For AI agents

Connect an agent to Outreach

Outreach runs a remote Model Context Protocol server. An agent that connects with it can manage campaigns, audiences, senders, contacts, templates and sending limits on your behalf.

Connection details

Endpoint
https://www.outreachemails.online/mcp
Transport
Streamable HTTP, stateless (no session to keep)
Authentication
OAuth 2.0 authorization code with PKCE
Required scope
outreach:manage
Machine-readable guide
https://www.outreachemails.online/llms.txt

Four steps

  1. 1. Discover

    The server card names the transport and the endpoint, so a path never has to be guessed.

    GET https://www.outreachemails.online/.well-known/mcp.json
  2. 2. Register

    Read registration_endpoint from https://www.outreachemails.online/.well-known/oauth-authorization-server and register there. There is no client secret to store: a public client cannot keep one.

  3. 3. Authorize

    Send the account owner to the authorization endpoint. They sign in to Outreach and approve outreach:manage. No password or token is ever shared with the agent.

  4. 4. Call

    Exchange the code plus the PKCE verifier at the token endpoint, then send the access token as a bearer credential.

    POST https://www.outreachemails.online/mcp
    Authorization: Bearer <access_token>
    Content-Type: application/json

If a step is unclear

Call the endpoint with no credentials and read the WWW-Authenticate response header. It states the required scope and the exact metadata URL to fetch next.

POST https://www.outreachemails.online/mcp   →   401
WWW-Authenticate: Bearer ..., scope="outreach:manage",
  resource_metadata="https://www.outreachemails.online/.well-known/oauth-protected-resource/mcp"

Common mistakes

  • Looking for an API key or a token file. The hosted server has neither. It is OAuth only.
  • Treating the 401 as a failure. It is the intended answer and carries the discovery information.
  • Storing the client secret. Registration returns a public client with no secret.
  • Guessing the scope. Use outreach:manage. Omitting the scope parameter also works, because it is a registered default scope.
  • Dropping the www. Use https://www.outreachemails.online exactly; that is the registered origin.

What the access allows

A connected agent can read and change campaigns, audiences, senders, contacts, templates and settings, and can send email. It cannot administer global Gmail OAuth credentials or mint access tokens. Treat an approved agent as equivalent to a signed-in browser session, and revoke it in Clerk under the account’s connected applications when it is no longer needed.