How 14 email platforms' MCP servers compare as of October 9, 2026: hosting, OAuth or API keys, write access, and who has to approve a send.

An email platform MCP server is an endpoint that exposes the platform's actions (read a report, edit a template, send a campaign) as tools an AI client such as Claude, ChatGPT or Cursor can call. Almost every large ESP has one. The real differences are what an agent can change and who approves a send.
Below, for each platform: where the server runs, how it authenticates, what it can write and send, and what stands between the agent and your list. Reviewed on October 9, 2026. Brew has its own MCP server, so competitor entries stick to their linked docs.
read-only=true, Brevo's per-module endpoints, Customer.io's read-only default."Remote" means the vendor hosts it; "local" means you run a package. The guardrail column covers only what the platform enforces.
| Platform | Server | Auth | Agent can write | Can it send? | Platform-side send guardrail | Live since |
|---|---|---|---|---|---|---|
| Brew | Remote, brew.new/api/mcp |
OAuth 2.1 or API key | Designs, automations, audiences, domains | Campaigns, tests, trigger fires | Confirmation id on OAuth and organization connections | June 2026 |
| Klaviyo | Remote mcp.klaviyo.com/mcp, or local |
OAuth (remote), private key (local) | Campaigns, flows, templates, profiles | Yes, send_campaign |
Optional read-only=true flag |
Remote GA Aug 20, 2025 |
| HubSpot | Remote mcp.hubspot.com |
OAuth with PKCE via your own connector | CRM records, email drafts, pages | Schedule and publish (Sep 15, 2026 changelog) | User permissions, audit log | GA Apr 13, 2026 |
| Braze | Remote, US and EU URLs | OAuth with dashboard login | Templates, Content Blocks, catalogs | Campaign API beta only | Admin toggle plus per-user permission, off by default | Remote Jul 23, 2026 |
| Customer.io | Remote, US and EU URLs | OAuth with scopes | Drafts (write), live data (write:live) |
With write:live |
Read-only default; live edits need admin opt-in | In release notes Oct 7, 2025 |
| Brevo | Remote mcp.brevo.com |
MCP token (API key) | Email, SMS, WhatsApp campaigns, contacts, CRM | SMS and WhatsApp documented | Per-module endpoints | Oct 14, 2025 (early access) |
| Kit | Remote app.kit.com/mcp |
OAuth | Subscribers, broadcasts, sequences, pages | Yes | Sends and deletes confirmed in Kit | May 19, 2026 |
| beehiiv | Remote mcp.beehiiv.com/mcp |
OAuth | Drafts, templates, segments, automations | No | Publishing and activation stay in the app | Mar 24, 2026 |
| Loops | Remote mcp.loops.so |
OAuth | Contacts, campaigns, workflows, content | Transactional and events | Campaigns sent from the dashboard | Claude connector Aug 12, 2026 |
| Salesforce MCE | Remote, per-tenant URL | OAuth via installed package scopes | Data extensions, journeys, content | Transactional; publish journeys | Package scopes plus user permissions | GA June 2026 |
| Resend | Remote mcp.resend.com/mcp, or local |
OAuth or API key | Emails, broadcasts, automations, templates | Yes | Client approval only; idempotency key on sends | Remote Jul 7, 2026 |
| Postmark | Local only (npm) | Server token | Sends, templates, suppressions, webhooks | Yes | Tool annotations only | npm package Nov 26, 2025 |
| ActiveCampaign | Remote, per-account URL | Sign in and approve | Contacts, lists, deals, campaign content | No send tool listed | Not documented | Not stated |
| Mailchimp | Transactional: mandrillapp.com/mcp |
API key | Transactional API | Transactional: yes | Key permission group | Not stated |

The table as five questions. Green is yes, grey no, amber partial or conditional.
The connection guide recommends remote (OAuth, dynamic client registration) over local uvx klaviyo-mcp-server@latest. The query parameters are the good part: read-only=true drops write tools, disable-tools-with-user-generated-content=true removes tools that read profile and event data, toolsets=campaigns:read limits tools to listed API scopes, and core-tools-only=true cuts the list to about 40. The tool list includes create_campaign, send_campaign and cancel_campaign_send. Klaviyo announced "260+ MCP tools" at K:BOS on September 9, 2026.
The remote server needs an MCP connector created under Development. Scopes follow the tools available at install and what the user grants. The docs list "create and update email drafts," and the September 15 Fall 2026 changelog adds "configure send details, schedule, publish." Configuration writes are "attributed in the Audit Log."
The remote server replaced an August 2025 local one. The setup guide has the strictest access rules here: users need a "Use MCP Server" permission on top of the admin toggle, and an admin can revoke every MCP token at once. Tools cover analytics, templates, Content Blocks, catalogs and segments, with no user profile data. Campaign creation and launch_campaign are beta-only.
The server reaches the whole Journeys and Data Pipelines APIs through three tools, cio_read_api, cio_write_api and cio_delete_api, all with dry-run previews. The verb split lets a client auto-approve reads and ask before writes. write:live, needed to send, works only after an admin turns on "Allow MCP to edit live data."
The server takes an API key with the MCP option checked as a Bearer token. The main endpoint combines 27 modules; each also has its own, such as /v1/brevo_contacts/mcp, because fewer tools "can improve response quality." SMS and WhatsApp modules "create and send"; email can "create and manage." Brevo's Claude connector, launched September 28, 2026, saves drafts only: "Sending, scheduling and deleting stay with you in Brevo."
The paid-plan Kit MCP maps the v4 API one to one at 120 requests per minute per token. The help article lists 65+ tools and the most concrete send guardrail here. For "sending a Broadcast, deleting an Email Sequence, unsubscribing a subscriber, firing a webhook," the server returns a deep link, and nothing happens until you click Confirm in Kit.
Paid plans got writes on June 16. The help article is blunt: drafts "must be published from the app," automations "must be activated in the app," and "Sending posts via the MCP is not currently available." It points production sends to the versioned API, since the MCP has "no fixed version."
The Loops server manages contacts, lists, events, campaigns, workflows and content, and sends published transactional emails. The August 12 changelog added "revision-safe Workflow writes": each write carries the revision it last read, and Loops rejects it if the workflow changed since. More servers should copy this. For campaigns, Loops says to "open the campaign in the dashboard to publish and send."
The hosted server is generally available. You install a package, choose its API scopes, and connect with your tenant and client IDs. The agent gets package scopes intersected with your permissions. Tools are labeled Destructive, Asynchronous, Read-only or Open-world, and calls count against your annual API limit.
Resend launched its remote server alongside the open-source resend-mcp package. The code registers 106 tools, including send-email, send-batch-emails and send-broadcast. Delete tools tell the model it "MUST double-check with the user," which the server doesn't enforce. send-email accepts an idempotencyKey.
The official server runs via npx -y @activecampaign/postmark-mcp. Its 24 tools, annotated read-only, destructive or idempotent, cover sends (500 per batch), templates, diagnostics, bounces, suppressions and webhooks. Postmark asks you to confirm the official repository, with reason: in September 2025 an unofficial postmark-mcp npm package copied every outgoing email to an outside address from version 1.0.16.
ActiveCampaign's remote server has about 50 tools (contacts, tags, lists, deals, custom objects, update_campaign_message, add_contact_to_automation) and no campaign send tool.
Mailchimp's Transactional MCP at https://mandrillapp.com/mcp "mirrors what our API can already do," sending included. The Marketing MCP server "searches documentation, not your Mailchimp account," and with the Claude connector you "move into your Mailchimp account to finalize and send your campaign."
Our September State of Email listed Klaviyo, HubSpot, Salesforce, Braze, Customer.io, Brevo, Kit, beehiiv and Loops as shipping or announcing agent access between August 12 and September 29. All but Loops already had a working MCP server. What was new: Loops' Claude connector, Klaviyo's tool count and SQL preview, Customer.io's analytics tools, HubSpot's marketing email scheduling, Brevo's and beehiiv's official connectors, Salesforce's Headless Marketing announcement, and Braze's Operator Connect.
Tool count makes the press release and tells you least.
OAuth ties the agent to a person whose permissions it inherits (Braze, Customer.io, beehiiv and Brew do this), so access ends when they leave. An API key on a laptop belongs to nobody and usually carries more access than the task needs. Keep keys for headless jobs, scoped.
If the agent can reach a live audience, does the platform enforce a human step bound to the exact action? A confirmation the model passes by setting confirm: true itself checks nothing. Kit's deep link puts a person in the loop on the server side: nothing happens until someone clicks Confirm in Kit. Brew's single-use confirmation id is enforced by the server too, but it proves something narrower. It stops the agent from changing the recipients or content after the preview, or replaying the send. The agent receives the id itself, so whether a person actually looked depends on your client showing the prompt. The rest rely on the MCP specification, which says clients "SHOULD" show confirmation prompts. Good advice, unenforced.
Agents retry, and an unrecognised retry after a timeout means a second send. Look for an idempotency key on sends (Resend, Brew), optimistic locking on edits (Loops' revision checks), or the idempotentHint annotation (Postmark). We wouldn't let a server with none of these send.
Agencies need to know which account a call hits. Braze passes the workspace per request and warns an agent "may select a different workspace than the one you intended." Klaviyo and beehiiv use one connector per account. Brew binds a brand connection to one brand and rejects calls for others with BRAND_SCOPE_MISMATCH.
Agent loops burn through inherited API limits fast. Kit and Loops publish theirs (see the FAQ), and Salesforce counts MCP calls against your annual allowance. Otherwise plan around the regular API limit.
Every tool definition eats context, and models choose worse from long lists, so 260+ tools isn't automatically better than three. Hence Klaviyo's core-tools-only and Brevo's per-module endpoints. Read a few descriptions first; good ones say what a tool costs and when not to use it.
Treat every tool result as untrusted input. OWASP's LLM01 calls this indirect prompt injection: external content that "alters the behavior of the model in unintended or unexpected ways." An instruction typed into a subscriber's first-name field lands in your agent's prompt. Klaviyo's user-generated-content flag exists for this.
Grant the least privilege the job needs. Start read-only. Salesforce warns "you might not be able to undo changes," and the MCP project's security guidance notes broad up-front scopes make a leaked token worse.
Require a human for anything that emails people. Have your client ask before every write, even on servers with their own checks. The specification says clients "MUST consider tool annotations to be untrusted unless they come from trusted servers."
Install only official packages. The Postmark copycat shipped clean code for 15 versions first. Prefer hosted URLs; for local servers, pin the version and use the vendor-linked repository.
Know how to revoke. Braze admins revoke all tokens at once, Customer.io users their own sessions, and Brew lists OAuth connections under Settings, then MCP. Find that page now. For sender rules, see what still applies when an agent sends your email.
Connect to https://brew.new/api/mcp with OAuth 2.1 for one brand or the whole organization, or with a brand or organization API key. The catalog has 88 tools, annotated with readOnlyHint and destructiveHint.
On OAuth and organization connections, a call that emails people or removes contact data first returns confirmation_required with the design preview, recipients, automation or addresses. Repeat it with confirmed: true and the returned confirmation_id, and it runs. Per the authentication docs, the id is good for those exact arguments, from the same connection, for 15 minutes, once. It covers send_email, real run_automation launches, every fire_trigger_event, publishing through save_automation, and delete_contacts. Be clear about what this guarantees: the server can't tell a person's approval from the agent's own, so pair it with a client that asks before running write tools. Write tools also take an idempotency_key, shared with the REST Idempotency-Key header, and when send_email can't guarantee deduplication it returns a retryable 503 rather than risk a double send.
Brand API-key connections skip the gate, so have your client or code ask. Contacts come in through the REST API, CSV import or integrations. Brew is email only. Production trigger code belongs on the REST API (MCP versus REST). Feature comparison: our earlier MCP roundup.
As of October 9, 2026: Klaviyo, HubSpot, Braze, Customer.io, Brevo, Kit, beehiiv, Loops, Salesforce Marketing Cloud Engagement, Resend, Postmark, ActiveCampaign, Mailchimp Transactional and Brew. Mailchimp Marketing's server only searches docs; account access is via a Claude connector.
On several platforms. Klaviyo, Customer.io (with write:live), Kit, Resend, Brew and HubSpot (per its September changelog) expose send or schedule actions. beehiiv doesn't send over MCP, Loops sends campaigns from its dashboard, and Brevo's Claude connector saves drafts only.
For people, OAuth. The token belongs to a user, inherits their permissions, and can be revoked without rotating a shared key. For headless jobs, give each agent its own narrowly scoped key.
Connect read-only or draft-only, and require client approval for every write. Prefer platforms that enforce a human step, like Kit, or bind confirmations to the exact action, like Brew, and always send to a seed list first.
Few publish an MCP-specific figure. Kit allows 120 requests per minute per token, Loops' content API 60 requests per 60 seconds per team, and Salesforce counts MCP calls against your annual API limit. Elsewhere, assume normal API limits.
