MCP reference
The ReachOut MCP server exposes contacts, campaigns, segments, and analytics as tools your agent can call directly. It speaks JSON-RPC 2.0 over HTTP and SSE. Delegated control-plane calls name their organization and, when applicable, project explicitly.
Endpoint
POST https://api.usereachout.com/mcp
Content-Type: application/json
Authorization: Bearer <api_key>Transports: http (single request/response) and sse (streaming). Server version is advertised in the initialize response under serverInfo.
Delegated OAuth
Control-plane tools use OAuth 2.1 Authorization Code with PKCE S256. Discover authorization metadata from the MCP endpoint, send the exact MCP audience, and obtain browser consent from the acting user. Request mcp:read for reads, both mcp:write and mcp:governancefor governance writes, and offline_access only when refresh is required.
Access tokens are short-lived and refresh tokens rotate. Every delegated call supplies an explicitorganizationId or projectId; there is no stored organization or project context. Organization API keys remain for legacy organization-scoped data tools and are limited to their explicit project grants for get_organization_overview. Governance tools require a delegated user and otherwise return the stable MCP_USER_DELEGATION_REQUIRED error.
Get an API key
Sign in to the Studio and go to Organization settings → API keys. Click Generate API key, give the key a label (e.g.Claude Desktop), and copy the rok_live_… plaintext from the modal — it is shown exactly once. The server stores only the SHA-256 hash and a 12-char visible prefix, so a key cannot be recovered if you lose it.
The same panel lists every active key with its prefix, label, and last-used time. Revoking a key invalidates the server-side context cache immediately, so any client using it stops authenticating on the next request. Owner/admin role required.
Filtering analytics by website
Analytics tools require a stable projectId. Discover accessible projects withlist_projects; MCP does not persist or switch an active project. An optionalclientId further restricts results to a tracking client owned by that project.
Discover the IDs first with list_tracking_clients, then pass one in:
# 1. list projects
{"method":"tools/call","params":{"name":"list_projects","arguments":{"organizationId":"org_example"}}}
# 2. query one concrete project
{"method":"tools/call","params":{
"name":"get_analytics_overview",
"arguments":{
"projectId":"project_01J6Y0N8V4J5Q2M7K3R9T6W1XA",
"range":"30d",
"clientId":"cl_example"
}
}}get_organization_overview is a read-only aggregate over the caller's currently authorized project grants. It is not an all-project data mode and never accepts caller-supplied project IDs.
Client setup
Use the same endpoint and bearer token in every MCP client. Keep the key out of committed project files unless you reference it through an environment variable.
Claude CLI / Claude Code
claude mcp add --transport http reachout https://api.usereachout.com/mcp \
--header "Authorization: Bearer YOUR_API_KEY"
claude mcp listCodex
# ~/.codex/config.toml
[mcp_servers."reachout"]
url = "https://api.usereachout.com/mcp"
[mcp_servers."ReachOut".headers]
Authorization = "Bearer YOUR_API_KEY"
# Then verify:
codex mcp listClaude Desktop
{
"mcpServers": {
"reachout": {
"type": "http",
"url": "https://api.usereachout.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}Cursor, LM Studio, and other MCP clients
{
"mcpServers": {
"reachout": {
"transport": "http",
"url": "https://api.usereachout.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_API_KEY"
}
}
}
}Some clients call the key transport; others call ittype. Use HTTP / Streamable HTTP when the client asks for the transport.
Authentication
Every tools/call requires a bearer token. Three token shapes are accepted:
| Token | Scope |
|---|---|
| Per-user API key Studio → Settings → API Keys | Delegated OAuth calls name the organization or project explicitly. |
| Legacy org-scoped key Created before user-linking was added | Legacy data tools use the single organization the key was issued for. |
Master key (REACHOUT_API_KEY)Server-level secret, self-hosted only | Self-hosted server access; not part of delegated OAuth. |
Unauthenticated methods: initialize, tools/list, ping.
revokedAt; subsequent requests with that key return -32002 Invalid API key.Organization scoping
Delegated control-plane tools include an organizationId or projectIdparameter. Authorization is resolved per request:
- Delegated user — the OAuth token identifies the consenting user and granted scopes.
- Explicit target —
organizationIdor a project resolved fromprojectId. - Legacy key — legacy data tools use only the organization issued to that key.
Membership and project permissions are checked live on every delegated call.
Response envelope
Every successful tool response is a single text block. The first two lines are a human-readable header showing the organization addressed by the call; the rest is JSON.
[organization] Acme Inc (id: org_abc123)
--------------------------------------------------------------
{
"organization": { "id": "org_abc123", "name": "Acme Inc", "slug": "acme" },
"result": { /* tool-specific payload */ }
}The header is part of the text content the model sees, so any well-behaved client will surface the addressed organization to the user on every tool call. For programmatic parsing, strip the header and decode the JSON body — result holds the tool payload, organizationis always present.
Errors are emitted with isError: true and the same header prefix where possible.
Tools — organization management
These tools require delegated OAuth and explicit organization targets.
There is no session-level organization selector. Delegated control-plane calls pass the target identifier on every request; legacy data tools remain scoped to the organization issued to the API key.
Tools — domain surface
Legacy data tools are explicitly organization-scoped to their API key. Control-plane tools require delegated OAuth and explicit targets.
| Tool | Category | Mode |
|---|---|---|
list_organization_campaignsList campaigns across accessible active projects. | Campaigns | Read |
get_organization_campaign_overviewRead campaign results across accessible active projects. | Campaigns | Read |
list_organization_templatesList templates across accessible active projects. | Campaigns | Read |
list_organization_assetsList assets across accessible active projects. | Campaigns | Read |
get_organization_realtime_analyticsRead live analytics across accessible active projects. | Analytics | Read |
list_organization_segmentsRead segments and counts across accessible active projects. | Contacts | Read |
search_organization_contactsSearch contacts across accessible active projects with global pagination. | Contacts | Read |
get_organization_contact_statsRead contact counts across accessible active projects. | Contacts | Read |
list_organization_insightsRead the latest persisted insights across accessible active projects. | Insights | Read |
get_organization_analytics_overviewRead scoped overview with period, filters and coverage. | Analytics | Read |
get_organization_analytics_contributionsRead scoped contributions with period, filters and coverage. | Analytics | Read |
get_organization_analytics_pagesRead scoped pages with period, filters and coverage. | Analytics | Read |
get_organization_analytics_refsRead scoped refs with period, filters and coverage. | Analytics | Read |
get_organization_analytics_devicesRead scoped devices with period, filters and coverage. | Analytics | Read |
get_organization_analytics_eventsRead scoped events with period, filters and coverage. | Analytics | Read |
get_organization_analytics_geoRead scoped geo with period, filters and coverage. | Analytics | Read |
get_organization_analytics_engaged_usersRead scoped engaged-users with period, filters and coverage. | Analytics | Read |
get_organization_analytics_identification_diagnosticRead scoped identification-diagnostic with period, filters and coverage. | Analytics | Read |
get_project_analytics_contributionsRead scoped contributions with period, filters and coverage. | Analytics | Read |
get_project_analytics_refsRead scoped refs with period, filters and coverage. | Analytics | Read |
get_project_analytics_devicesRead scoped devices with period, filters and coverage. | Analytics | Read |
get_project_analytics_eventsRead scoped events with period, filters and coverage. | Analytics | Read |
get_project_analytics_geoRead scoped geo with period, filters and coverage. | Analytics | Read |
get_project_analytics_engaged_usersRead scoped engaged-users with period, filters and coverage. | Analytics | Read |
get_project_analytics_identification_diagnosticRead scoped identification-diagnostic with period, filters and coverage. | Analytics | Read |
create_organizationCreate a ReachOut organization and its default project. | Organization | Write |
get_organization_provisioningReturn the provisioning snapshot of one organization. | Organization | Read |
retry_organization_provisioningRetry terminal provisioning for one organization. | Organization | Write |
get_organization_dashboard_statsDashboard for active authorized projects, including explicit data availability. | Organization | Read |
billing_usage_getOrganization usage in the current billing period: emails, MCP calls, insights. | Organization | Read |
billing_plans_listCurrent plan with its caps and entitlements, and the available plans. | Organization | Read |
get_organization_overviewAggregate analytics across only the projects authorized for the caller. | Organization | Read |
list_transport_safety_blocksList active and reviewed transport safety blocks for one organization. | Organization | Read |
remove_transport_safety_blockRemove one transport safety block after live Postal evidence verification. | Organization | Write |
get_legacy_removal_readinessEvaluate runtime-local readiness for immutable legacy surface removal. | Platform | Read |
approve_legacy_surface_removalApprove or reject legacy removal for the exact current evidence digest. | Platform | Write |
request_legacy_surface_removalDisable every legacy wrapper after exact evidence confirmation. | Platform | Write |
get_project_activation_readinessEvaluate runtime-local readiness for one multi-project activation cohort. | Platform | Read |
activate_project_cohortActivate one ready multi-project cohort with matching evidence. | Platform | Write |
record_runtime_compatibility_floorRecord one attested runtime compatibility floor. | Platform | Write |
list_bot_rulesList canonical global bot rules as a root user. | Platform | Read |
create_bot_ruleCreate one canonical global bot rule as a root user. | Platform | Write |
replace_bot_rulesReplace the canonical global bot-rule set as a root user. | Platform | Write |
delete_bot_ruleDelete one canonical global bot rule as a root user. | Platform | Delete |
list_projectsList the projects the delegated user can access in one organization. | Projects | Read |
get_projectReturn one project the delegated user can access. | Projects | Read |
create_projectCreate an additional project in one organization. | Projects | Write |
update_projectRename one active project. | Projects | Write |
archive_projectArchive one non-default project. | Projects | Write |
restore_projectRestore one archived project. | Projects | Write |
set_default_projectMake one active project the organization default. | Projects | Write |
get_project_provisioningReturn the provisioning snapshot of one project. | Projects | Read |
retry_project_provisioningRetry terminal provisioning for one project. | Projects | Write |
list_project_membersList the member grants of one project. | Projects | Read |
grant_project_memberGrant one organization member a role on one project. | Projects | Write |
update_project_member_roleChange the project role of one existing member grant. | Projects | Write |
revoke_project_memberRevoke one member grant from one project. | Projects | Delete |
list_api_key_project_grantsList the explicit project grants of one organization API key. | Projects | Read |
grant_api_key_projectGrant one organization API key a role on one explicit project. | Projects | Write |
update_api_key_project_roleChange the project role of one existing API-key grant. | Projects | Write |
revoke_api_key_projectRevoke one API-key grant from one project. | Projects | Delete |
get_current_organizationReturn the organization fixed to this legacy MCP API key. | Organization | Read |
list_organizationsReturn only the organization fixed to this legacy MCP API key. | Organization | Read |
list_timezonesList supported IANA timezone names. | Organization | Read |
list_contactsQuery contacts with search, filters, sort, and pagination. | Contacts | Read |
search_contactsSearch and filter contacts in one authorized project. | Contacts | Read |
list_contact_fieldsList custom contact fields available for filters and edits. | Contacts | Read |
create_contact_fieldRegister a new custom contact field. | Contacts | Write |
update_contact_fieldUpdate or rename a custom contact field. | Contacts | Write |
delete_contact_fieldDelete a custom contact field and strip stored values. | Contacts | Delete |
list_duplicate_contactsFind duplicate-email contact groups. | Contacts | Read |
deduplicate_contactsBulk merge or delete duplicate contact groups. | Contacts | Write |
resolve_duplicate_contactsResolve one duplicate contact group with an explicit keeper. | Contacts | Write |
get_contactGet a single contact by ID. | Contacts | Read |
create_contactCreate a contact in the API key's organization. | Contacts | Write |
list_campaignsList campaigns, optionally filtered by status. | Campaigns | Read |
get_campaign_statsFetch delivery and engagement stats for one campaign. | Campaigns | Read |
list_segmentsList segments in the API key's organization. | Campaigns | Read |
send_campaignTrigger a campaign send for its assigned segment. | Campaigns | Write |
get_analyticsRead daily, weekly, or monthly analytics summaries. Optional clientId to filter to one website. | Analytics | Read |
list_tracking_clientsList website tracking clients and embed credentials. | Analytics | Read |
create_tracking_clientCreate a website tracking client and optional secret. | Analytics | Write |
delete_tracking_clientDelete a website tracking client. | Analytics | Delete |
list_domainsList email sender domains for the API key's organization. | Campaigns | Read |
get_domainGet one email domain including its DNS verification records and status. | Campaigns | Read |
verify_domainRe-check DNS for an email domain against Postal and refresh its status. | Campaigns | Write |
add_domainAdd a custom email sender domain by hostname; returns the DNS records to publish. | Campaigns | Write |
delete_domainDelete an email sender domain (blocked when MCP deletions are disabled, default, or in use). | Campaigns | Delete |
get_analytics_overviewAggregate visitors, sessions, pageviews, bounce, and duration. Optional clientId to filter to one website. | Analytics | Read |
get_top_pagesList top pages with pageviews, uniques, and visible time. Optional clientId to filter to one website. | Analytics | Read |
get_top_referrersList top referrer hosts. Optional clientId to filter to one website. | Analytics | Read |
get_realtime_analyticsReturn realtime visitors and optional details for one project. | Analytics | Read |
list_insightsList generated insight reports. | Insights | Read |
get_insight_reportGet one insight report with evidence rows. | Insights | Read |
run_insightsRun all active insight definitions now. | Insights | Write |
run_insightRun one insight definition now. | Insights | Write |
archive_insightArchive one custom insight; its past reports stay available. | Insights | Write |
create_custom_insightCreate and run a custom insight from a natural-language prompt. | Insights | Write |
update_contactupdate contact in one authorized project. | Contacts | Write |
delete_contactdelete contact in one authorized project. | Contacts | Delete |
bulk_update_contactsbulk update contacts in one authorized project. | Contacts | Write |
bulk_delete_contactsbulk delete contacts in one authorized project. | Contacts | Write |
list_contact_listslist contact lists in one authorized project. | Contacts | Read |
create_contact_listcreate contact list in one authorized project. | Contacts | Write |
get_contact_listget contact list in one authorized project. | Contacts | Read |
update_contact_listupdate contact list in one authorized project. | Contacts | Write |
delete_contact_listdelete contact list in one authorized project. | Contacts | Delete |
list_contact_list_memberslist contact list members in one authorized project. | Contacts | Read |
add_contact_list_membersadd contact list members in one authorized project. | Contacts | Write |
remove_contact_list_memberremove contact list member in one authorized project. | Contacts | Delete |
create_contact_importcreate contact import in one authorized project. | Contacts | Write |
get_contact_importget contact import in one authorized project. | Contacts | Read |
delete_contact_importdelete contact import in one authorized project. | Contacts | Delete |
get_campaigns_overviewget campaigns overview in one authorized project. | Campaigns | Read |
create_campaigncreate campaign in one authorized project. | Campaigns | Write |
get_campaignget campaign in one authorized project. | Campaigns | Read |
update_campaignupdate campaign in one authorized project. | Campaigns | Write |
get_campaign_progressget campaign progress in one authorized project. | Campaigns | Read |
estimate_segment_rulesestimate segment rules in one authorized project. | Contacts | Write |
get_segmentget segment in one authorized project. | Contacts | Read |
create_segmentcreate segment in one authorized project. | Contacts | Write |
update_segmentupdate segment in one authorized project. | Contacts | Write |
estimate_segmentestimate segment in one authorized project. | Contacts | Write |
list_segment_contactslist segment contacts in one authorized project. | Contacts | Read |
delete_segmentdelete segment in one authorized project. | Contacts | Delete |
get_recipient_list_bindingget recipient list binding in one authorized project. | Contacts | Read |
upsert_recipient_list_bindingupsert recipient list binding in one authorized project. | Contacts | Write |
lock_recipient_list_bindinglock recipient list binding in one authorized project. | Contacts | Write |
unlock_recipient_list_bindingunlock recipient list binding in one authorized project. | Contacts | Write |
validate_recipient_list_bindingvalidate recipient list binding in one authorized project. | Contacts | Write |
cancel_campaigncancel campaign in one authorized project. | Campaigns | Write |
preview_campaign_emailpreview campaign email in one authorized project. | Campaigns | Write |
send_campaign_testsend campaign test in one authorized project. | Campaigns | Write |
delete_campaigndelete campaign in one authorized project. | Campaigns | Delete |
list_templateslist templates in one authorized project. | Campaigns | Read |
create_templatecreate template in one authorized project. | Campaigns | Write |
get_templateget template in one authorized project. | Campaigns | Read |
update_templateupdate template in one authorized project. | Campaigns | Write |
delete_templatedelete template in one authorized project. | Campaigns | Delete |
preview_templatepreview template in one authorized project. | Campaigns | Write |
list_assetslist assets in one authorized project. | Projects | Read |
create_assetcreate asset in one authorized project. | Projects | Write |
get_assetget asset in one authorized project. | Projects | Read |
update_assetupdate asset in one authorized project. | Projects | Write |
delete_assetdelete asset in one authorized project. | Projects | Delete |
list_data_sourceslist data sources in one authorized project. | Projects | Read |
create_data_sourcecreate data source in one authorized project. | Projects | Write |
get_data_sourceget data source in one authorized project. | Projects | Read |
update_data_sourceupdate data source in one authorized project. | Projects | Write |
delete_data_sourcedelete data source in one authorized project. | Projects | Delete |
list_data_source_tableslist data source tables in one authorized project. | Projects | Read |
list_data_source_fieldslist data source fields in one authorized project. | Projects | Read |
list_data_source_rowslist data source rows in one authorized project. | Projects | Read |
update_tracking_clientupdate tracking client in one authorized project. | Projects | Write |
rotate_tracking_client_secretrotate tracking client secret in one authorized project. | Projects | Write |
list_automationslist automations in one authorized project. Stored but not executed. | Campaigns | Read |
create_automationcreate automation in one authorized project. Stored but not executed. | Campaigns | Write |
update_automationupdate automation in one authorized project. Stored but not executed. | Campaigns | Write |
toggle_automationtoggle automation in one authorized project. Stored but not executed. | Campaigns | Write |
delete_automationdelete automation in one authorized project. Stored but not executed. | Campaigns | Delete |
update_domainupdate domain in one authorized project. | Campaigns | Write |
get_project_dashboard_statsget project dashboard stats in one authorized project. | Projects | Read |
preview_insightpreview insight in one authorized project. | Insights | Read |
Full JSONSchema for every tool lives at /mcp-manifest.json.
Error codes
| Code | Meaning |
|---|---|
-32001 | Authentication required — missing Authorization: Bearer. |
-32002 | Invalid or expired API key. |
-32003 | Explicit organization or project target not found. |
-32601 | Unknown method or tool. |
-32602 | Invalid params (missing required input, bad type). |
Changelog
- v2.0.0
- Delegated OAuth 2.1 control plane with explicit organization and project targets. Governance tools require scoped user consent; legacy data tools remain organization-scoped until their cutovers.
- v1.0.0
- Initial release. Per-tool
organizationIdinputs, org-scoped API keys only.
Next steps
- Local AI quickstart — Ollama, LM Studio, Claude Desktop, Cursor configs.
- mcp-manifest.json — machine-readable tool schema.
- llms-full.txt — data model and REST endpoints.