MCP server
Connect Claude, ChatGPT or another AI assistant to one Adrails workspace through the Model Context Protocol, with your Adrails sign-in and the permissions you choose.
Adrails runs a remote MCP server. An AI assistant that supports remote MCP with OAuth connects to it, signs in with your Adrails account, and works in the one workspace you choose: it reads your accounts, figures and findings, prepares advertising changes for you to approve, and, if you allow it, manages integrations, automations, Knowledge and campaign drafts.
The assistant's own model does the reasoning. Adrails returns data, prepares changes and applies nothing to an ad account without your approval in Adrails.
Server URL
https://adrails.ai/api/mcp
- Transport: Streamable HTTP,
POSTonly, JSON responses.GETandDELETEanswer405: there is no event stream and no session. - Authentication: an OAuth 2.1 bearer token, obtained through the sign-in below.
- Tools: 63, described in the tools reference.
In Adrails, MCP in the sidebar gives the same URL with setup steps for each client, your connections and the tool catalog. Settings > Account > AI connections links there too.
How connecting works
- You add the server URL to your client. See Connect an AI client.
- The client registers itself with Adrails, then opens Adrails in your browser. There is no client ID or secret to copy.
- You sign in to Adrails if you are not already.
- The consent screen, titled with the client's name, such as Connect Claude to Adrails, asks for the Workspace and the Permissions this client receives. The workspace list shows your role in each.
- Allow access sends you back to the client, connected. Cancel refuses.
You cannot give consent in an impersonated session, or before you belong to a workspace.
Permissions
The consent screen lists only the permissions your client asked for. A client that asks for nothing in particular gets read access only.
| Permission | Scope | What it allows | Selected at first | Who can grant it |
|---|---|---|---|---|
| Read workspace data | adrails:read | Read accounts, analysis, campaigns, commerce and Knowledge. Required. | Yes | Any member |
| Stay connected | offline_access | Renew access without signing in again, until you revoke the connection. | Yes | Any member |
| Prepare advertising changes | adrails:actions:prepare | Prepare advertising changes, launches and undos for your approval in Adrails. | No | Owner or admin |
| Manage integrations | adrails:integrations:manage | Connect, synchronize and disconnect integrations, enable or disable ad accounts. | No | Owner or admin |
| Manage automations | adrails:workflows:manage | Manage automations and their channels, and run them, including message delivery. | No | Owner or admin |
| Edit Knowledge | adrails:knowledge:write | Create, update, favorite and delete workspace Knowledge. | No | Any member |
| Manage campaign assets | adrails:campaigns:write | Manage campaign drafts, templates and media. | No | Owner or admin |
- Read access cannot be left out: consent without it is refused.
- Select a write permission only for what you want the assistant to do.
- A permission never goes beyond your role. A member who connects with Edit Knowledge still cannot change skills, and permissions that need an owner or admin stop working the day your role drops to member. Which tool needs what: Who can call what.
One workspace per connection
- The connection works in the workspace you chose on the consent screen, for as long as it lasts. Switching workspace in Adrails does not move it.
- To work in another workspace, connect again and choose it. Each workspace is a separate connection.
- Read access covers the whole workspace: every ad account and integration it has. A call can narrow to some accounts, never reach past them.
Tokens
| Token | Lifetime |
|---|---|
| Access token | 10 minutes |
| Authorization code | 10 minutes, single use |
| Refresh token | 30 days, replaced at every use |
- The client renews its access token with a refresh token only if you granted Stay connected. Without it, the client sends you through sign-in again once the access token expires.
- A refresh token used a second time is refused.
- A connection left unused for 30 days has to be authorized again.
Revoke access
Open MCP in Adrails and go to Your connections, at https://adrails.ai/mcp#mcp-connections. It lists every AI client you authorized, in all your workspaces, each with its workspace and its Allowed access. Revoke access asks you to confirm.
Once revoked:
- The next request from that client is refused, and its tokens cannot be renewed.
- Its setup links and approval links stop working.
- Calls already running, changes already applied and automations already started are not undone.
Removing Adrails from your AI client does not revoke the connection in Adrails: revoke it here too.
Access also ends when you leave the workspace or are removed from it, and when the refresh token goes unused for 30 days. A client can revoke its own tokens at the revocation endpoint below.
Plans and credits
The connection uses your workspace's plan, roles and limits, the same as the app. A tool call does not run Adrails' AI model and uses no agent credit. Proposals need an active plan. See Who can call what.
For client developers
Clients find everything below through discovery; it is listed for checking a setup.
| Document or endpoint | URL |
|---|---|
| Protected resource metadata | https://adrails.ai/.well-known/oauth-protected-resource |
| Authorization server metadata | https://adrails.ai/.well-known/oauth-authorization-server |
| Issuer | https://adrails.ai/api/auth |
| Client registration | https://adrails.ai/api/auth/oauth2/register |
| Authorization | https://adrails.ai/api/auth/oauth2/authorize |
| Token | https://adrails.ai/api/auth/oauth2/token |
| Revocation | https://adrails.ai/api/auth/oauth2/revoke |
- A request without a valid token gets
401withWWW-Authenticate: Bearer resource_metadata="https://adrails.ai/.well-known/oauth-protected-resource". - Clients register dynamically, with no credentials. Client ID metadata documents are not supported.
- The grant is the authorization code with PKCE, method
S256, then the refresh token. - The authorization request and the token request both carry
resource=https://adrails.ai/api/mcp. Tokens are issued for that resource only. - The protected resource metadata lists the six Adrails scopes. Add
offline_accessto receive a refresh token.
