Optimove MCP Connector

📘 Version 1.3 · September 2026. API and integration reference for the Optimove Model Context Protocol (MCP) connector. For the marketer-facing setup guide, see Optimove Academy.

Optimove MCP is a hosted, OAuth-secured Model Context Protocol server that connects an MCP-compatible AI client directly to your Optimove tenant. It exposes campaigns, promotions, triggers, journeys, segments, and platform-health signals as queryable surfaces, plus a constrained set of safe-write actions that create and edit campaign building blocks (Target Groups, triggers, templates, attributes, actions, promotions) and draft campaigns and streams. This page is the technical reference: transport, safety contracts, the full tool catalog, authentication, and operational limits.

MCP server endpoint

The connector is hosted at https://mcp.optimove.net/mcp.

The endpoint is hosted, HTTPS-only, and uses Streamable HTTP transport. There is nothing to install locally — clients connect to the remote server directly.

Supported clients

Optimove MCP works with any MCP-compatible client that supports remote servers with OAuth. The following clients are supported and tested:

Claude

  • Claude Code
  • Claude Web
  • Claude Desktop
  • Claude Cowork

OpenAI

  • ChatGPT
  • Codex

Developer tools

  • Claude Code (Terminal)
  • Cursor
  • VS Code
  • Kiro
  • GitHub Copilot CLI (by Microsoft)

Microsoft

  • Microsoft Copilot — surfaced as a Copilot Studio agent, available across Microsoft 365 Copilot, Teams, Outlook, Word, Excel, and PowerPoint

Connecting from a client

Add a remote MCP server entry pointing to https://mcp.optimove.net/mcp with OAuth authentication. The exact configuration path varies by client; consult your client's documentation for its connector or MCP-server settings.

The full machine-readable tool manifest is published at the server endpoint and is surfaced automatically by the host client once connected.

Connecting from Microsoft Copilot

Microsoft Copilot connects through a Copilot Studio agent rather than a direct connector entry. The flow:

  1. In Microsoft Copilot Studio, add the Optimove MCP to your agent as a tool (Tools → Add a tool → New tool → Model Context Protocol), with Server URL https://mcp.optimove.net/mcp.
  2. For authentication, select OAuth 2.0 → Dynamic discovery. The Optimove MCP supports OAuth 2.0 Dynamic Client Registration (DCR) with discovery, so Copilot Studio registers itself and resolves the endpoints automatically — no manual client ID/secret or redirect URI to configure.
  3. Publish the agent to the Microsoft 365 Copilot channel (and optionally Microsoft Teams), then roll it out to yourself, or submit it to your organization catalog for admin approval.
  4. Users @-mention the agent in any Copilot chat. The first tool call surfaces a Connect card where each user signs in with their own Optimove credentials and selects their tenant.
    Per-user OAuth, server-side role-based permissions, and PII masking apply exactly as with any other client — the Copilot Studio agent does not share a single service credential; every user authenticates as themselves.

Copilot Studio supports the Streamable transport, which matches the Optimove MCP endpoint. Copilot Studio's publish and rollout flow is managed by Microsoft and changes frequently — verify against Microsoft's documentation:

Safety model

The connector is built around two contracts: read-only by default, and safe-write where the action is reversible and non-destructive.

Read-only tools

All inspection, listing, and search tools are read-only and cannot modify state. Examples: list campaigns, get promotion details, inspect a trigger, search the documentation.

Safe-write tools

The builder tool can create and edit assets in Optimove. Most are building blocks — Target Groups, triggers, templates, attributes, actions, promotions, and gamification items — that are saved in the tenant and become available to select in the campaign builder. They do not message customers or take effect on their own; they only do something once attached to a campaign that a user activates. Campaigns and streams are created as drafts and never activated, scheduled, or sent by the connector.

The connector can also edit existing drafts and building blocks, provided they are not used by a live or scheduled campaign. For the full list of what can be created and edited, see the Optimove MCP actions reference.

These tools cannot:

  • Activate, schedule, or send a campaign
  • Send a message to any customer
  • Delete any asset
  • Edit anything used by a live or scheduled campaign
  • Change platform settings

Assets created via the MCP appear inside Optimove exactly like ones created in the UI. Campaign activation is always a human action in Optimove — the assistant cannot do it.

Permissions

The connector inherits the permissions of the authenticated Optimove user. A user who cannot see a campaign in the Optimove UI cannot retrieve it through the MCP. Role-based access controls are enforced server-side, not at the prompt layer.

What the connector does not do

  • Does not read or store conversation history
  • Does not access user files outside explicit tool calls
  • Does not transfer money, vouchers, or credits
  • Does not generate images, video, or audio

Tool catalog

The connector exposes five tools, each with a set of actions. They are listed below with their safety hint. Read-only tools may run without per-call approval; safe-write actions always prompt for confirmation. For every action and what it does, see the Optimove MCP actions reference.

ToolWhat it doesAnnotation
analystRead-only analytics and KPIs: campaign and channel performance, uplift and significance, campaign timelines and reach, stream results, funnels, cohorts, audience sizes and profiles, business performance, and real-time and batch execution status.readOnlyHint: true
explorerRead-only inspection of the building blocks in your tenant: attributes, segments, events, KPIs, templates, personalization tags, actions, triggers, target groups, promotions, channels, brand guidelines, the image library, the minigame library, and gamification settings.readOnlyHint: true
builderCreates and edits drafts and building blocks: campaign and stream drafts, target groups, triggers, templates, actions, SDK events, attributes, promotions, and gamification items. Minigames are generated with create_mini_game and published to the library with save_mini_game; see Gamify — AI Minigame Creator (MCP-Driven Generation). Cannot delete, activate, schedule, or send.destructiveHint: true
expertSearches Optimove product documentation (Academy, Developer Hub, Trust Center) and the MCP's own usage docs. Answers "how does X work" and "how do I configure Y" questions.readOnlyHint: true
show_image_galleryDisplays images, such as those from the image library, as a gallery in the AI client.readOnlyHint: true

Authentication

Optimove MCP uses OAuth 2.0 with Dynamic Client Registration. When you connect from a new client, you are redirected to the Optimove sign-in page, where you authenticate with your normal Optimove credentials and approve the requested scope.

Scopes

The connector requests read access to the entities described above, plus safe-write access for the Builder tools. No other scopes are requested. Scopes can be revoked at any time from the Optimove user profile.

Redirect URIs

The Optimove OAuth provider allowlists the redirect URIs of each supported client so that authorization completes cleanly across every surface.

Claude surfaces:

https://claude.ai/api/mcp/auth_callback
https://claude.com/api/mcp/auth_callback

Developer tools (Cursor, VS Code, Kiro, GitHub Copilot CLI) register their own redirect URIs dynamically via Dynamic Client Registration; no static allowlisting is required for these clients.

Session lifetime

Authorization is per-user and per-client. Tokens are short-lived and refreshed automatically by the host client. Revoking a session in Optimove invalidates the connector immediately.

Limits and constraints

  • Tool responses are capped at 25,000 tokens. Large list operations are paginated.
  • Tool handlers complete within 5 minutes; long-running analytics queries return a job handle for polling.
  • Rate limits follow standard Optimove platform rate limits, scoped per user.
  • Supported entities are listed in the Optimove MCP actions reference. Other entities will be added in subsequent releases.
  • Read actions are available across all supported entities. Safe-write actions are limited to the builder tool.

Data handling and privacy

All data accessed through Optimove MCP is governed by the existing Optimove Data Processing Addendum (DPA) and security commitments — the same terms that already cover your Optimove tenant.

Collected:

  • Tool call parameters and results, retained for operational logging and audit — searchable for 15 days, then archived for 1 year
  • OAuth tokens, encrypted at rest and rotated per Optimove's standard token policy
  • Aggregate, anonymized usage telemetry (tool name, latency, success/failure) — never tenant data

Not collected:

  • Conversation history or message content from the host AI client — no prompts or conversations are logged
  • Customer files attached to the conversation in the host client
  • Any data outside the explicit tool call payload

Where data is processed: All processing happens within Optimove's existing tenant infrastructure, in the same region as your Optimove tenant. No tenant data is sent to Anthropic, OpenAI, or any other third party by the Optimove MCP server.

AI training: Optimove does not train AI models on customer data. The MCP server is a stateless gateway between the host AI client and Optimove — it does not forward tenant data to any model provider.

Full privacy policy: optimove.com/privacy-policy

Example prompts for developers and integrators

  • "List all draft campaigns created in the last hour and return their IDs."
  • "Pull the JSON definition of segment lapsed_vip and explain each predicate."
  • "Create a trigger that fires on a deposit event with amount greater than 100, then draft a campaign that uses it."
  • "Create a football-themed scratch card minigame with our brand colors and give me a live preview URL."

Support

FAQ

Common questions about the Optimove MCP connector, covering security, governance, access, supported clients, and capabilities. For the underlying contracts, see the Safety model and Data handling and privacy sections above.

Security, privacy and compliance

Q: Does connecting the Optimove MCP give Optimove access to my AI chat history?

No. The Optimove MCP server only receives structured tool calls — specific API requests with parameters. It never receives or stores your conversation history. Your chat remains within your AI client (Claude or ChatGPT) only.

Q: What data does the MCP actually access — is it raw customer data or aggregated?

The MCP exposes business intelligence: campaign metrics, audience sizes, KPI uplift, lifecycle distributions, and catalog data (templates, actions, attributes). It does not return raw customer records. PII attributes are blocked at the server level. The data returned is consistent with what the authenticated user already sees in the Optimove UI — not more.

Q: Can we control or limit what data the MCP accesses?

Yes — in two ways. First, the MCP respects each user's existing Optimove permissions, so access is bounded to what that user can already see in the UI. Second, PII masking settings configured in Optimove apply to MCP responses — PII attributes are blocked. Admins can manage MCP access by controlling user roles in Optimove.

Q: Is each client's data sandboxed from other clients?

Yes. Tenant isolation is enforced at the authentication layer — every MCP request is cryptographically bound to a single tenant using the verified JWT. Cross-tenant data access is architecturally impossible.

Q: Can the AI agent go rogue and delete data or activate/send campaigns on its own?

No. The MCP's write access is deliberately limited to creating drafts — campaigns, target groups, templates, streams, and similar assets are all saved as drafts, never activated. There is no delete capability exposed anywhere in the MCP; destructive actions simply aren't available as a tool the AI can call. It also can't modify entities that are currently in use by active campaigns or streams — target groups and triggers attached to live campaigns are protected by in-use guards that block any edit which would alter their audience or firing behavior, with no override available. Activating a campaign, sending a message, or deleting anything — or changing something that's live — always requires a human to do it manually in the Optimove platform. The AI can prepare and configure, but it cannot pull the trigger, remove anything, or disturb what's already running — those actions are architecturally out of reach, not just policy-restricted.

Q: What protection exists against prompt injection attacks?

All permissions are enforced server-side. Even if malicious content in an AI conversation attempted to escalate access, the MCP server validates every request against the authenticated user's Optimove role and rejects anything out of scope. The AI client cannot grant itself permissions it doesn't hold.

Q: Where is the data processed and stored?

Queries are processed on Optimove's servers and returned to the authenticated user's AI client in real time. Optimove does not store conversation content or query history. Optimove logs only the tool calls made through the MCP (action, parameters, returned result, user, AI client, and time); these logs are kept for 15 days, then archived for 1 year. Data handling within the AI client is governed by the provider's own infrastructure and retention policies.

Q: What happens if the AI provider (Claude/ChatGPT) experiences a data breach?

Once data is returned to the AI client, it falls under that provider's data regulations and security posture. Anthropic (Claude) and OpenAI (ChatGPT) both hold enterprise-grade security certifications, SOC 2 compliance, and breach notification obligations. Clients with strict data governance requirements should review the relevant provider's Data Processing Agreement (DPA).

Q: Once data reaches the AI provider, who is responsible for it?

The AI provider — Anthropic for Claude, OpenAI for ChatGPT — assumes data processing responsibility once data enters their systems. Their DPAs, retention policies, and compliance frameworks apply from that point. Optimove's responsibility covers the MCP server and the data up to the point it is returned to the authenticated user's client.

Q: Is the data used to train AI models?

Optimove does not train AI models on customer data, and the MCP server does not forward tenant data to any model provider for training. Anthropic and OpenAI both explicitly exclude API and connector data from model training.

One point to be aware of is that model training can also happen on the client side, outside the MCP's control: once data is returned to your AI client, the queries you run and the API responses you receive could be used to train a model within your own environment. That falls under your organization's own data governance rather than the MCP. Clients with strict requirements should address this in the relevant provider's DPA and their internal policies.

Q: Where is the MCP hosted, and who manages each component?

Optimove hosts and runs the MCP server in its own managed cloud environment, in the same region as your Optimove tenant. The AI assistant (Claude, ChatGPT, Microsoft Copilot and so on) runs with your AI provider, under your contract with them. Optimove manages the MCP server, authentication and permission checks. Your AI provider manages the model and chat environment. You manage which users get access, their Optimove roles, and your AI tool's policies.

Q: Is the MCP covered by our existing Optimove DPA?

Yes. There is no separate DPA for the MCP. The MCP is part of the Optimove services, so it falls under your existing signed Optimove DPA; no addendum is needed and it adds no new sub-processor. Once data reaches your AI provider, your agreement with that provider applies.

Q: Exactly which fields are masked as PII?

PII is blocked on the server, at the data and query layer, before anything is returned. It does not depend on the prompt. By default the following are withheld, matched on both display name and field name:

  • Contact: email, phone, mobile
  • Names: first, last, middle, nickname, full name, username, display name
  • Postal: address, street, post code, zip

City, country, state and region stay visible. Any attribute you flag as Use as PII in Data Studio is also withheld; changes are picked up within about 10 minutes. If your customer IDs are email addresses, they are encrypted on the server and never returned.

Q: What data does reach the AI assistant, then?

The MCP returns business data: campaign performance, KPIs (including monetary values), audience sizes and breakdowns, non-PII customer-level values such as lifecycle stage or value tier, and data about entities such as target groups, templates and campaigns. It returns only what the connected user can already see in the Optimove UI. To check exactly what was returned, open the tool call in your AI client.

Audit logs and governance

Q: Does Optimove store our prompts or chat conversations?

No. Optimove never receives your prompts, your chat history or the assistant's answers; those stay in your AI tool. Optimove logs only the actions (tool calls and responses) the assistant performs in Optimove through the MCP. Each log entry records the parameters sent, the result Optimove returned, and who performed the action and when.

Q: Are audit logs generated for what users do through the MCP?

Yes, for actions. Every tool call the assistant makes in Optimove through the MCP is logged with:

  • the tool and action
  • the parameters sent and the result Optimove returned
  • the Optimove user, tenant and region
  • the time, duration and session
  • the AI client used (for example Claude or Copilot)
  • whether it succeeded

Prompts, conversations and the assistant's replies are not logged. Customer PII is masked in results before they are returned or logged.

Q: How traceable is a user's question to the agent's answer?

On Optimove's side, each action traces to the user, the AI client, and the time. The link between the user's question and the assistant's answer exists only in your AI client's chat history, which Optimove never sees or stores. Users can open any tool call in their client to see exactly what Optimove returned. Campaigns, target groups and attributes created through the MCP are tagged "AI Generated" in Optimove; other objects are not tagged.

Q: What is the retention period for operational and audit logs?

Action logs are searchable for 15 days, then archived for 1 year. They are kept in a SOC 2-certified logging platform with restricted internal access.

Q: Can we set our own retention, purge or deletion policies?

Not today. Retention is the same for every customer. Content in your AI assistant follows your AI provider's retention settings, which you control.

Q: Can we export audit or usage data to our own monitoring or governance tools?

There is no self-serve export or feed today. Token usage and cost are visible in your AI provider's admin console.

Access and authentication

Q: How do permissions work? Can some users read but not create?

The MCP inherits each user's Optimove roles and permissions. Access isn't gated by plan or tier. Every action is checked on the server against that user's rights: view rights for reading and analysis, edit rights for creating. If a user can't create a campaign in the UI, the MCP won't let them create one either. Some capabilities also depend on features enabled for your tenant.

Q: Can we give a user separate, more limited permissions for AI use (for example Mike and Mike_AI)?

Not as a separate identity. Access is tied to the user's own Optimove account and permissions. To restrict someone, change their Optimove role.

Q: Does the MCP support SSO and Okta?

Yes. The MCP uses the same sign-in as the Optimove UI, so SSO (including Okta and Microsoft) works the same way. Every MCP user needs a user in the Optimove tenant.

Q: Can we limit connections to our company's managed Claude or ChatGPT account, not personal accounts?

Not today. Access is controlled by the Optimove login, not by which AI account it is used from. Use your AI provider's admin controls to govern which accounts can add connectors.

Q: Can the MCP be turned off for a tenant?

Yes. The MCP can be disabled per tenant. Contact your CSM.

Q: How often do users need to sign in again?

After the initial sign-in, a session lasts up to 31 days (configurable per account) before users need to sign in again. Revoking the session disconnects the connector immediately.

Q: Can one connection access multiple tenants?

No. Each connection is to one tenant.

Supported AI clients

Q: Which AI tools can connect, and which do you recommend?

We support a tested list: Claude (web, desktop, Code, Cowork), ChatGPT, Microsoft Copilot (through a Copilot Studio agent), Codex, GitHub Copilot, Amazon Kiro, VS Code and Cursor. Every tool implements MCP a little differently, so a tool that "supports MCP" is not necessarily compatible. We recommend Claude, which most MCP users choose.

Q: Is Gemini supported?

Not yet. Gemini on the web doesn't support custom MCP connectors.

Q: What licensing is needed?

No Optimove license is required for the MCP. Any licensing for your AI tool is between you and your AI provider.

Q: Our AI tool shows the connector as "requested" and we can't continue. Why?

Your organization's AI admin policy requires approval to install connectors. Ask your IT or AI admin to approve the Optimove connector.

Capabilities and limits

Q: What can the MCP create or change, and what can it never touch?

See the Optimove MCP actions reference for every action the MCP supports. It can never delete anything, activate or send a campaign, or edit anything attached to a live campaign.

Q: What are the response size limits, especially on large accounts?

Each tool response is capped at 25,000 tokens. That is a per-response limit, not a monthly one, and long results come back in pages. Customer lists return the top 100 customers, the same as Customer Explorer. For very large accounts, ask focused questions (a date range, channel or campaign type) rather than full-history questions.

Q: Can we use Data Share or our Snowflake data through the MCP?

No, the MCP returns the data available in Optimove. If you have Data Share, you can combine MCP results with your own Snowflake connection in the same AI assistant.

Q: Can the agent queries or creations be loaded into our data warehouse?

The MCP doesn't push data anywhere. Results stay in your AI assistant, and you can export them from there under your own governance. For warehouse-grade, scheduled data, use Optimove Data Share or the relevant Optimove API endpoint.

Q: What does the MCP cost?

The MCP is free for Optimove customers. Token consumption is billed by your AI provider, and read-heavy questions use more tokens.

Version history

VersionDateChanges
1.3September 2026Expanded the FAQ with questions on security and compliance, audit logs and governance, access and authentication, supported AI clients, and capabilities and limits. Clarified that the connector can edit existing drafts and building blocks not used by a live or scheduled campaign, and added audit-log retention periods (15 days searchable, 1 year archived). Restructured the Tool catalog around the five tools (analyst, explorer, builder, expert, show_image_gallery), added a separate Optimove MCP actions reference page, and noted that stream drafts are now available.
1.2July 2026Added Microsoft Copilot support via a Copilot Studio agent (Microsoft 365 Copilot, Teams, and Office apps). No Microsoft partner status required. Connection uses OAuth 2.0 Dynamic Client Registration through the Copilot Studio Connect card; per-user permissions and PII masking are unchanged.
1.1July 2026Expanded supported-client list: added OpenAI surfaces (ChatGPT, Codex) and developer tools (Cursor, VS Code, Kiro, GitHub Copilot CLI) alongside the Claude surfaces (Claude Code, Web, Desktop, Cowork). Added a dedicated Supported clients section and updated Redirect URIs for the new surfaces.
1.0 (MVP)May 2026Initial public release. Read tools across campaigns, promotions, triggers, journeys, streams, segments, target groups, channels, tenant metadata, Mission Control, and product knowledge. Safe-write tools that create target groups, triggers, calculated attributes, actions, promotions, and minigames, plus draft campaigns. Stream drafting is planned for a future release.


Did this page help you?