MCP Server

Connect your favorite AI tools — Claude Desktop, VS Code, Cursor, Windsurf, Claude Code, and more — to Yaplet using the Model Context Protocol. Work in your account through natural conversation, at an access level you choose.

What Is MCP?

The Model Context Protocol (MCP) is an open standard that lets AI assistants connect to external services and use their tools. Yaplet exposes an MCP server so you can work in your account from any MCP-compatible client — teach your AI agent, write knowledge base articles, draft email campaigns, handle conversations and tickets, and more, all through natural language.

The same server powers Copilot, the assistant inside your dashboard, so an outside AI app and Copilot can do exactly the same things.

Requirements: MCP access requires an active paid subscription with the Copilot feature enabled, and the person the connection runs as must hold the Copilot permission. Everything else follows from the dashboard permissions that person already holds — an AI connection can never do more than they could do by hand.

How Authentication Works

Yaplet's MCP server supports two authentication methods. Both let you decide how much the AI may do.

OAuth 2.0 (Browser Login)

The default method. Just add the server URL to your client — when you connect, your browser opens a login page where you sign in with your Yaplet account, pick your organization, and approve access. On that page you also choose:

  • Which areas the app may work in — one checkbox per area (widgets, conversations, tickets, newsletter, workflows, and so on). Only areas your permissions allow are offered.
  • What the app may do — one of three access levels:
LevelWhat the app may do
Read onlyLook things up. It changes nothing.
Read and change (preselected)Also create and update things that can be changed back.
Read, change, delete and sendAlso delete a record for good, or send a message to someone outside your team (a reply to a visitor, an email to a ticket's reporter). Deletes are permanent and sent messages cannot be taken back.

Everything the app does is done as you, with your permissions. If you suspend a team member, every app they connected stops working at once, and works again when you re-enable them.

The page also names the app that asks to connect and the address you are sent back to once you approve. Yaplet has not checked the app, so continue only if you started the connection yourself. A link with an unknown app, or with a return address the app never registered, shows This sign-in link is not valid instead, with nothing to approve.

Connected before access levels existed? A browser login made before then counts as Read and change. To let the app delete or send, disconnect it and log in again, choosing Read, change, delete and send. Logging in again also refreshes the app's list of tools.

API Key

For clients that don't support OAuth redirects (like Cursor or Antigravity), you can authenticate with an API key instead. Generate one at Settings → Organization settings → API in your dashboard, switch its AI access (MCP) on there, then pass the key as a Bearer token in the Authorization header of your MCP config.

AI access is set per key. New keys start with AI access Off — the key works for Yaplet's other APIs, but an AI app using it is refused. Switching it on picks one of the same three levels, and the key then runs as the person who switched it on: it can only do what that person may do in the dashboard. Only the person who created the key can switch its AI access on; anyone who manages API keys can switch it off. See API Keys. Keys that existed before this setting kept full AI access and run as the organization owner — switch them off if you don't use them with an AI app. Treat every key like a password.

Setup Guides

Yaplet's MCP server is available at:

https://yaplet.com/api/mcp

It uses the Streamable HTTP transport — the current MCP standard. Select your client below for setup instructions.

Claude Desktop supports remote MCP servers through its Connectors feature with automatic browser login.

Open Settings

In Claude Desktop, go to Settings > Connectors.

Add a New Connector

Click Add Connector and configure it:

  • Name: Yaplet
  • URL: https://yaplet.com/api/mcp

Log In

Your browser will open automatically. Sign in with your Yaplet account, select your organization, choose what the app may do, and approve access. That's it — no API key needed.

Start Using It

Open a new conversation and you'll see Yaplet's tools available. Ask something like "List my widgets" to verify the connection.

Older versions: If your version of Claude Desktop doesn't support Connectors yet, you can use the mcp-remote bridge as a fallback. Add this to your claude_desktop_config.json:
{
    "mcpServers": {
        "yaplet": {
            "command": "npx",
            "args": ["-y", "mcp-remote", "https://yaplet.com/api/mcp"]
        }
    }
}

mcp-remote will open a browser window for you to log in.

Alternative: API Key. If browser login doesn't work in your setup, you can use an API key instead. Replace the config above with:
{
    "mcpServers": {
        "yaplet": {
            "command": "npx",
            "args": ["-y", "mcp-remote", "https://yaplet.com/api/mcp", "--header", "Authorization:Bearer yAPI_your-api-key-here"]
        }
    }
}

Config file location:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json
Other MCP clients: Any client that supports the Streamable HTTP transport can connect to Yaplet. Point it to https://yaplet.com/api/mcp — the client will handle OAuth login automatically. If your client doesn't support OAuth redirects, pass your API key as a Bearer token in the Authorization header — with the key's AI access (MCP) switched on under Settings → API. When a client registers itself, its return addresses must use https:// or the app's own scheme (such as cursor://); plain http:// is accepted only for addresses on your own computer (localhost).

How the AI Works in Yaplet

Your AI app sees nine tools. It doesn't need one tool per feature: it looks up the action it needs, then runs it.

ToolWhat it does
get_guideExplains every product area: what it is for, whether your plan and permissions include it, what an AI can do there, and a link to these docs.
get_account_stateShows what is set up, missing or failing in your account, per brand and for the whole organization. Each line is only shown to people who have that area's permission.
search_yaplet_docsSearches this documentation and the Yaplet help center.
list_records / get_recordLists and reads records — widgets, conversations, tickets, contacts and more.
find_actionsLists the actions this connection can run: the action categories, every action in one or more categories with a one-line summary, or all actions at once. Then it gives the full details of the actions the AI picks.
run_read_actionRuns an action that only reads.
run_change_actionRuns an action that creates or updates something.
run_irreversible_actionRuns an action that deletes something for good or sends a message to someone outside your team.

Behind find_actions sit around a hundred small actions, each one thing you would ask for in one sentence — Update ticket, Clock in, Write article with AI. Each has a name like tickets.update, and each is one of three kinds that match the three access levels:

KindExampleNeeds the level
Readreports.visitors — visitor statisticsRead only
Changetickets.update — move, assign or label a ticketRead and change
Delete or sendtickets.delete, conversations.send_replyRead, change, delete and send

An app connected below the level an action needs doesn't get the run tool for it, and find_actions tells it which level is missing. Some actions write text with AI; those are marked as using AI credits.

Actions by area

Each page lists every action in its area, what it does, and what an AI cannot do there.

Data Access

Browse and read any resource in your organization, plus the guide, account state and documentation search.

Widget Tools

Create and configure chat widgets, their design, Home texts, cards and quick buttons, and get the install code. Needs the Brands & chat widgets permission.

Chatbot Tools

Set up the brand's AI agent, add knowledge documents and API tools, and diagnose individual AI answers. The agent needs Vex AI; knowledge documents and API tools need Content sources.

Product Tools

Connect the catalogues your products come from and draft the binding rules the AI must follow when it talks about them. Needs Content sources.

Workflow Tools

Build, check and change chat workflows, duplicate them into another brand, switch them off, and read recent runs and failures. Switching a workflow on stays with you. Needs the Workflows permission.

Help Tools

Build knowledge bases and documentation sets: categories, articles and pages, writing with AI, and publishing.

Conversation Tools

Search and read conversations, assign them, add private notes, and reply to visitors.

Ticket Tools

Create, update, move, assign and archive tickets, comment internally, email the reporter, and delete a ticket.

Newsletter Tools

Draft campaigns, build email automations, set up Newsletter Autopilot and its topic ideas, manage subscribers, and check email performance. Sending stays with you.

Engagement Tools

Draft banners, surveys, product tours, chat messages and news posts, then read back how they performed.

Analytics Tools

Read agent performance, AI agent results, visitor statistics and AI usage.

Time Management Tools

Clock in and out, record, correct and delete shifts, and pull hours reports.


How a Task Runs

You don't need to orchestrate anything — describe what you want and the AI works through it.

Get oriented

For a question about your account ("why isn't my widget answering?", "what should I set up next?"), the AI starts with get_account_state and search_yaplet_docs, so it works from facts about your account and how the feature is meant to work.

Find the action

It opens the category that fits with find_actions — or lists every action when unsure — picks the action from the one-line summaries, and reads that action's full details before running it: what it does and the exact information it needs. It understands your wording in any language and never has to guess a name or a field.

Read what is there

It reads the records involved with list_records, get_record or a read action — to find the right ticket, widget or column.

Act

It runs the change, delete or send with the run tool for that kind. In Copilot, every change waits for your Confirm first.

Example: Asking "Add a document about our refund policy to my AI agent's knowledge and write a help article covering the same thing" would find your AI agent, add and index the document, then write the article and publish it — all from a single prompt.


What an AI Can Never Do

Some things stay with a person in every connection — Copilot, browser logins and API keys alike. The AI can explain them and link you to the right dashboard page, but it cannot do them, even when asked:

  • Money: your plan, add-ons, the payment card, credit top-ups, phone numbers, the dedicated IP.
  • Access: team members, invitations, permissions, members' pay rates, API keys, integrations.
  • The account: data export, deleting the account, signing the data-processing agreement.
  • Emails to your subscribers and public posts: an AI never sends, schedules or resumes a campaign, switches an email automation on, approves a Newsletter Autopilot issue, switches an autopilot's Require my approval off or switches on one that sends without approval, and never publishes a social post. It prepares the draft and tells you where to send it or switch it on.
  • Switching a chat workflow on: an AI creates and changes only workflows that are switched off. It may switch a workflow off, but never on, and a change to a workflow that is on is refused — the AI has to switch it off first, or duplicate it and change the copy. You switch a workflow on in the dashboard.

Deletes are limited too: one named record at a time, and the AI must repeat the record's exact name, so a wrong id is refused. A workflow can only be deleted while it is switched off. An AI never deletes in bulk by a filter, never deletes a brand, widget, knowledge base, documentation set or board, and never deletes subscribers.


Privacy & Security

  • All requests are authenticated and scoped to one organization.
  • Every connection runs as one person and can do only what that person's permissions allow in the dashboard right now. Suspending a member stops their Copilot, the apps they connected and the API keys they switched on, at once.
  • Every change, delete and send an AI makes is written to your Audit Log as AI change or AI delete or send, naming the person, the connection (Copilot, the app's name or the API key's name), the action and the record. The values sent are not stored there. Reads are not logged.
  • Apps connected by browser login cannot see or add private notes in conversations; Copilot and API-key connections can.
  • Results that contain text written by outsiders — such as visitor messages, survey answers or fetched web pages — reach the AI with a note that they are data, never instructions.