MCP
MCP tools
Every tool the MISSIN MCP server offers an AI assistant: endpoint, auth, limits, status codes, access levels and tools by area.
The hosted MCP server lets an AI assistant work in a MISSIN workspace through an API key. Every tool below maps to one public API operation, or is a task tool that chains several of them.
Connect
Endpoint: POST https://api.missin.co.uk/mcp (stateless Streamable HTTP, JSON responses). Send Authorization: Bearer sk_live_… with a secret key; nothing else is accepted, and OAuth is not available yet (it is planned for a later phase).
Tools in the core toolset load by default. Add others with ?toolsets=forms,waitlists on the URL, or all for every toolset.
Access levels
A key has an access level, and a tool needs that level or higher: Read only reads, Write changes workspace data, Admin also changes settings, connections and the brand. Tools above the key's level are left out of the tool list and refused if called by name. A tool with destructiveHint set removes or replaces something (an "Irreversible." summary is always destructive), so an agent must say what it will change and wait for the merchant's yes.
When a tool needs the merchant
Capture costs credits
start_capture quotes first: call quote_capture, show the credits and the price, and only then call start_capture with the quotedCredits the merchant approved. The raw DispatchPartnerCapture and DispatchHashtagCapture operations spend credits directly and the balance gate is the real limit on them, so prefer start_capture.
Limits and status codes
| Limit | Value |
|---|---|
| Request body | 256 KB |
| One request | 30 seconds |
| Rate | per key; over it the server answers 429 |
| Origin | A request carrying an Origin header is refused unless that origin is allowlisted; agents and servers send none |
A 504 does not cancel work already running: a write in flight may still commit after the timeout, so check with a list or get before you retry a create.
| Status | Meaning |
|---|---|
| 400 | Body is not valid JSON, or toolsets names one that does not exist |
| 401 | No key, a login token instead of a key, or an invalid key |
| 403 | A publishable or connection key, a refused Origin, or insufficient_scope when the tool needs a higher access level |
| 405 | GET and DELETE are not supported; the server is stateless |
| 413 | Body over 256 KB |
| 429 | Over the key's rate limit |
| 504 | The request took longer than 30 seconds |
Tool names are public. A 403 insufficient_scope on a name, against a forbidden tool result, tells a caller the tool exists; it does not give them access. A tool name that does not exist returns a tool result with isError set, not a protocol error.
Tools by area
| Area | Tools |
|---|---|
| Attribution | 11 |
| Campaigns | 14 |
| Capture | 20 |
| Channels | 6 |
| Discounts | 31 |
| Forms | 26 |
| Incentives | 12 |
| Integrations | 12 |
| Marketing | 9 |
| Orders | 3 |
| Partners | 23 |
| Posts | 16 |
| Waitlists | 31 |
| Workspace | 15 |