Model Context Protocol
The open protocol an AI agent uses to work in your Sendly account, and the permission model around it
The Model Context Protocol (MCP) is an open standard for connecting AI agents to systems they can act in. A server exposes a set of tools — named operations with typed arguments — and any MCP-capable client can discover them and call them on the user's behalf.
Sendly runs a remote MCP server, so an agent can answer which of your domains are verified, tidy your contacts, diagnose why a message did not arrive, build and pause your workflows, draft your next campaign, and — if you say so — send it.
The endpoint
https://app.sendly.now/api/mcpThe transport is Streamable HTTP. Authorization is OAuth 2.1 with PKCE, or a Sendly secret
key on the Authorization header. Dynamic client registration is open and the
protected-resource and authorization-server metadata documents are published at their
conventional well-known URLs, so a client that has never spoken to Sendly can discover
what it needs and start the flow unattended.
What makes it safe to use
The tools an agent can see are decided before it asks, by filtering the registry against the credential's own permissions. A tool outside the grant is never registered, so the agent does not know it exists rather than being refused when it tries.
Eight permissions produce effects nothing in the dashboard undoes — sending mail, sending a campaign, enabling a workflow, removing a suppression, and four more. Those arrive unchecked on the consent screen, each with a sentence naming the consequence.
Drafting a campaign and sending one are separate permissions, which is what lets an agent be genuinely useful without being able to mail your whole audience.
One check is enforced by Sendly rather than by your client: in a project with more than 1,000 contacts, sending a campaign is refused the first time and has to be repeated with an explicit confirmation argument. A stateless server cannot ask a person anything mid-call, so the confirmation is something it can demand instead of something it has to request.
See the MCP guide for the full tool list and the consent walkthrough.