# Email platform MCP servers: auth, writes and sends

Canonical: https://brew.new/blog/esp-mcp-servers-compared
Author: Thomas Park
Published: 2026-10-09
Updated: 2026-10-09

An email platform MCP server is an endpoint that exposes the platform's actions (read a report, edit a template, send a campaign) as tools an AI client such as Claude, ChatGPT or Cursor can call. Almost every large ESP has one. The real differences are what an agent can change and who approves a send.

Below, for each platform: where the server runs, how it authenticates, what it can write and send, and what stands between the agent and your list. Reviewed on October 9, 2026. Brew has its own MCP server, so competitor entries stick to their linked docs.

## Key takeaways

- All 14 platforms let an agent act on the account officially. Mailchimp's Transactional server can send; its Marketing one only searches docs.
- The August and September 2026 "agent access" news was mostly expansion. Klaviyo's remote server went GA on August 20, 2025, Brevo's entered early access on October 14, 2025, and HubSpot's went GA on April 13, 2026.
- Remote plus OAuth is the norm. Postmark is local only; Brevo and Mailchimp Transactional use API keys.
- Few servers enforce a human step on sends. Kit requires a click in Kit, Customer.io has an admin toggle and beehiiv has no MCP sends. Brew adds a server-side confirmation step that binds the exact action, but the human approval itself still happens in your client. Elsewhere your client's prompt is the only check.
- Connect narrow first: Klaviyo's `read-only=true`, Brevo's per-module endpoints, Customer.io's read-only default.

## The comparison table

"Remote" means the vendor hosts it; "local" means you run a package. The guardrail column covers only what the platform enforces.

| Platform | Server | Auth | Agent can write | Can it send? | Platform-side send guardrail | Live since |
| --- | --- | --- | --- | --- | --- | --- |
| Brew | Remote, `brew.new/api/mcp` | OAuth 2.1 or API key | Designs, automations, audiences, domains | Campaigns, tests, trigger fires | Confirmation id on OAuth and organization connections | June 2026 |
| Klaviyo | Remote `mcp.klaviyo.com/mcp`, or local | OAuth (remote), private key (local) | Campaigns, flows, templates, profiles | Yes, `send_campaign` | Optional `read-only=true` flag | Remote GA Aug 20, 2025 |
| HubSpot | Remote `mcp.hubspot.com` | OAuth with PKCE via your own connector | CRM records, email drafts, pages | Schedule and publish (Sep 15, 2026 changelog) | User permissions, audit log | GA Apr 13, 2026 |
| Braze | Remote, US and EU URLs | OAuth with dashboard login | Templates, Content Blocks, catalogs | Campaign API beta only | Admin toggle plus per-user permission, off by default | Remote Jul 23, 2026 |
| Customer.io | Remote, US and EU URLs | OAuth with scopes | Drafts (`write`), live data (`write:live`) | With `write:live` | Read-only default; live edits need admin opt-in | In release notes Oct 7, 2025 |
| Brevo | Remote `mcp.brevo.com` | MCP token (API key) | Email, SMS, WhatsApp campaigns, contacts, CRM | SMS and WhatsApp documented | Per-module endpoints | Oct 14, 2025 (early access) |
| Kit | Remote `app.kit.com/mcp` | OAuth | Subscribers, broadcasts, sequences, pages | Yes | Sends and deletes confirmed in Kit | May 19, 2026 |
| beehiiv | Remote `mcp.beehiiv.com/mcp` | OAuth | Drafts, templates, segments, automations | No | Publishing and activation stay in the app | Mar 24, 2026 |
| Loops | Remote `mcp.loops.so` | OAuth | Contacts, campaigns, workflows, content | Transactional and events | Campaigns sent from the dashboard | Claude connector Aug 12, 2026 |
| Salesforce MCE | Remote, per-tenant URL | OAuth via installed package scopes | Data extensions, journeys, content | Transactional; publish journeys | Package scopes plus user permissions | GA June 2026 |
| Resend | Remote `mcp.resend.com/mcp`, or local | OAuth or API key | Emails, broadcasts, automations, templates | Yes | Client approval only; idempotency key on sends | Remote Jul 7, 2026 |
| Postmark | Local only (npm) | Server token | Sends, templates, suppressions, webhooks | Yes | Tool annotations only | npm package Nov 26, 2025 |
| ActiveCampaign | Remote, per-account URL | Sign in and approve | Contacts, lists, deals, campaign content | No send tool listed | Not documented | Not stated |
| Mailchimp | Transactional: `mandrillapp.com/mcp` | API key | Transactional API | Transactional: yes | Key permission group | Not stated |

![A matrix of 14 email platforms showing whether each MCP server is remote, uses OAuth, can write, can send, and whether the platform runs its own check before a send.](/images/blog/esp-mcp-servers-compared-matrix.png)

*The table as five questions. Green is yes, grey no, amber partial or conditional.*

## Platform notes

### Klaviyo

The [connection guide](https://developers.klaviyo.com/en/docs/connect_to_the_klaviyo_mcp_server) recommends remote (OAuth, dynamic client registration) over local `uvx klaviyo-mcp-server@latest`. The query parameters are the good part: `read-only=true` drops write tools, `disable-tools-with-user-generated-content=true` removes tools that read profile and event data, `toolsets=campaigns:read` limits tools to listed API scopes, and `core-tools-only=true` cuts the list to about 40. The [tool list](https://developers.klaviyo.com/en/docs/klaviyo_mcp_server_available_tools) includes `create_campaign`, `send_campaign` and `cancel_campaign_send`. Klaviyo announced "260+ MCP tools" at K:BOS on September 9, 2026.

### HubSpot

The [remote server](https://developers.hubspot.com/docs/apps/developer-platform/build-apps/integrate-with-the-remote-hubspot-mcp-server) needs an MCP connector created under Development. Scopes follow the tools available at install and what the user grants. The docs list "create and update email drafts," and the September 15 [Fall 2026 changelog](https://developers.hubspot.com/changelog/fall-2026-spotlight) adds "configure send details, schedule, publish." Configuration writes are "attributed in the Audit Log."

### Braze

The remote server replaced an August 2025 local one. The [setup guide](https://www.braze.com/docs/user_guide/brazeai/mcp_server/setup) has the strictest access rules here: users need a "Use MCP Server" permission on top of the admin toggle, and an admin can revoke every MCP token at once. Tools cover analytics, templates, Content Blocks, catalogs and segments, with no user profile data. Campaign creation and `launch_campaign` are beta-only.

### Customer.io

The [server](https://docs.customer.io/ai/mcp/get-started/) reaches the whole Journeys and Data Pipelines APIs through three tools, `cio_read_api`, `cio_write_api` and `cio_delete_api`, all with dry-run previews. The verb split lets a client auto-approve reads and ask before writes. `write:live`, needed to send, works only after an admin turns on "Allow MCP to edit live data."

### Brevo

The [server](https://developers.brevo.com/docs/mcp-protocol) takes an API key with the MCP option checked as a Bearer token. The main endpoint combines 27 modules; each also has its own, such as `/v1/brevo_contacts/mcp`, because fewer tools "can improve response quality." SMS and WhatsApp modules "create and send"; email can "create and manage." Brevo's [Claude connector](https://www.brevo.com/blog/ask-a-question-get-a-campaign-with-the-brevo-connector-for-claude/), launched September 28, 2026, saves drafts only: "Sending, scheduling and deleting stay with you in Brevo."

### Kit

The paid-plan Kit MCP maps the v4 API one to one at 120 requests per minute per token. The [help article](https://help.kit.com/en/articles/14827557-how-to-connect-the-kit-mcp-to-your-ai-tools) lists 65+ tools and the most concrete send guardrail here. For "sending a Broadcast, deleting an Email Sequence, unsubscribing a subscriber, firing a webhook," the server returns a deep link, and nothing happens until you click Confirm in Kit.

### beehiiv

Paid plans got writes on June 16. The [help article](https://www.beehiiv.com/support/article/39255979546263) is blunt: drafts "must be published from the app," automations "must be activated in the app," and "Sending posts via the MCP is not currently available." It points production sends to the versioned API, since the MCP has "no fixed version."

### Loops

The [Loops server](https://loops.so/docs/mcp-server) manages contacts, lists, events, campaigns, workflows and content, and sends published transactional emails. The [August 12 changelog](https://loops.so/changelog/workflows-api-claude-connector) added "revision-safe Workflow writes": each write carries the revision it last read, and Loops rejects it if the workflow changed since. More servers should copy this. For campaigns, Loops says to "open the campaign in the dashboard to publish and send."

### Salesforce Marketing Cloud Engagement

The hosted server is [generally available](https://developer.salesforce.com/blogs/2026/06/the-mcp-server-for-marketing-cloud-engagement-is-now-ga). You install a package, choose its API scopes, and connect with your tenant and client IDs. The agent gets package scopes intersected with your permissions. Tools are labeled Destructive, Asynchronous, Read-only or Open-world, and calls count against your annual API limit.

### Resend

Resend [launched its remote server](https://resend.com/changelog/remote-mcp-server) alongside the open-source `resend-mcp` package. The code registers 106 tools, including `send-email`, `send-batch-emails` and `send-broadcast`. Delete tools tell the model it "MUST double-check with the user," which the server doesn't enforce. `send-email` accepts an `idempotencyKey`.

### Postmark

The [official server](https://postmarkapp.com/lp/mcp) runs via `npx -y @activecampaign/postmark-mcp`. Its 24 tools, annotated read-only, destructive or idempotent, cover sends (500 per batch), templates, diagnostics, bounces, suppressions and webhooks. Postmark asks you to confirm the official repository, with reason: in September 2025 an unofficial `postmark-mcp` npm package [copied every outgoing email](https://www.bleepingcomputer.com/news/security/unofficial-postmark-mcp-npm-silently-stole-users-emails/) to an outside address from version 1.0.16.

### ActiveCampaign and Mailchimp

ActiveCampaign's [remote server](https://developers.activecampaign.com/page/mcp) has about 50 tools (contacts, tags, lists, deals, custom objects, `update_campaign_message`, `add_contact_to_automation`) and no campaign send tool.

Mailchimp's [Transactional MCP](https://mailchimp.com/developer/transactional/guides/how-to-use-mailchimps-transactional-messaging-mcp/) at `https://mandrillapp.com/mcp` "mirrors what our API can already do," sending included. The Marketing MCP server "searches documentation, not your Mailchimp account," and with the Claude connector you "move into your Mailchimp account to finalize and send your campaign."

## What changed in August and September

Our [September State of Email](/blog/state-of-email-september-2026) listed Klaviyo, HubSpot, Salesforce, Braze, Customer.io, Brevo, Kit, beehiiv and Loops as shipping or announcing agent access between August 12 and September 29. All but Loops already had a working MCP server. What was new: Loops' Claude connector, Klaviyo's tool count and SQL preview, Customer.io's analytics tools, HubSpot's marketing email scheduling, Brevo's and beehiiv's official connectors, Salesforce's Headless Marketing announcement, and Braze's Operator Connect.

## How to evaluate an email MCP server

Tool count makes the press release and tells you least.

### Auth model

OAuth ties the agent to a person whose permissions it inherits (Braze, Customer.io, beehiiv and Brew do this), so access ends when they leave. An API key on a laptop belongs to nobody and usually carries more access than the task needs. Keep keys for headless jobs, scoped.

### Write safety

If the agent can reach a live audience, does the platform enforce a human step bound to the exact action? A confirmation the model passes by setting `confirm: true` itself checks nothing. Kit's deep link puts a person in the loop on the server side: nothing happens until someone clicks Confirm in Kit. Brew's single-use confirmation id is enforced by the server too, but it proves something narrower. It stops the agent from changing the recipients or content after the preview, or replaying the send. The agent receives the id itself, so whether a person actually looked depends on your client showing the prompt. The rest rely on the [MCP specification](https://modelcontextprotocol.io/specification/2025-06-18/server/tools), which says clients "SHOULD" show confirmation prompts. Good advice, unenforced.

### Idempotency

Agents retry, and an unrecognised retry after a timeout means a second send. Look for an idempotency key on sends (Resend, Brew), optimistic locking on edits (Loops' revision checks), or the `idempotentHint` annotation (Postmark). We wouldn't let a server with none of these send.

### Scoping per brand or account

Agencies need to know which account a call hits. Braze passes the workspace per request and warns an agent "may select a different workspace than the one you intended." Klaviyo and beehiiv use one connector per account. Brew binds a brand connection to one brand and rejects calls for others with `BRAND_SCOPE_MISMATCH`.

### Rate limits

Agent loops burn through inherited API limits fast. Kit and Loops publish theirs (see the FAQ), and Salesforce counts MCP calls against your annual allowance. Otherwise plan around the regular API limit.

### Tool count versus tool quality

Every tool definition eats context, and models choose worse from long lists, so 260+ tools isn't automatically better than three. Hence Klaviyo's `core-tools-only` and Brevo's per-module endpoints. Read a few descriptions first; good ones say what a tool costs and when not to use it.

## Security: what to set up before you connect

**Treat every tool result as untrusted input.** [OWASP's LLM01](https://genai.owasp.org/llmrisk/llm01-prompt-injection/) calls this indirect prompt injection: external content that "alters the behavior of the model in unintended or unexpected ways." An instruction typed into a subscriber's first-name field lands in your agent's prompt. Klaviyo's user-generated-content flag exists for this.

**Grant the least privilege the job needs.** Start read-only. Salesforce warns "you might not be able to undo changes," and the MCP project's security guidance notes broad up-front scopes make a leaked token worse.

**Require a human for anything that emails people.** Have your client ask before every write, even on servers with their own checks. The specification says clients "MUST consider tool annotations to be untrusted unless they come from trusted servers."

**Install only official packages.** The Postmark copycat shipped clean code for 15 versions first. Prefer hosted URLs; for local servers, pin the version and use the vendor-linked repository.

**Know how to revoke.** Braze admins revoke all tokens at once, Customer.io users their own sessions, and Brew lists OAuth connections under Settings, then MCP. Find that page now. For sender rules, see [what still applies when an agent sends your email](/blog/agent-email-deliverability).

## How Brew's MCP server handles this

Connect to `https://brew.new/api/mcp` with OAuth 2.1 for one brand or the whole organization, or with a brand or organization API key. The [catalog](https://docs.brew.new/api-reference/mcp/tools) has 88 tools, annotated with `readOnlyHint` and `destructiveHint`.

On OAuth and organization connections, a call that emails people or removes contact data first returns `confirmation_required` with the design preview, recipients, automation or addresses. Repeat it with `confirmed: true` and the returned `confirmation_id`, and it runs. Per the [authentication docs](https://docs.brew.new/api-reference/mcp/authentication-and-scoping), the id is good for those exact arguments, from the same connection, for 15 minutes, once. It covers `send_email`, real `run_automation` launches, every `fire_trigger_event`, publishing through `save_automation`, and `delete_contacts`. Be clear about what this guarantees: the server can't tell a person's approval from the agent's own, so pair it with a client that asks before running write tools. Write tools also take an `idempotency_key`, shared with the REST `Idempotency-Key` header, and when `send_email` can't guarantee deduplication it returns a retryable 503 rather than risk a double send.

Brand API-key connections skip the gate, so have your client or code ask. Contacts come in through the REST API, CSV import or integrations. Brew is email only. Production trigger code belongs on the REST API ([MCP versus REST](/blog/mcp-vs-rest-api-for-email-marketing-which-workflow-should-you-use)). Feature comparison: our [earlier MCP roundup](/blog/best-email-marketing-tools-with-mcp-support-campaigns-automations-and-analytics-compared).

## Frequently asked questions

### Which email platforms have an official MCP server?

As of October 9, 2026: Klaviyo, HubSpot, Braze, Customer.io, Brevo, Kit, beehiiv, Loops, Salesforce Marketing Cloud Engagement, Resend, Postmark, ActiveCampaign, Mailchimp Transactional and Brew. Mailchimp Marketing's server only searches docs; account access is via a Claude connector.

### Can an AI agent send an email campaign through MCP?

On several platforms. Klaviyo, Customer.io (with `write:live`), Kit, Resend, Brew and HubSpot (per its September changelog) expose send or schedule actions. beehiiv doesn't send over MCP, Loops sends campaigns from its dashboard, and Brevo's Claude connector saves drafts only.

### Is OAuth or an API key safer for an MCP connection?

For people, OAuth. The token belongs to a user, inherits their permissions, and can be revoked without rotating a shared key. For headless jobs, give each agent its own narrowly scoped key.

### How do I stop an agent from emailing my whole list by mistake?

Connect read-only or draft-only, and require client approval for every write. Prefer platforms that enforce a human step, like Kit, or bind confirmations to the exact action, like Brew, and always send to a seed list first.

### Do email MCP servers have rate limits?

Few publish an MCP-specific figure. Kit allows 120 requests per minute per token, Loops' content API 60 requests per 60 seconds per team, and Salesforce counts MCP calls against your annual API limit. Elsewhere, assume normal API limits.
