The cold email MCP server for AI agents
Give Claude, ChatGPT, Grok, Claude Code, Cursor or any compatible MCP client direct, secure access to your Emailchaser workspace. 101 tools let your AI agent run campaigns, leads, replies, deliverability and Autopilot, using scoped API keys you can revoke at any time.
The Model Context Protocol (MCP) is the open standard that lets AI assistants use real tools instead of just answering questions. The Emailchaser MCP server exposes your cold email software as 101 tools an AI agent can call (as of September 2026), covering campaigns, leads and prospect sourcing, the Lead Finder contact database, replies and AI reply drafts, sender email accounts, inbox placement and deliverability, ICPs and audience sizing, autopilot runs, credits and spend reports, done-for-you infrastructure, blocklist, webhooks, workspaces with their API keys. It's hosted, so there's nothing to install. Connect your client to the endpoint below with a key from API & MCP in the Emailchaser side menu.
https://app.emailchaser.com/api/mcp
Under the hood, every tool call goes through the Emailchaser API with your key, so the same authentication, scopes and rate limits apply. An AI agent can never do more than the key you gave it allows.
How the MCP server connects
Your AI agent speaks MCP to the hosted server with your API key. The server maps each request to a tool, calls the REST API, and acts on your workspace. Nothing runs on your machine.
Why connect an AI agent
Natural-language control
Ask in plain English (“pause my two worst campaigns”) instead of writing HTTP calls or clicking through a dashboard.
Hosted, zero setup
Nothing to install or run locally. Point your client at one URL with your API key and the tools appear automatically.
Scoped and revocable
Every action uses an API key you control. Use a read-only key for analysis; a read_write key can also spend credits, order infrastructure and send replies. Revoke access instantly whenever you want.
Reads your live data
Tools return live campaign stats, so your agent can read reply rates, decide what to change, then act: read, reason, then do.
Connect your AI assistant in one step
Open API & MCP in the Emailchaser side menu. The “Connect your AI” wizard there writes the exact steps for your tool, and all 101 tools appear the moment you connect.
Claude, ChatGPT and Grok: paste one link
These three add a remote MCP server by address and give you nowhere to type a header, so the key rides in the address instead. Copy your personal MCP link from API & MCP and add it as a custom connector:
https://app.emailchaser.com/api/mcp/YOUR_API_KEY/mcp
That link contains your key, so treat it like a password. Delete the key in API & MCP and the link stops working straight away.
Connect with a link
Claude (claude.ai, desktop and mobile), ChatGPT (chatgpt.com and the apps), Grok (grok.com). One address, pasted once, key included.
Connect with a header
Claude Code (In the terminal), Cursor (The code editor), VS Code (GitHub Copilot). The key travels in the Authorization header, never in the address.
Claude Code
Cursor and other MCP clients
Add the server to your client's MCP configuration (for Cursor, that's ~/.cursor/mcp.json):
Any MCP client that supports remote servers over Streamable HTTP with custom headers works the same way: server URL plus your API key as a Bearer token in the Authorization header.
101 tools for running outbound with AI
The 15 groups below show 95 of the 101 tools. Your MCP client lists the full set the moment you connect.
- list_campaigns
List campaigns with status and stats (sent, replies, bounces)
- create_campaign
Create a campaign
- get_campaign
Get one campaign's settings, schedule and stats
- update_campaign
Change name, timezone, sending limits and deliverability settings
- launch_campaign
Launch a new campaign or resume a paused one
- pause_campaign
Pause sending and cancel scheduled emails
- update_campaign_schedule
Set timezone, sending days, daily window and frequency
- get_campaign_sequence
Read the ordered emails in a sequence, A/B variants included
- replace_campaign_sequence
Replace a campaign's whole sequence
- delete_campaign
Permanently delete a campaign and all its data
- get_campaign_stats
Totals, per-variant and per-step results in one call
- attach_campaign_sender_emails
Attach sending mailboxes to a campaign
- detach_campaign_sender_email
Stop a campaign sending through one mailbox
- list_leads
List leads, newest first, 20 per page
- add_leads
Create or update up to 1,000 leads, straight into a campaign
- get_lead
Get a lead's contact and company details
- update_lead
Update a lead's contact details
- delete_lead
Permanently delete a lead
- get_lead_conversation
Read a lead's full email thread in order
- move_lead_to_campaign
Move a lead to another campaign
- mark_lead_meeting
Record that a meeting was booked
- unmark_lead_meeting
Remove a booked-meeting mark
- update_lead_category
Fix a lead's category after an AI misread a reply
- list_replies
List replies received from prospects, newest first
- list_reply_drafts
List AI reply drafts awaiting review
- update_reply_draft
Edit a draft's subject or body before it goes out
- send_reply_draft
Send a draft to the prospect (cannot be recalled)
- list_sender_emails
List sending accounts with status and daily limits
- get_sender_email
Get one sending account
- connect_sender_email
Connect an SMTP/IMAP mailbox with an app password
- update_sender_email
Change display name, signature or daily limits
- get_sender_email_dns
Check SPF, DKIM, DMARC and MX, with the fix for each
- get_sender_email_warmup
Read a mailbox's warm-up settings: on or off, and the ramp
- update_sender_email_warmup
Turn warm-up on or off and set the ramp, up to 100 mailboxes at once
- list_inbox_placement_tests
List the placement tests in the workspace
- list_inbox_placement_runs
List placement runs, newest first
- get_inbox_placement_run
One run's report: inbox, spam, promotions, missing
- list_inbox_placement_run_results
One row per probe: sender, seed mailbox, where it landed
- get_inbox_placement_stats_by_date
Roll completed runs up by day for a trend
- get_sender_reputation
Latest health check for every mailbox, blacklists included
- get_deliverability_insights
What is wrong right now, worst first, with the fix
- create_icp
Store an ideal-customer profile as targeting criteria
- list_icps
List stored ICPs with their criteria
- get_icp
Get one ICP
- get_primary_icp
Get the profile the workspace currently targets
- set_primary_icp
Promote an ICP to the active one
- update_icp
Partially edit an ICP
- delete_icp
Delete an ICP
- refresh_icp_audience_size
Re-count matching prospects against live data
- get_audience_size
Count prospects matching ad-hoc criteria
- source_prospects
Find and verify prospects into a campaign (spends credits)
- copilot_plan
Build an ICP and a suggested sequence from a website
- copilot_launch
Create a draft campaign and start finding leads for it
- get_lead_finder_filters
The filter values it accepts, today's limits and the credit price
- search_lead_finder
Search the B2B contact database; masked results, no credits
- get_lead_finder_search
Read a search that was still running
- add_lead_finder_prospects
Add chosen people, or N new matches, to a campaign (spends credits and metered verification)
- list_lead_finder_imports
List adds, newest first, with progress and credits spent
- get_lead_finder_import
One add: added, skipped and why, credits spent
- cancel_lead_finder_import
Stop a running add; nothing after the current batch is charged
- plan_autopilot
Turn a monthly budget into domains, mailboxes and volume
- start_autopilot_run
Build the ICP, write the sequence and check prospects match, spending nothing
- list_autopilot_runs
List runs with their status
- get_autopilot_run
One run with its full audit trail
- approve_autopilot_run
Approve a run awaiting approval, the one human gate, which reveals its prospects
- pause_autopilot_run
Suspend a run that is still in flight
- resume_autopilot_run
Resume a paused run
- kill_autopilot_run
Halt a run for good and pause what it launched
- get_credit_balance
Available, reserved, granted and used credits
- list_credit_transactions
Every grant, spend, reservation and refund
- purchase_credits
Buy credits (spends real money)
- get_outcomes_report
Money against results for a time window
- search_dfy_domains
Check availability and pricing of sending domains
- create_dfy_order
Order domains and mailboxes (spends real money)
- list_dfy_orders
List orders with status and cost breakdown
- get_dfy_order
One order's status, costs, domains and mailboxes
- list_blocklist_entries
List blocked domains and addresses
- add_blocklist_entries
Block up to 1,000 entries in one call
- remove_blocklist_entries
Unblock up to 1,000 entries in one call
- get_blocklist_entry
One entry, when it was added and which list
- update_blocklist_entry
Change one entry's value or scope
- remove_blocklist_entry
Remove one entry
- list_webhooks
List endpoints with their event type and status
- create_webhook
Subscribe a URL to replies, bounces, sends and more
- update_webhook
Change an endpoint's URL, event type or enabled state
- delete_webhook
Remove an endpoint so it stops receiving events
- import_instantly
Import Instantly.ai campaigns and leads
- list_instantly_accounts
List Instantly sending accounts, with a pre-filled CSV
- confirm_connection
Confirm the key works and show the app which AI connected
- get_workspace_details
Campaign counts by status, plus the member list
- list_workspaces
The main workspace and its sub-workspaces
- create_workspace
Create a sub-workspace, one per client for an agency
- create_workspace_api_key
Mint a key for a workspace the calling key owns
- get_billing_profile
Registrant and postal details held for the workspace
- set_billing_profile
Create or replace registrant and postal details
What you can ask your AI agent to do
- “Onboard acme.com on Autopilot with a $500/month budget, and tell me when it's ready for my approval.”
- “Which of my campaigns got the most replies? Pause the two worst performers.”
- “Add these 40 leads from the attached CSV to my "SaaS founders" campaign and launch it.”
- “Check if any of my sender email accounts are disconnected and list them.”
- “Set every running campaign to send Monday to Friday, 9am to 5pm New York time.”
- “Register a webhook so my CRM gets notified whenever a lead replies.”
Because the tools return live campaign stats, your agent can combine them: read reply rates with list_campaigns, decide what to change, then act with pause_campaign or update_campaign_schedule.
An agent can also drive Autopilot: hand it a company domain and a monthly budget, and Autopilot derives the ICP, sizes the audience and drafts the sequence, then parks the whole run at a single human approval. Nothing is revealed, bought or sent until the run is approved. Approval is what reveals the prospects, buys and ramps any sending infrastructure the budget calls for, and launches the campaign. The approve_autopilot_run tool tells an agent to show you the plan first, but the backend cannot tell an agent's approval from yours: the read_write key an agent needs to start a run can also approve it.
Agents can chain servers, too. Our sister product exposes 1Lookup's MCP server for email and phone validation, so an agent can check a list there first and push only the contacts that verify into an Emailchaser campaign.
Secure by design
Giving an agent access should never mean giving up control. Every connection is scoped to a key you own and can pull back instantly.
Your key, your scope
Every key is read-only or read_write, with nothing in between, enforced by the backend, not by the MCP layer. A read-only key can use the read tools plus three that buy and change nothing (the connection check, audience sizing and Lead Finder search) and gets HTTP 403 on everything else. A read_write key can use every tool, including the ones that spend credits, order domains and mailboxes, approve Autopilot runs and send replies to prospects.
Revoke any time
Delete a key in API & MCP in the side menu and the agent loses access immediately. Every call is authenticated with that key.
Annotated tools, money flagged
Read-only tools are marked safe and delete tools destructive, so MCP clients can run reads freely and prompt you before actions that change your data. The tools that spend real money (purchase_credits, create_dfy_order, approve_autopilot_run) say so in their own descriptions.
Same limits as the API
Every call runs through the REST API with the same authentication and rate limits, so an agent can never exceed them.
API or MCP: same power, two front doors
Both surfaces do the same things with the same keys. Pick the one that matches how you work, or use both.
REST API
MCP server
Same keys · same scopes · same rate limits
What customers reported
“I’ve been managing cold email campaigns for quite some time, mostly for clients using Instantly and Smartlead. Recently, I started managing campaigns for two clients on Emailchaser, and honestly, it feels much smoother and more reliable than the other platforms. I’ve also seen higher reply rates here, which has been a great result.”
“Btw thanks for your continuous help, best support ever! It means a lot as when I understand how the tool works, esp. In problematic situations, and And what it can do and cannot so from the start, I have more trust. There’s nothing worse for a user than what Smartlead does: lots of great features that don’t really work, including crucial ones for a sequencer like auto fallback to connected accounts when account gets disconnected (doesn’t have to get back to the original one after reconnection, no one expects miracles, just a solid infra delivering on its specs - not promises), plus their low quality support when the issues are revealed.”
MCP server FAQ
MCP (Model Context Protocol) is an open standard that lets AI assistants like Claude securely use external tools. An MCP server exposes a set of tools (in Emailchaser's case, tools for managing cold email campaigns, leads, sender accounts and webhooks) that an AI agent can call on your behalf, with your permission.
Anything the 101 tools allow: list and analyze campaigns, launch or pause sending, rewrite sequences, add up to 1,000 leads at a time, search the Lead Finder contact database and add people from it to a campaign, read and send AI reply drafts, connect and health-check sender mailboxes, run inbox placement tests, build ICPs and size an audience, run Autopilot, manage credits, done-for-you orders, the blocklist and webhooks. You stay in control. Read-only tools are marked safe and the delete tools are marked destructive, so MCP clients can run reads freely and prompt you before anything that changes your data.
Two kinds. Claude, ChatGPT and Grok add a remote MCP server by address, so you paste your personal MCP link (https://app.emailchaser.com/api/mcp/YOUR_API_KEY/mcp) as a custom connector. Claude Code, Cursor, VS Code and anything else that supports Streamable HTTP with custom headers take the server URL plus your key as a Bearer token in the Authorization header. The "Connect your AI" wizard under API & MCP writes the exact steps for whichever you use.
The MCP server only works with an API key you create, scoped to one workspace. Create a read-only key if you just want analysis and reporting, and revoke any key instantly from API & MCP in the side menu. Every call is subject to the same authentication and rate limits as the regular API, and destructive tools are flagged so MCP clients can prompt before using them. The three tools that spend real money say so in their descriptions. There is no scope between read-only and read_write, though: a read_write key lets the agent spend credits, order domains and mailboxes, approve Autopilot runs and send replies to prospects, so give it one only if you are happy for it to do all of that.
Yes. Connect with a read-only key and the agent can call the list and get tools but not the ones that create, update, launch, pause, delete, buy or send. The backend rejects any write attempt, so the agent simply gets an error instead of modifying your data. There is no middle setting: a read_write key unlocks every tool at once.
The MCP server returns tool results to whichever MCP client you connect, for example Claude Code. Whatever model that client uses will see those results, exactly as it would see any other context you give it. Connect only clients you trust, and use a read-only key when you just need analysis.
No. The Emailchaser MCP server is hosted. There is no npm package to install or process to run locally. Point your MCP client at the server URL with your API key and the tools appear automatically.
Delete the API key in API & MCP in the side menu. Because every MCP call is authenticated with that key, the connection stops working the moment the key is removed.
They expose the same capabilities. The REST API is for code: your product, scripts or no-code tools making HTTP calls. The MCP server wraps that same API so AI agents can use it through natural language. Same keys, same scopes, same rate limits.
Still not convinced?
Read all 34 customer messages.
SEE REVIEWSP.s. these are actually real reviews (not fake G2 reviews) 🙂
“Btw thanks for your continuous help, best support ever! It means a lot as when I understand how the tool works, esp. In problematic situations, and And what it can do and cannot so from the start, I have more trust. There’s nothing worse for a user than what Smartlead does: lots of great features that don’t really work, including crucial ones for a sequencer like auto fallback to connected accounts when account gets disconnected (doesn’t have to get back to the original one after reconnection, no one expects miracles, just a solid infra delivering on its specs - not promises), plus their low quality support when the issues are revealed.”
“Got my first reply with Emailchaser :)”
“We've recently upgraded to the premium plan to increase our sending volume. Just wanted to say thanks for such an awesome platform and the support you've already given in getting us started.”
Ready to 10x your pipeline?
Send your first cold email campaign today.
Start my free trial