Agents
ArcDemo MCP server
Connect AI assistants such as Claude, ChatGPT and Cursor to your ArcDemo workspace over the Model Context Protocol (MCP). Agents can read your demos, analytics and leads, draft and apply edits you can review, and, with an admin's approval, publish demos or sync leads to your CRM.
Availability: the MCP server is part of ArcDemo's early access and is switched on per deployment, read access first. If connecting fails, email support@arcdemo.io.
Connect
- Server URL:
https://mcp.arcdemo.io/mcp(Streamable HTTP). - Sign in with OAuth 2.1 (authorization code with PKCE). You choose one workspace and the scopes the client gets. Discovery follows RFC 9728 protected-resource metadata, so MCP clients that support OAuth find the sign-in page on their own.
- Clients without an OAuth flow can use a personal MCP token from Settings → Agent access. It is shown once, is bound to you, one workspace and the MCP server, and expires (30 days by default).
What agents can do
- Read: demos, steps, collections, share links, workspace context, analytics, step funnels, visitors, accounts and leads, limited by the scopes you grant.
- Draft and edit: audit a demo, draft copy, plan HTML edits, preview a change set, apply it against the current revision, and revert it.
- With approval: publishing, unpublishing, creating or revoking share links, and CRM sync need a single-use approval from a workspace admin in ArcDemo. A model saying "confirmed" is never enough.
- There are no delete or admin tools.
The server also offers read-only resources and a few guided prompts. Everything an agent sees is filtered by the same permissions as the tools.
Safety model
- Access comes from the credential and your membership, never from tool arguments.
- Edits are checked against the demo's current revision, so an agent can't overwrite newer work.
- Captured pages, demo text and CRM data are treated as untrusted content, never as instructions.
- Every call is rate limited and written to the workspace audit log.
- CRM credentials stay in ArcDemo, encrypted. Agents act on a connection you set up in Settings → Integrations and never see the provider's tokens.
REST API for automation
The same capabilities are available to backends and CI over HTTPS at POST https://api.arcdemo.io/api/agent/v1/capabilities/{name} with a scoped, expiring service credential created in Settings → Agent access.