tracking_client_secret
rotate tracking client secret in one authorized project.
ProjectsWrite
list_automations
list automations in one authorized project. Stored but not executed.
CampaignsRead
create_automation
create automation in one authorized project. Stored but not executed.
CampaignsWrite
update_automation
update automation in one authorized project. Stored but not executed.
CampaignsWrite
toggle_automation
toggle automation in one authorized project. Stored but not executed.
CampaignsWrite
delete_automation
delete automation in one authorized project. Stored but not executed.
CampaignsDelete
update_domain
update domain in one authorized project.
CampaignsWrite
get_project_dashboard_stats
get project dashboard stats in one authorized project.
ProjectsRead
preview_insight
preview insight in one authorized project.
InsightsRead

Full JSONSchema for every tool lives at /mcp-manifest.json.

Error codes

CodeMeaning
-32001Authentication required — missing Authorization: Bearer.
-32002Invalid or expired API key.
-32003Explicit organization or project target not found.
-32601Unknown method or tool.
-32602Invalid params (missing required input, bad type).

Changelog

v2.0.0
Delegated OAuth 2.1 control plane with explicit organization and project targets. Governance tools require scoped user consent; legacy data tools remain organization-scoped until their cutovers.
v1.0.0
Initial release. Per-tool organizationId inputs, org-scoped API keys only.

Next steps