- The server holds no database credentials. It authenticates each call with your MCP key and forwards it to the API; the project is resolved from the key, never from what the assistant asks for. A key from one project cannot read another.
- Each key carries its own permissions. The assistant only sees, and can only use, the tools its permissions enable.
- You can revoke it any time and access is cut on the next call.
From claude.ai (fastest)
On claude.ai you don’t need to create a key by hand or edit any config file:Add the connector
Authorize
With a key (Claude Desktop, Cursor, Claude Code)
Clients that accept headers in their config use your MCP key directly.Create an MCP key
- Open the dashboard and select your project.
- In the sidebar go to Integrations → API Keys.
- Scroll to the MCP Keys section and click Create key.
- Give it a name and check the permissions you want to grant (see Permissions). Grant only what the assistant needs.
- Copy the key (
rqe_mcp_...).
Connect your AI client
https://mcp.reallyquickemails.com/mcp with your key in the X-API-Key header.- Claude Desktop
- Cursor
- Claude Code
claude_desktop_config.json directly:Verify the connection
Which ReallyQuickEmails project am I connected to?It will call the
whoami tool and answer with your project name and the key’s permissions. If you see an authorization error instead, check that you copied the full key and that it is not revoked.Permissions
Each key grants one or more permissions. The assistant does not see the tools it wasn’t authorized for, and if it tries to use them anyway, the call is rejected.Capabilities and guided workflows
Any valid key can callget_capabilities (no permission needed, just like whoami) and gets the server’s full catalog back: every tool that exists — marking which ones are available for your key and, if not, how to enable them —, what each permission grants, the hard limits of the API (pagination, send_email max recipients, idempotency window), and a set of guided, step-by-step workflows for the jobs people actually ask for.
The same workflows are registered as MCP prompts (prompts/list, prompts/get): a client that supports them can offer them directly, without going through a tool.
Available tools
idempotency_key (optional, in the body or the Idempotency-Key header): the same key with the same body, within 24 hours, replays the original result instead of acting again. The same key with a different body responds 409 IDEMPOTENCY_CONFLICT — a fresh UUID per real action is enough.view_in_app: the direct link to that screen in the app.Contacts — contacts:read
Contacts — contacts:read
Campaigns — campaigns:read
Campaigns — campaigns:read
Metrics, segments, templates and automations
Metrics, segments, templates and automations
Diagnostics — integrations:read
Diagnostics — integrations:read
Writing — contacts:write / segments:write / templates:write / campaigns:write / automations:write
Writing — contacts:write / segments:write / templates:write / campaigns:write / automations:write
Sending — sends:execute
Sending — sends:execute
idempotency_key: the same key within 24h returns the previous result instead of sending again.Identity and utilities — no permission
Identity and utilities — no permission
Errors
Every non-2xx response has the same shape:codeis stable: it decides the next step without parsing prose.suggestionis the concrete fix — your assistant can act on it in the same turn without you stepping in.request_ididentifies that call and also travels in theX-Request-Idheader of every response, success or error. Share it if you need support.
Partner mode (manage your client portfolio)
If you’re a partner managing several clients (each one an RQE project), you can connect the MCP with your partner key (sk_partner_...) instead of a project key. In that mode, a single connection operates at the organization level and exposes 3 tools to manage your portfolio:
list_clients/get_client_stats only see projects in your org, and create_client creates them inside it. To operate a client in detail (send, contacts, campaigns), use its project api_key with the regular MCP. Endpoint details in Partner / Provisioning.Revoke a key
Under Integrations → API Keys → MCP Keys, click Revoke on the key. Access is cut on the next call; an assistant using it will get an authorization error. The revoked key stays listed for your records and cannot be reactivated.FAQ
How is this different from my regular API Key?
How is this different from my regular API Key?
sk_...) gives full access to the API, including sending email, and is meant for your own backend. The MCP key (rqe_mcp_...) has granular permissions and is meant to connect a third-party AI assistant with exactly the access you decide. Never paste your sk_... into an AI client.Can the assistant send email or delete data?
Can the assistant send email or delete data?
sends:execute — without that permission it does not even see the sending tools. Campaigns it creates are always drafts; you send them from the app or, if you granted sends:execute, with send_campaign (which first shows you the summary, can be scheduled with scheduled_at, and waits for your approval) — send_campaign_test sends a test copy before launching, and cancel_campaign stops one that is already sending or scheduled. It does not delete contacts or data: there are no delete tools. Each capability is a separate permission you grant explicitly when creating the key.Can it build complete automations (flows)?
Can it build complete automations (flows)?
automations:write), pause and resume them, and check their performance, but designing the flow itself (nodes, triggers, conditions) happens in the app.What if my assistant gets stuck or something doesn't work?
What if my assistant gets stuck or something doesn't work?
send_flare (no permission needed, any key) to report it with full context: what you were trying to do, what happened, and the chain of calls that led there. It returns a flare_id — hand that to support if you need follow-up.Can I have multiple keys?
Can I have multiple keys?
Why won't claude.ai let me paste the key?
Why won't claude.ai let me paste the key?
rqe_mcp_...), listed and revoked in the same place.