Mint a key
On the MCP Server screen in Birsend, name the key after the agent that will hold it and pick the role it should have. The key is shown once.
HomeFeaturesWhatsApp MCP Server
Model Context Protocol
Point Claude, ChatGPT or your own agent at a WhatsApp number you already own. It reads conversations, answers customers, files work under a client and stops a campaign — under the same sending rules as everybody else on your team.
No SDK to install and nothing to host. Birsend’s MCP server is a URL and a bearer token.
https://api.birsend.com/mcpAuthorization: Bearer <your MCP key>The key decides which of the twenty-two tools the server even advertises. An agent holding a read-only key is not told that sending exists.
On the MCP Server screen in Birsend, name the key after the agent that will hold it and pick the role it should have. The key is shown once.
Add the endpoint and the key to your MCP client — Claude Desktop, an SDK, or your own runner. The server advertises only the tools that key may use.
“Reply to everybody who asked about delivery.” It reads the threads, drafts and sends, under the same sending hours and word filter as a person.
Each one needs a permission, and they are the same permissions your Permissions screen manages. A key minted against the Analyst role sees the read tools and no way to send anything.
inbox.view · inbox.manage
list_conversationsOpen threads on a numberread_conversationThe messages in one threadsend_messageReply with textsend_imageReply with a picturesend_audioReply with a voice noteget_mediaFetch a file a customer sentcontacts.view · contacts.manage
search_contactsFind somebody by name, company, email or numberget_contactOne person, with their historycreate_contactAdd somebodyimport_contactsAdd a list at onceadd_tagTag somebody for latercampaigns.view · campaigns.manage
list_campaignsWhat is scheduled, sending or finishedpause_campaignStop a send that is going outassign_campaign_clientFile a campaign under a clientattach_campaign_imageAdd a picture before it goes outclients.* · templates.view
list_clientsThe businesses the work is forcreate_clientAdd onelist_templatesSaved messages available to send fromfiles.manage · links.manage
upload_imagePut a picture in the libraryupload_audioPut a voice note in the librarycreate_linkMake a tracked short linkreports.view
get_reportThe numbers over a period, the same ones the panel showsHanding a model the keys to a phone number is a real decision. These are the four things that make it a reasonable one.
What a key may do is the overlap between the role you gave it and your own permissions. Nobody can mint a key more capable than themselves, and a key stops growing when the person behind it is demoted.
Sending hours, daily caps, the opt-in requirement, blocked contacts and your word filter are all checked per message, whoever asked for it. A key is a door, not an exemption.
An agent can pause a campaign that is going out. It cannot resume one, and it cannot schedule or send one — putting thousands of messages back in motion off a single sentence is not a thing to automate.
Messages an agent sends appear in the shared inbox like any other, and the workspace activity log names the key that sent them. Nothing an agent does is invisible.
MCP — the Model Context Protocol — is an open standard for giving an AI model tools it can call. An MCP server publishes those tools; an MCP client, such as Claude Desktop or your own agent, connects and uses them. Birsend’s MCP server publishes twenty-two tools for a real WhatsApp number.
Any client that speaks MCP. Claude Desktop and Claude Code connect natively, and the major agent SDKs support it. Birsend publishes the tools; the model is your choice, and Birsend never sees your model provider or your bill for it.
Yes, if you give it a key with sending permission — that is the point of it. What it cannot do is exceed your rules: every message it sends passes the same sending window, daily cap, opt-in requirement and word filter as a message somebody types by hand.
No. A key carries a role, and what it may actually do is the overlap between that role and its maker’s own permissions. So nobody can mint a key more capable than themselves, and a key stops growing the moment the person behind it is demoted.
It can pause one that is going out. It cannot resume one, and it cannot schedule or send one — sending to thousands of people needs a person who has seen the audience count. An agent may narrow what is happening, never widen it.
No, and that is the reason to use it. Birsend drives a number you already own, so there is no application, no template approval and no per-message fee to a provider. Your agent works the same line your customers already message.
Everything using it stops immediately. Only a hash of the key is stored, so a lost key cannot be recovered — you revoke it and mint another.
Different reader, different door. The REST API is for software you wrote, which does exactly what you programmed. MCP is for an agent, which does something reasonable that you did not specify — so the two use separate key types, and one leak stays one door.
Fourteen days free, no credit card. Connect a number, mint a key, and watch what your agent does with a real inbox.