HomeFeaturesWhatsApp MCP Server

Model Context Protocol

WhatsApp MCP Server

Point Claude, ChatGPT or your own agent at a WhatsApp number you already own. It reads conversations, answers customers, files work under a client and stops a campaign — under the same sending rules as everybody else on your team.

  • 22 tools
  • 1 endpoint
  • 0 extra fees per message
Claude Code, on a number the business already owns.

One address, one key

No SDK to install and nothing to host. Birsend’s MCP server is a URL and a bearer token.

Endpointhttps://api.birsend.com/mcp
AuthAuthorization: Bearer <your MCP key>

The key decides which of the twenty-two tools the server even advertises. An agent holding a read-only key is not told that sending exists.

Step 1

Mint a key

On the MCP Server screen in Birsend, name the key after the agent that will hold it and pick the role it should have. The key is shown once.

Step 2

Point your agent at it

Add the endpoint and the key to your MCP client — Claude Desktop, an SDK, or your own runner. The server advertises only the tools that key may use.

Step 3

Ask it to do the work

“Reply to everybody who asked about delivery.” It reads the threads, drafts and sends, under the same sending hours and word filter as a person.

The twenty-two tools

Each one needs a permission, and they are the same permissions your Permissions screen manages. A key minted against the Analyst role sees the read tools and no way to send anything.

The inbox

inbox.view · inbox.manage

  • list_conversationsOpen threads on a number
  • read_conversationThe messages in one thread
  • send_messageReply with text
  • send_imageReply with a picture
  • send_audioReply with a voice note
  • get_mediaFetch a file a customer sent

Contacts

contacts.view · contacts.manage

  • search_contactsFind somebody by name, company, email or number
  • get_contactOne person, with their history
  • create_contactAdd somebody
  • import_contactsAdd a list at once
  • add_tagTag somebody for later

Campaigns

campaigns.view · campaigns.manage

  • list_campaignsWhat is scheduled, sending or finished
  • pause_campaignStop a send that is going out
  • assign_campaign_clientFile a campaign under a client
  • attach_campaign_imageAdd a picture before it goes out

Clients and templates

clients.* · templates.view

  • list_clientsThe businesses the work is for
  • create_clientAdd one
  • list_templatesSaved messages available to send from

Files and links

files.manage · links.manage

  • upload_imagePut a picture in the library
  • upload_audioPut a voice note in the library
  • create_linkMake a tracked short link

Reporting

reports.view

  • get_reportThe numbers over a period, the same ones the panel shows

An agent cannot outrank you

Handing a model the keys to a phone number is a real decision. These are the four things that make it a reasonable one.

A key is narrower than its maker

What a key may do is the overlap between the role you gave it and your own permissions. Nobody can mint a key more capable than themselves, and a key stops growing when the person behind it is demoted.

Your sending rules still apply

Sending hours, daily caps, the opt-in requirement, blocked contacts and your word filter are all checked per message, whoever asked for it. A key is a door, not an exemption.

It may narrow, never widen

An agent can pause a campaign that is going out. It cannot resume one, and it cannot schedule or send one — putting thousands of messages back in motion off a single sentence is not a thing to automate.

Everything it did is on the record

Messages an agent sends appear in the shared inbox like any other, and the workspace activity log names the key that sent them. Nothing an agent does is invisible.

Frequently asked questions

What is an MCP server?

MCP — the Model Context Protocol — is an open standard for giving an AI model tools it can call. An MCP server publishes those tools; an MCP client, such as Claude Desktop or your own agent, connects and uses them. Birsend’s MCP server publishes twenty-two tools for a real WhatsApp number.

Which AI models can connect to Birsend?

Any client that speaks MCP. Claude Desktop and Claude Code connect natively, and the major agent SDKs support it. Birsend publishes the tools; the model is your choice, and Birsend never sees your model provider or your bill for it.

Can an agent message my customers without me watching?

Yes, if you give it a key with sending permission — that is the point of it. What it cannot do is exceed your rules: every message it sends passes the same sending window, daily cap, opt-in requirement and word filter as a message somebody types by hand.

Can an agent do more than the person who created its key?

No. A key carries a role, and what it may actually do is the overlap between that role and its maker’s own permissions. So nobody can mint a key more capable than themselves, and a key stops growing the moment the person behind it is demoted.

Can an agent start a campaign?

It can pause one that is going out. It cannot resume one, and it cannot schedule or send one — sending to thousands of people needs a person who has seen the audience count. An agent may narrow what is happening, never widen it.

Is this the WhatsApp Business API?

No, and that is the reason to use it. Birsend drives a number you already own, so there is no application, no template approval and no per-message fee to a provider. Your agent works the same line your customers already message.

What happens if I revoke a key?

Everything using it stops immediately. Only a hash of the key is stored, so a lost key cannot be recovered — you revoke it and mint another.

How is this different from the REST API?

Different reader, different door. The REST API is for software you wrote, which does exactly what you programmed. MCP is for an agent, which does something reasonable that you did not specify — so the two use separate key types, and one leak stays one door.

Give your agent a phone number.

Fourteen days free, no credit card. Connect a number, mint a key, and watch what your agent does with a real inbox.

Cookies

The site runs what it needs to work, including the Crisp chat bubble. Google Analytics is the one thing we will not load unless you agree to it.