MCP
Connect Claude
Connect Claude Code, or any MCP client that sends a Bearer header, to your MISSIN workspace with a secret API key, then manage partners and captures.
MISSIN runs a hosted MCP server at https://api.missin.co.uk/mcp. An AI assistant connects with a secret API key and works inside your workspace, at that key's access level and no higher.
Create a key
The key is shown once. Copy it now, and keep it out of chats and repositories.
Add the server
The .mcpb extension is one file and needs no config editing.
- Download missin.mcpb.
- Open the file, or drag it into Claude Desktop.
- Paste your secret key when Claude Desktop asks for it. It is stored as a secret.
The extension runs the same tools as the hosted server, on your computer, and calls the MISSIN API with your key. It has one more setting, Toolsets, with core as the default.
Let an agent install it
Paste this prompt into a coding agent (Claude Code, Codex, Cursor) to have it add the server and prove it works. It is the same prompt the merchant guide gives. The agent checks the endpoint without a key, asks for the key without echoing it, adds the server at user scope with the client's own command, and calls whoami.
Install with an AI assistant
Copy this prompt into the AI assistant you're using.
Install the MISSIN MCP server for me and check that it works.
About the server
- MISSIN's hosted MCP server is https://api.missin.co.uk/mcp (Streamable HTTP, JSON responses).
- It takes a MISSIN secret API key as the header "Authorization: Bearer sk_live_...". It has no OAuth sign-in, so do not start one.
- Guides: https://docs.missin.co.uk/integrations/ai-assistants and https://developer.missin.co.uk/mcp/connect-claude
Steps
1. Check the server is reachable, without a key: POST {"jsonrpc":"2.0","id":1,"method":"initialize"} to https://api.missin.co.uk/mcp with Content-Type: application/json. Expect 401 with the header WWW-Authenticate: Bearer realm="missin".
2. Ask me for my secret API key. If I do not have one, tell me to create one in MISSIN under Settings, then Developers, at Read or Write. Never print the key back, never write it into a file under version control, and leave it out of your report.
3. Add a server named "missin" with this client's own command, at user level, never project level:
- Claude Code: claude mcp add --transport http --scope user missin https://api.missin.co.uk/mcp --header "Authorization: Bearer <the key>"
- Codex: have me export MISSIN_API_KEY, then run: codex mcp add missin --url https://api.missin.co.uk/mcp --bearer-token-env-var MISSIN_API_KEY
- Cursor: in ~/.cursor/mcp.json, "missin": { "url": "https://api.missin.co.uk/mcp", "headers": { "Authorization": "Bearer ${env:MISSIN_API_KEY}" } }
- Any other client: its user-level MCP config, Streamable HTTP, the same header.
4. Reload the MCP servers if this client needs it, then call the missin tool "whoami".
5. Report: which config you changed and where, whether whoami answered, and the workspace and access level it reported (as created and as it acts now). If it failed, give the status code: 401 means the key is missing, revoked or expired; 403 with secret_key_required means a publishable key was used.Check what the key can do
Ask the assistant "which workspace are you connected to, and what can you change?". It calls whoami, a tool every key has, which answers with the workspace, the key's name and its access level, and the display name of the person who created it. It also lists the toolsets and actions the key can use at its level. The answer shows two levels: the one the key was created with, and the one it acts with now, which is capped by its creator's current role. Use the second.
Ask for something
Make a partner for @test11 on Instagram and TikTok, pull their posts and add them to my spring campaign.
The assistant works through it with the task tools, and stops to ask when it needs you:
- It calls
save_partnerwith both handles, so one partner holds the Instagram and TikTok accounts. - It calls
quote_captureand tells you the credits and the price. Nothing is spent yet. - After your yes, it calls
start_capturewith the price you approved, andsave_campaignorassign_posts_to_campaignfiles the posts under your spring campaign. - Capture runs in the background. It checks with
get_capture_statusand tells you when posts arrive.
If two campaigns match "spring", or a handle already belongs to more than one partner, the result has kind needs_choice and lists the candidates. That is a question, not an error: the assistant asks you which one you meant, then calls again with that record's id. It never guesses.
Access levels
A tool above the key's level is not listed, and a call to it by name is refused with 403 and insufficient_scope.
| Level | What the assistant can do |
|---|---|
| Read | Look up campaigns, partners, posts, forms, orders and more. Get a capture quote. |
| Write | Also create and change partners, campaigns, posts, discounts and forms, and start captures. |
| Admin | Also change connections, integration settings, the brand and workspace settings. |
A key acts as the member who created it, and its level is capped by that member's role. whoami reports both levels.
Load more tools
The core toolset loads by default: the task tools plus listing and reading the main records. Add toolsets to the URL, for example https://api.missin.co.uk/mcp?toolsets=forms,waitlists, or toolsets=all for everything. The assistant can call list_toolsets to see what exists. Every tool is on the tool registry, and every operation behind them is in the API reference.
Limits
- Rate. Each key may make 600 requests a minute unless MISSIN set another limit; over it the server answers
429withrate_limited. Requests the server refuses are also counted per IP address, at 200 a minute; past that the server answers429withRATE_LIMITED. - Size and time. A request body is capped at 256 KB, and a request that runs longer than 30 seconds is answered with
504. - Check before you retry. A timeout does not cancel work already running, so a write may still complete after the
504. List or get the record before you repeat a create.
Troubleshooting
401: the key is missing, revoked or expired, or you sent a login token instead of a key.403withsecret_key_required: you used a publishable key. Use a secret key.403withinsufficient_scope: the tool needs a higher access level. TheWWW-Authenticateheader carries the full sentence, for examplesave_partner needs a Write key; this key is Read.Create a key at the level the job needs, or askwhoamiwhat this one allows.400naming a toolset: thetoolsetsvalue is not one of the toolset names. Calllist_toolsets.- Posts you already had did not move: posts the workspace already held keep their campaign. Ask the assistant to file them with
assign_posts_to_campaign. 403with no code, and your client sends anOriginheader: the server refuses any request that carries anOriginheader unless that origin is on the server's own allowlist. Agents and servers send none. Connect from a local MCP client or a server, not from a web page.- Claude.ai or Claude Desktop connector does not authenticate: check that the header name is
authorizationand the value starts withBearer, and that the key is a secret key. If your plan has no Request headers field, use the extension ormcp-remote.
Sources
Anthropic's own docs for adding an unlisted custom connector, connector authentication and Claude Code MCP servers, and the mcp-remote README.