Agent Planners MCP server: drive your ad accounts from any MCP client
Agent Planners exposes its own MCP server at https://www.agentplanners.com/api/mcp. An external agent signs in with OAuth (a person approves it on a consent page) or authenticates with an API key, and gets one of two modes, decided by the scopes it holds: AGENT mode, where it hands the platform a goal and the platform plans and executes the whole task; or TOOLS mode, where it calls the ad and analytics tools directly under your connected accounts while the platform brokers credentials, guardrails and the audit trail. A key's writes are queued for an admin's approval or run inside the organization's autonomy guardrails, as the admin chose when minting it, and a write a platform marks as a person's decision never applies without a person, whatever the key's mode — an external client does not get a way around it.
Two modes, chosen by the key
You do not pick a mode in a config file; the scopes of the key (or of the OAuth connection a person approved) decide it, and describe_permissions tells the client exactly what it may do before it tries anything.
| Mode | Scopes | What the client gets |
|---|---|---|
| Agent | tasks:* + accounts:read | create_task, get_task, list_accounts — the platform plans and executes; the client polls. |
| Tools | tools:read / tools:write | Direct family__tool calls (google_ads__search, ga4__run_report, …) against your connected accounts. |
| Raw | tools:raw | Compose your own read-only REST calls with family__raw_request — credentials injected, paths bound to the connected resource. |
The tool list loads on demand
A key that reaches more than 100 platform tools does not send all of them to your client. Its tools/list carries three tools instead — search_tools, describe_tool and call_tool — and the client's model searches by what it wants to do (in English or Chinese), reads the arguments of the tool it picked, and runs it through call_tool with the same approvals, scopes and credit charges as a direct call. A key with 100 tools or fewer gets the plain list.
Measured on the full catalogue (October 2026) with three models: the same tool chosen as with the full list, about 97 % fewer input tokens per request and roughly half the latency, because the full list is 130,000–175,000 tokens on every turn. The API & MCP page shows each key's listing — auto, full or on demand — and changes it instantly.
What an external client cannot do
- It cannot see a credential. The platform injects them; nothing is returned to the client.
- It cannot go around the guardrails: a tools:write key's writes run inside the organization's autonomy guardrails (magnitude caps, protected names, the monthly spend cap), or queue for an admin when the key was minted in approval mode, and every write is audited. A write a platform marks as a person's decision — a permanent delete on any ad platform, a store refund, Tag Manager code — is held for a person on every key, or not offered over MCP at all (publishing a Tag Manager container, deleting a Merchant Center feed).
- A raw WRITE from a key that also has tools:write is queued for human approval unless the key was minted for autonomous raw writes — nothing changes until an admin approves, and the client polls raw_request_status.
- It cannot exceed the organization's plan entitlement; tools mode is limited to paid plans.
- It cannot spend credits on tools you have not allowed. Platform tools — web search, scraping, the hosted browser, page audits, image and video generation, email, worker hosting, DataForSEO and Context.dev — run on Agent Planners' own credentials, so each key exposes all of them, a chosen few or none, and a task the key creates follows the same choice. Every tools-mode call is billed to the organization's credits, a platform tool at its own rate on top; with no credits left a call is refused with a message to top up, never charged.
Connecting
The transport is Streamable HTTP (JSON-RPC 2.0 over POST), protocol version 2025-06-18. An MCP host that implements MCP authorization needs only the endpoint URL: it finds the OAuth sign-in on its own and opens the Agent Planners consent page, where a person signs in, picks the workspace and approves what the host may do. Any other host sends an API key in an Authorization: Bearer header. The OAuth guide has every client's steps and the flow for your own app.
- Claude (claude.ai, Desktop, mobile): Customize → Connectors → Add custom connector, enter the URL, select Connect.
- Claude Code: claude mcp add --transport http agent-planners https://www.agentplanners.com/api/mcp, then /mcp to sign in.
- ChatGPT: turn on developer mode (Settings → Security and login), then add the URL on ChatGPT's plugins page.
- Codex: codex mcp add agentplanners --url https://www.agentplanners.com/api/mcp, then codex mcp login agentplanners.
Frequently asked questions
- Where is the endpoint?
- https://www.agentplanners.com/api/mcp — one URL for both modes. Add it to your MCP host and sign in with OAuth, or create an API key on the API & MCP page and send it as Authorization: Bearer.
- Can I connect without copying an API key?
- Yes. The server supports OAuth 2.1 sign-in: add https://www.agentplanners.com/api/mcp to Claude, ChatGPT, Codex or another MCP host that implements MCP authorization, and it opens the Agent Planners consent page, where you sign in, choose the workspace and approve what the host may do. The connection then appears on the API & MCP page under Connected apps, where you can disconnect it. See OAuth sign-in.
- How do I add Agent Planners to Claude, ChatGPT or Codex?
- Claude (claude.ai, Desktop and mobile): Customize → Connectors → Add custom connector, enter https://www.agentplanners.com/api/mcp and select Connect. Claude Code: claude mcp add --transport http agent-planners https://www.agentplanners.com/api/mcp, then /mcp to sign in. ChatGPT: turn on developer mode (Settings → Security and login) and add the same URL on ChatGPT's plugins page. Codex: codex mcp add agentplanners --url https://www.agentplanners.com/api/mcp, then codex mcp login agentplanners. Each one opens the Agent Planners consent page once; OAuth sign-in has the details.
- Is it listed in the Claude connector directory?
- Not yet. The OAuth sign-in a directory listing needs is live, so Claude and ChatGPT already connect the server by its URL as a custom connector, with no key to copy; until a listing is published, add it that way.
- Does an MCP client get more access than the web app?
- No — less. It is the same scope, guardrail, approval and audit stack, narrowed further by the key's own scopes.
- Can I limit a key to read-only?
- Yes. Scopes are per key, so a research client can be given reads and nothing else.
- Why does my client list only three tools?
- Because the key reaches more than 100 tools, its tool list loads on demand: search_tools finds a tool by intent, describe_tool returns its arguments and call_tool runs it — every platform tool stays callable, with the same approvals and charges. Set the key to full on the API & MCP page if a client needs the whole list up front.
- Can a key expose only some platforms?
- Yes. On the API & MCP page each key has a platforms setting: every connected platform (the default — a platform you connect later is added automatically) or only the ones you tick (a platform you connect later is not added until you tick it; one you tick before connecting it switches on once it is connected). The key then lists, searches and calls only those platforms' tools, reads only their accounts, and a task it starts is held to the same choice. Fewer platforms also means a shorter tool list for the agent: a key set to full whose list would pass the 400 KB budget is served on demand until you narrow it.
- Can my local Codex or Claude Code use the custom MCP servers and Composio tools I connected?
- Yes. A key whose platform-tools choice is all platform tools lists list_connector_tools and call_connector_tool when your workspace has a custom MCP server or a Composio key. A read runs at once; a write always waits for a person to approve it on the API & MCP page, whatever the key's write mode. What comes back is third-party text, never instructions.
- Which built-in tools can a local agent use over MCP?
- Almost all of them: sending an email (it always tells you it left the workspace, and a key that queues writes asks a person first), uploading a file from a URL to the asset library, creating, pausing, editing and deleting alert rules, listing, pausing and deleting schedules, dashboards, reports, PDF / Sheets / Slides exports, image and video generation, web search and page fetches, public data feeds, memory and skills. Three stay inside a task because they read the task itself: reading a chat attachment, drafting a recommendation and building a slide deck.
- Can a local agent read the workspace's memory?
- Yes, read-only: search_memory recalls the facts and learnings earlier runs saved, get_account_memory returns one account's rules, targets, protected names and recent history, and list_skills / get_skill return your playbooks. Memory text comes back with emails masked, and phone numbers too for CRM, email and store accounts.
- Can a key be kept off the paid platform tools?
- Yes. Each key chooses which platform tools it exposes — web search, scraping, the hosted browser, generation, DataForSEO, Context.dev and the rest — all of them, a chosen few or none, and a task it creates follows the same choice. Every call it makes is billed to the organization's credits, and with none left a call is refused with a message to top up.