The Arcalotl MCP server
Arcalotl exposes its subscription, member, entitlement and analytics data to AI agents over the Model Context Protocol, using the same API keys and the same scopes as the REST API.
Arcalotl runs a Model Context Protocol server at https://api.arcalotl.com/mcp. An MCP client such as Claude Code, Claude Desktop or Cursor connects to it directly, so an assistant can answer a question like "which subscribers are past due" or create a checkout link for a tier without anyone writing a custom integration first.
There are eleven read tools and one write tool. The write tool creates a checkout link. Destructive writes are deliberately not exposed to agents.
Every tool call is scoped to the community that owns the API key, and enforces the same scope as its REST equivalent. A key that lacks the required scope gets a named scope-denial error instead of data.
One endpoint, one bearer key
The server lives at https://api.arcalotl.com/mcp and speaks the streamable HTTP transport. Authentication is the same bearer API key the REST API uses, sent as an Authorization header. Keys are created and revoked in the dashboard under Developers, then API Keys.
Thirteen read tools cover the community's data
An agent can call list_subscriptions, get_subscription, get_switch_options, list_plans, list_members, get_member_entitlements, check_entitlement, list_purchases, get_analytics_summary, list_discounts, list_events, list_webhook_endpoints and list_webhook_deliveries. Tool results are the same public JSON objects the REST endpoints return.
Two write tools: a checkout link and a plan switch
create_checkout_link takes a tier_id and either a platform and platform_uid or your own namespace and external_user_id, plus a plan_id when the tier has more than one active plan. It returns the URL of a real checkout page for that buyer. switch_subscription moves a subscription to a plan from get_switch_options. Both require a write scope and neither is destructive.
There is no destructive tool
The server exposes no cancel_subscription tool. Destructive writes driven by an agent are out of scope by design. Cancelling still works over REST with POST /v1/subscriptions/{id}/cancel, where a human or a service holds the key.
Results are scoped to one community
Every result is limited to the community that owns the API key, so an agent cannot read another community's subscribers or revenue. An id belonging to another community is reported as not found rather than as forbidden.
A missing scope returns a named error
When a key lacks the scope a tool needs, the tool call returns a scope-denial error naming the scope, for example missing_scope: members:read. That is the same outcome as a 403 missing_scope over REST, so an agent can report exactly which permission to add.
Read tools are annotated read-only
Each read tool carries the readOnlyHint annotation, so MCP clients that honor annotations can call it without asking the user to confirm. create_checkout_link and switch_subscription are annotated as non-destructive.
Adding the server takes one command
In Claude Code, run claude mcp add --transport http arcalotl https://api.arcalotl.com/mcp with an Authorization header carrying your key. Clients that use an mcpServers configuration object accept the same server as a url plus a headers map.
MCP costs nothing extra
The MCP server is part of the product. Arcalotl charges $0/month plus 2% of each successful payment, on the creator's own Stripe account through Stripe Connect direct charges. There is no separate API or agent plan.
Tools the MCP server exposes
| Tool | Input | Scope |
|---|---|---|
| list_subscriptions | status, plan_id, member_id, cursor, limit (all optional) | subscriptions:read |
| get_subscription | subscription_id | subscriptions:read |
| get_switch_options | subscription_id | subscriptions:read |
| list_plans | None | plans:read |
| list_members | cursor, limit (optional) | members:read |
| get_member_entitlements | member_id | members:read |
| check_entitlement | platform and platform_uid, or namespace and external_user_id; tier_id (optional) | members:read |
| list_purchases | cursor, limit (optional) | purchases:read |
| get_analytics_summary | None | analytics:read |
| list_events | types, after_id, limit (all optional) | events:read |
| list_webhook_endpoints | None | webhooks:read |
| list_webhook_deliveries | endpoint_id, cursor (optional) | webhooks:read |
| create_checkout_link | tier_id, plan_id (optional), platform and platform_uid, or namespace, external_user_id and return_url | checkout:write |
| switch_subscription | subscription_id, plan_id | subscriptions:write |
One service behind two protocols
The MCP tools call the same internal application service the REST handlers call, in-process, rather than calling the public REST API over HTTP. Every resource, filter and scope check behaves identically whether you reach Arcalotl with curl or through an agent.
That also means a fix or a new field lands in both surfaces at once. The MCP tool list tracks the REST API instead of lagging behind it.
Because the data is the same, an agent workflow can mix the two. An assistant can read plans and members over MCP, then hand a checkout link to a person, while a backend service uses the REST API and webhooks for the parts that must be durable.
Questions
Read next
Point your agent at your own community data
Create an API key in the dashboard, give it the scopes you want the agent to have, and connect it to https://api.arcalotl.com/mcp.
Create an account