MCP server for AI assistants
MCP (Model Context Protocol) is the open standard that lets an AI assistant use a piece of software through tools. The WhatSetter MCP server exposes 34 tools, one per API endpoint, so your assistant can read your leads, import contacts or block a dial prefix from a chat.
The server
Section titled “The server”| Item | Value |
|---|---|
| URL | https://mcp.whatsetter.com/mcp |
| Transport | Streamable HTTP. https://mcp.whatsetter.com/sse still works for older clients. |
| Authentication | OAuth (recommended) or a direct Authorization: Bearer ws_live_… header |
| What it needs | An API key created in Settings, then API & MCP |
The server is a thin translator: every tool call is a call to the REST API with your key. Scopes, rate limits and the anti-ban rules apply exactly as they do for the API.
Two ways to authenticate
Section titled “Two ways to authenticate”OAuth. You add the server URL in your client. The client opens a WhatSetter consent page in your browser; you paste your ws_live_… key once and click Authorize. The client then holds a revocable token and never sees the key again. Use this for Claude, ChatGPT, Cursor, VS Code and any client that supports OAuth.
Direct bearer. You pass the key yourself, in an Authorization: Bearer ws_live_… header. Use this for scripts, servers and clients where you prefer to manage the secret in an environment variable.
POST https://mcp.whatsetter.com/mcpAuthorization: Bearer ws_live_…Either way, revoking the key in the dashboard cuts the connection within a minute.
Claude Code
Section titled “Claude Code”Add the server, then run /mcp inside Claude Code to open the consent page:
claude mcp add --transport http whatsetter https://mcp.whatsetter.com/mcpTo use the key directly instead of OAuth:
claude mcp add --transport http whatsetter https://mcp.whatsetter.com/mcp \ --header "Authorization: Bearer ws_live_…"Add --scope user to make the server available in every project instead of the current one.
Claude (web and desktop app)
Section titled “Claude (web and desktop app)”Custom connectors are configured in your Claude account and then available in the web app and in the Claude desktop app.
- Open Customize, then Connectors.
- Click +, then Add custom connector.
- Paste
https://mcp.whatsetter.com/mcpas the remote MCP server URL, then click Add. - A WhatSetter page opens: paste your API key and click Authorize.
Cursor
Section titled “Cursor”Click the install link, or add the server to ~/.cursor/mcp.json by hand. Cursor opens the consent page on first use.
{ "mcpServers": { "whatsetter": { "url": "https://mcp.whatsetter.com/mcp" } }}To use the key directly, add a headers object with "Authorization": "Bearer ws_live_…" to the same entry.
VS Code
Section titled “VS Code”From the command line, or in .vscode/mcp.json (or your user profile via MCP: Open User Configuration). VS Code runs the OAuth flow in your browser on first connection.
code --add-mcp '{"name":"whatsetter","type":"http","url":"https://mcp.whatsetter.com/mcp"}'{ "servers": { "whatsetter": { "type": "http", "url": "https://mcp.whatsetter.com/mcp" } }}ChatGPT
Section titled “ChatGPT”Remote MCP servers are available to Pro, Plus, Business, Enterprise and Education accounts on the web, after enabling developer mode.
- Open Settings, then Security and login, and turn on Developer mode.
- Go to
chatgpt.com/pluginsand select the plus button to create an app for your MCP server. - Give it a name, and under Connection enter
https://mcp.whatsetter.com/mcpas the MCP server URL. - Choose OAuth as the authentication and complete the WhatSetter consent page.
In a conversation, pick Developer mode from the plus menu and select WhatSetter.
Gemini CLI
Section titled “Gemini CLI”Gemini CLI discovers the OAuth flow by itself for remote HTTP servers:
gemini mcp add --transport http whatsetter https://mcp.whatsetter.com/mcpTo use the key directly:
gemini mcp add --transport http --header "Authorization: Bearer ws_live_…" whatsetter https://mcp.whatsetter.com/mcpCodex CLI
Section titled “Codex CLI”With the key in an environment variable:
export WHATSETTER_API_KEY="ws_live_…"codex mcp add whatsetter --url https://mcp.whatsetter.com/mcp --bearer-token-env-var WHATSETTER_API_KEYOr with OAuth:
codex mcp add whatsetter --url https://mcp.whatsetter.com/mcpcodex mcp login whatsetterThe equivalent in ~/.codex/config.toml:
[mcp_servers.whatsetter]url = "https://mcp.whatsetter.com/mcp"bearer_token_env_var = "WHATSETTER_API_KEY"The 34 tools
Section titled “The 34 tools”Each tool needs the scope of the endpoint it calls. A key without that scope makes the tool answer insufficient_scope.
| Tool | Scope | What it does |
|---|---|---|
whoami |
none | Workspace, key name and granted scopes. Call it first. |
list_leads |
leads:read |
List leads, filterable by status, campaign, phone, source, tracked link, date. |
get_lead |
leads:read |
One lead with status, tags, owner, next action, counters. |
update_lead |
leads:write |
Change status, tags, assigned_to, next_action_at, next_action_label, deal_status, lost_reason. |
handoff_lead |
leads:write |
Stop the AI on this conversation and hand it to a human. |
resume_lead |
leads:write |
Give the conversation back to the AI. |
list_lead_notes |
leads:read |
Notes on a lead, newest first. |
add_lead_note |
leads:write |
Add a note to a lead. |
list_conversations |
conversations:read |
Inbox, most recent activity first. |
get_conversation_messages |
conversations:read |
Full message history of one lead. |
send_whatsapp_message |
messages:send |
Sends a real WhatsApp message to a lead already in conversation. Anti-ban rules and an automatic Idempotency-Key apply. |
list_lists |
lists:read |
Your contact lists. |
create_list |
lists:write |
Create an empty list. |
import_leads |
lists:write |
Push up to 500 contacts into a list. No message is sent by the import itself. |
list_campaigns |
campaigns:read |
Campaigns with status and connected number. |
pause_campaign |
campaigns:write |
Pause an active campaign. |
resume_campaign |
campaigns:write |
Resume a paused campaign. Sending restarts. |
add_campaign_lead |
messages:send |
Sends the first message to an opt-in lead through the campaign pipeline. |
list_bookings |
bookings:read |
Meetings booked by the agent. |
list_groups |
groups:read |
Tracked WhatsApp groups. |
get_group |
groups:read |
One group with counts, invite link, AI mode. |
list_group_members |
groups:read |
Members of a group, active or left. |
list_group_messages |
groups:read |
Transcript of a group. |
list_group_events |
groups:read |
Join and leave events of a group. |
list_webhooks |
webhooks:manage |
Your subscriptions, without secrets. |
create_webhook |
webhooks:manage |
Subscribe an HTTPS endpoint. The secret is returned once. |
delete_webhook |
webhooks:manage |
Remove a subscription. |
test_webhook |
webhooks:manage |
Post a signed test event to your endpoint. |
list_blocked_contacts |
blocklist:manage |
Blocked numbers and dial prefixes. |
block_contact |
blocklist:manage |
Block a number or a dial prefix. The agent stops replying to it. |
unblock_contact |
blocklist:manage |
Remove a block. |
list_team_members |
team:read |
Members of the workspace, to assign leads. |
list_links |
links:read |
Tracked links with click counts. |
get_link |
links:read |
One link with its 30-day stats. |
Only two tools reach a real person on WhatsApp: send_whatsapp_message and add_campaign_lead. resume_campaign restarts a campaign’s own sending. test_webhook posts to your server, not to a contact.
Example prompts
Section titled “Example prompts”- “Show me the leads qualified this week and who owns each one.”
- “Assign every unassigned qualified lead to Julien and set a next action for Monday 9am called Call back.”
- “Block the +91 prefix, reason: out of market.”
- “Which tracked link brought the most leads in the last 30 days?”
- “Import these 40 contacts into a new list called Webinar September.” (paste the contacts)
- “Pause the Acme France campaign.”
- “Summarize the conversation with +33612345678 and add a note with the summary.”
Safety
Section titled “Safety”- Read tools are marked read-only.
send_whatsapp_messageandadd_campaign_leadare marked as side-effecting: a well-behaved client asks you before calling them. Read the message before you approve it, it goes to a real person. - The assistant can only do what the key allows. Give an assistant a Custom key with read scopes if it should not send anything.
- Every
/mcpsession is bound to the key that opened it: a stolen session id is useless without the key. - Revoke the key in Settings, then API & MCP, and everything stops: REST calls, OAuth sessions and direct-bearer sessions alike.

