Skip to main content
Peeve speaks Model Context Protocol in both directions, and they behave very differently. Know which one you mean.
If you are asking “can MCP write?”, the answer depends on which. Yes for the connector — that is Peeve calling your tools. No for the server on this page — that is an assistant asking Peeve what your product can do.
Two things determine whether the server is useful to you, and both are on this page.
Treat an MCP token as full account reach, not “an MCP key”.The pv_ut_… you point an assistant at MCP with is the same credential that reaches the whole /v1 API at that person’s live role — including, for an owner or admin, writing guardrails, re-statusing leads and operating the kill switch.So scope by who you issue it to, not by what you intend to use it for. There is no MCP-only token. Hand one to a teammate whose role is as narrow as the job allows, and revoke it in Settings → API keys when the integration ends.
What tools/call returns today. On the current release this endpoint returns a grounded guide — where the capability lives in your product and how to complete it — and does not itself perform the action.Writes through MCP happen in the other direction, via the Custom MCP connector, where they route through the kill switch, the writes switch, the permission mode, a per-tool allow-list and a mandatory human confirmation. Build against the role model above rather than assuming nothing anywhere can change.
Both endpoints require a credential. The workspace endpoint takes a user token (pv_ut_…) — the same credential as the /v1 API — and the token’s workspace must match the id in the URL. The per-contact endpoint takes either a pv_grant_… token or a teammate’s API token.There is no anonymous access to either.
The agent channel requires Growth or above.Both MCP endpoints check the agent_write entitlement. On Starter, or during a trial, or with a lapsed subscription, they return “agent channel not available for this workspace”. The same gate applies to the agent channel as a whole.It also requires the agent channel to be enabled for the workspace, and the kill switch to be off.

What it exposes

Tools are projected from your workspace’s verified capabilities — the ones Peeve has confirmed exist in your product by mapping it. A capability appears as a tool only when all of the following hold:
  • it belongs to the current production version of your product map;
  • its status is verified — not draft, stale or broken;
  • its agent access is set to allowed — not human-only or blocked;
  • it has not been disabled by a builder.
Everything else is invisible to an assistant. Nothing is hand-written; the projection is generated from the same graph that grounds the in-product agent, so the two can never disagree about what your product does.

The two endpoints

Workspace-level

https://mcp.peeve.ai/{workspace}A teammate’s API token, acting for the workspace. Any role (read). The token’s workspace must match the URL.

Per-user

https://mcp.peeve.ai/{workspace}/u/{contact}Scoped to one contact. Takes a pv_grant_… token, or a teammate’s user token with reply (owner, admin or responder).

Protocol

JSON-RPC 2.0 over HTTP. Protocol version 2024-11-05, negotiated in the initialize handshake. Anything else returns -32601 Method not found. Notifications — a message with no id, or any method in the notifications/* namespace — get no reply. A batch consisting only of notifications is answered 202 with no body. Batches are supported: send an array, get an array back.
There is no version segment in the URL, on purpose. MCP negotiates its protocol version in the handshake and tool changes are additive, so the URL you paste into an assistant stays valid indefinitely.

What a tools/call actually returns

The guide names the capability’s purpose, where it lives (a deep link, or the route path), and its permission class. For anything that changes data it says so explicitly. For a read or navigation capability it says the assistant is safe to walk the user there directly. Permission classes: read, write, write — needs the user's confirmation, and destructive — needs the user's confirmation.

Auditing

Every tools/call and every initialize lands in your activity log, recorded after the response so it never slows a call. The record carries the capability key, the method and the outcome — never the arguments. On the per-user endpoint it is attributed to the granted contact, so you can see which person’s assistant did what.

Next

Workspace endpoint

Full request and response shapes.

Per-user grants

Issuing and revoking pv_grant_… tokens.

Connect a client

Claude, Cursor and generic MCP client configuration.

Custom MCP connector

The other direction — Peeve calling your MCP server, where writes do happen.