MCP

The Arcalotl MCP server

Arcalotl exposes its subscription, member, entitlement and analytics data to AI agents over the Model Context Protocol, using the same API keys and the same scopes as the REST API.

Arcalotl runs a Model Context Protocol server at https://api.arcalotl.com/mcp. An MCP client such as Claude Code, Claude Desktop or Cursor connects to it directly, so an assistant can answer a question like "which subscribers are past due" or create a checkout link for a tier without anyone writing a custom integration first.

There are eleven read tools and one write tool. The write tool creates a checkout link. Destructive writes are deliberately not exposed to agents.

Every tool call is scoped to the community that owns the API key, and enforces the same scope as its REST equivalent. A key that lacks the required scope gets a named scope-denial error instead of data.

  • One endpoint, one bearer key

    The server lives at https://api.arcalotl.com/mcp and speaks the streamable HTTP transport. Authentication is the same bearer API key the REST API uses, sent as an Authorization header. Keys are created and revoked in the dashboard under Developers, then API Keys.

  • Thirteen read tools cover the community's data

    An agent can call list_subscriptions, get_subscription, get_switch_options, list_plans, list_members, get_member_entitlements, check_entitlement, list_purchases, get_analytics_summary, list_discounts, list_events, list_webhook_endpoints and list_webhook_deliveries. Tool results are the same public JSON objects the REST endpoints return.

  • Two write tools: a checkout link and a plan switch

    create_checkout_link takes a tier_id and either a platform and platform_uid or your own namespace and external_user_id, plus a plan_id when the tier has more than one active plan. It returns the URL of a real checkout page for that buyer. switch_subscription moves a subscription to a plan from get_switch_options. Both require a write scope and neither is destructive.

  • There is no destructive tool

    The server exposes no cancel_subscription tool. Destructive writes driven by an agent are out of scope by design. Cancelling still works over REST with POST /v1/subscriptions/{id}/cancel, where a human or a service holds the key.

  • Results are scoped to one community

    Every result is limited to the community that owns the API key, so an agent cannot read another community's subscribers or revenue. An id belonging to another community is reported as not found rather than as forbidden.

  • A missing scope returns a named error

    When a key lacks the scope a tool needs, the tool call returns a scope-denial error naming the scope, for example missing_scope: members:read. That is the same outcome as a 403 missing_scope over REST, so an agent can report exactly which permission to add.

  • Read tools are annotated read-only

    Each read tool carries the readOnlyHint annotation, so MCP clients that honor annotations can call it without asking the user to confirm. create_checkout_link and switch_subscription are annotated as non-destructive.

  • Adding the server takes one command

    In Claude Code, run claude mcp add --transport http arcalotl https://api.arcalotl.com/mcp with an Authorization header carrying your key. Clients that use an mcpServers configuration object accept the same server as a url plus a headers map.

  • MCP costs nothing extra

    The MCP server is part of the product. Arcalotl charges $0/month plus 2% of each successful payment, on the creator's own Stripe account through Stripe Connect direct charges. There is no separate API or agent plan.

Tools the MCP server exposes

ToolInputScope
list_subscriptionsstatus, plan_id, member_id, cursor, limit (all optional)subscriptions:read
get_subscriptionsubscription_idsubscriptions:read
get_switch_optionssubscription_idsubscriptions:read
list_plansNoneplans:read
list_memberscursor, limit (optional)members:read
get_member_entitlementsmember_idmembers:read
check_entitlementplatform and platform_uid, or namespace and external_user_id; tier_id (optional)members:read
list_purchasescursor, limit (optional)purchases:read
get_analytics_summaryNoneanalytics:read
list_eventstypes, after_id, limit (all optional)events:read
list_webhook_endpointsNonewebhooks:read
list_webhook_deliveriesendpoint_id, cursor (optional)webhooks:read
create_checkout_linktier_id, plan_id (optional), platform and platform_uid, or namespace, external_user_id and return_urlcheckout:write
switch_subscriptionsubscription_id, plan_idsubscriptions:write

One service behind two protocols

The MCP tools call the same internal application service the REST handlers call, in-process, rather than calling the public REST API over HTTP. Every resource, filter and scope check behaves identically whether you reach Arcalotl with curl or through an agent.

That also means a fix or a new field lands in both surfaces at once. The MCP tool list tracks the REST API instead of lagging behind it.

Because the data is the same, an agent workflow can mix the two. An assistant can read plans and members over MCP, then hand a checkout link to a person, while a backend service uses the REST API and webhooks for the parts that must be durable.

Questions

Read next

Point your agent at your own community data

Create an API key in the dashboard, give it the scopes you want the agent to have, and connect it to https://api.arcalotl.com/mcp.

Create an account