
Your SAGARIS CRM and Brain, in your AI assistant
Connect an MCP client to /api/v1/mcp with a workspace API key. Read CRM data, draft Social work, or coordinate gated LinkedIn actions through an explicitly enabled external agent.
The endpoint is running today. This page lists the tools it offers, shows how your API key decides what each one can reach, and gets you connected in a few minutes. Ask your assistant about a deal and the answer comes from the record. Give it your Social checklist and it drafts the work for you to approve. LinkedIn execution has a separate permission and activation gate for your connected external agent.
Your assistant reads the real record
Model Context Protocol is an open standard. It hands an AI client a set of tools it can call. SAGARIS runs the server half at /api/v1/mcp, over Streamable HTTP in stateless JSON mode. That means one JSON-RPC message per POST, one JSON response back, and no session to open or close. Connecting a client is one short piece of configuration: the endpoint URL and your API key.
So the assistant your team already works in can ask your workspace a question and get the answer from the record itself. No more pasting a stale export into a chat window and hoping it is current. Your pipeline stays where it lives, and your people read it where they already work.
Your revenue data becomes something the assistant can call, not something a person has to go and look up.
Safe to connect on day one
Choose the permissions your assistant needs. The tool list is derived from the public API and the Brain's read views, and filtered by your key's scopes. CRM, sequences and Brain tools read the record; they cannot edit contacts, dial or enroll people. LinkedIn execution is a separate, explicit permission, not something a read-only key inherits.
Social checklist writes hand you work. A post the assistant drafts waits in your Social review queue until a person approves it. A document, such as a voice guide or a profile rewrite, arrives as an approval card: approve it, ask for a change, or deny it. On a few research items, such as a knowledge panel check or the weekly read, it can record what it found, marked as the assistant's and never over what your team recorded. Each of those needs its own scope on the key.
With linkedin.execute, a connected external agent can claim and start a LinkedIn action only when execution is explicitly activated, a person approved the action or set its account to run automatically, and sender, campaign, safety and quota checks pass. The external agent acts in its LinkedIn session and reports the outcome; SAGARIS does not host that browser session. SAGARIS logs a reported send on the contact and moves its LinkedIn status forward. The API key alone does not establish a LinkedIn login or turn on execution. With MCP Events, a client that takes webhooks, such as a ChatGPT Dot, subscribes to linkedin.work.available, linkedin.schedule.changed and linkedin.reconnect.requested and is told when to act, in ids, counts and the account's label in SAGARIS, never a contact's name, a profile URL or message copy.
Read tools identify themselves as read only. Checklist writes and LinkedIn execution are marked as writes, and execution carries a destructive-action hint because an external message cannot be taken back.
Read access, draft preparation and LinkedIn execution are separate permissions. Grant only the work your assistant should perform.
You decide what each key can see
It uses the workspace API key you already create in settings, sent as a bearer token. Three things follow, and all three are enforced in code rather than written in a policy:
- The key names the workspace. A client never gets to pick one, so it only ever reaches yours.
- Scopes filter the tool list before the client sees it. A tool your key does not cover is never offered at all. That is the version an assistant handles cleanly.
- Every message needs a valid key, the opening handshake included. There is no step where the server talks to a stranger.
Requests are rate limited per key, and a browser client has its origin checked before anything else happens. Revoke the key in settings and the access ends. That is the part you want on the day somebody leaves the team.
You choose what leaves the workspace
The Brain holds more kinds of record than this endpoint hands out, and every one of those calls was made on purpose. Internal delivery commitments, the record of what your own team promised a customer, stay inside the workspace. So does machine-derived competitor intelligence, which only reads properly next to its source and its date. Your most sensitive context stays where you can see who touched it.
The list of subject types this endpoint can read is compiled from the same table the runtime check uses. So this page and the product cannot drift apart. Add a new kind of subject and the build stops until someone decides, on purpose, whether an outside client should see it.
Included in your seat
Nothing beyond the seat. SAGARIS is $499 per seat per month on the founding price, every module and every agent included, with no seat minimum. The endpoint ships with the product rather than in a tier above it, and tool calls are not metered.
The tool surface
What your assistant can ask for.
These are the tools the endpoint offers today, with the scope each one needs. You control the scopes, so a key only ever sees the tools you granted it. Social checklist writes and LinkedIn execution each need their own scope.
sagaris_list_contactsrequires contacts.readYour workspace contacts, through the same route and the same pagination the public API serves. The assistant sees exactly what a key holder sees, so the answer matches the screen.
sagaris_get_contactrequires contacts.readOne contact by id, through the same route and the same workspace scope the list uses. Ask about a specific person and the assistant reads their record rather than paging the whole list to find them.
sagaris_list_sequencesrequires sequences.readYour outbound sequences, so you can ask what a contact is enrolled in right now and get a straight answer.
sagaris_get_linkedin_actionsrequires linkedin.readReads the LinkedIn actions assigned to a connected agent, including the exact recipient, copy and campaign context. The key stays in its workspace and reads only actions in the campaigns its agent was granted or, when none were named, in every campaign on its LinkedIn account.
sagaris_manage_linkedin_executionrequires linkedin.executeCoordinates an external agent's heartbeat, claim, execution start and result for a LinkedIn action. Sending happens in the agent's LinkedIn session, not on this server. Claiming and starting require explicitly activated execution, a connected sender, a person's approval or an account set to run automatically, and passing safety and quota checks.
sagaris_brain_claims_currentrequires contacts.readWhat your workspace believes right now about one contact, account or opportunity. Best-rank claims only, with facts known to be wrong left out and counted so you can see the number. Reach for this one when you need what is true today.
sagaris_brain_contact_dossierrequires contacts.readEvery claim on record about one subject, each with its confidence, when it was seen, and a pointer to the evidence behind it. Ask as of a past date and you get the answer as it stood that day.
sagaris_brain_nba_featuresrequires contacts.readOne flat record of the signals a next-best-action decision runs on: renewal window, buying-intent stage, budget approval, competitor activity, open objections, and which facts are contested. It answers as of a past date too.
sagaris_list_social_checklist_itemsrequires social_checklist.readYour Social checklist, every one-time and ongoing item, with what your workspace has recorded for each: status, evidence, how often it repeats, when it is next due, who acts on it, and any card waiting for you. Each item also says what the assistant may do with it.
sagaris_list_due_social_checklist_itemsrequires social_checklist.readWhat is due on your Social checklist right now, in the order SAGARIS's own runner takes it: a change you asked for first, then unfinished setup work, then the ongoing work whose window is open. Each item says why it is due.
sagaris_get_social_checklist_item_contextrequires social_checklist.readOne checklist item in full, with what the work is done from: your saved brand voice, the facts in your profile, the state of each social connection and your recent posts. The assistant writes from your record, not from a guess.
sagaris_submit_social_checklist_item_outputrequires social_checklist.submitHands the assistant's finished work for one item to a person. A post lands in your Social review queue as a draft; a document, such as a voice guide, becomes an approval card to approve, change or deny. Nothing is published, sent or scheduled by this tool.
sagaris_record_social_checklist_item_evidencerequires social_checklist.recordRecords what the assistant found on a research item, such as a knowledge panel check or the weekly read, where the finding is the work. The mark is shown as the assistant's, never replaces one your team recorded, and changes nothing live.
CRM and Brain tools read; Social checklist tools write drafts and research findings, never publish or approve. LinkedIn execution is separate: an explicitly enabled external agent can act only where a person approved the action or set its account to run automatically, subject to safety and quota checks. It acts only in the campaigns it was granted or, when none were named, in every campaign on its LinkedIn account; every agent connected through OAuth has none named. A read-only key cannot execute actions.
FAQ
The questions this endpoint gets asked.
Short answers, including the ones about what it will not do. Every one of them describes behaviour that is running today.
What is the SAGARIS MCP endpoint?
A Model Context Protocol server at /api/v1/mcp that lets an AI client read your SAGARIS workspace, work through your Social checklist, coordinate gated LinkedIn actions with a connected external agent, and subscribe that agent to three LinkedIn events delivered as signed webhooks. Each read and write capability needs its own scope. It speaks Streamable HTTP in stateless JSON mode and authenticates with your workspace API key as a bearer token.
Can an assistant change anything in my workspace through it?
With Social checklist scopes, it can submit drafts for approval and record research evidence, but cannot publish or approve them. With linkedin.execute, a connected external agent can claim and start a LinkedIn action when execution is explicitly activated, a person approved the action or set its account to run automatically, and safety and quota checks pass, then report what happened. SAGARIS logs a reported send on the contact, moves its LinkedIn status forward and, for a sequence step, advances the sequence. The agent sends from its own LinkedIn session; SAGARIS does not host that session. Read-only keys cannot execute actions, edit CRM contacts, dial or enroll people.
What can the SAGARIS MCP server read?
Your contacts and your sequences, and three Brain views over a contact, account or opportunity: what the workspace currently believes, the full dossier of asserted claims with their evidence, and the flat feature record behind a next-best-action. The Brain views also answer as of a past date. Checklist scopes add your Social checklist and the context an item is done from. With linkedin.read, a connected agent reads the LinkedIn actions assigned to it: in the campaigns it was granted or, when none were named, in every campaign on its LinkedIn account.
How does it know which workspace to read?
From the key. The workspace is resolved from the API key itself and a client cannot pass one, so it cannot reach a workspace the key does not belong to. Scopes then filter the tool list before the client ever sees it, and every message needs a valid key including the opening handshake.
Which MCP clients can connect to SAGARIS?
Any MCP client that speaks the Streamable HTTP transport and lets you set a bearer token: paste your workspace API key into that field, with nothing to install. A client that connects through OAuth sign-in instead gets only linkedin.read and linkedin.execute, so it is offered the LinkedIn tools and nothing else. A person allowed to approve outbound sends signs in to allow it, and the key the client receives is listed under Settings > API keys. Tell us which client your team uses and we will check it for you.
What does it cost?
It is included in the seat. SAGARIS is $499 per seat per month on the founding price, with every module and every agent in it and no seat minimum. There is no per-call charge and no higher tier gating the endpoint, so your team can wire it into whatever assistant they already use.
How do I turn off MCP access to my SAGARIS workspace?
Revoke the API key in workspace settings and access ends immediately, because the key is the only credential the endpoint accepts. A client connected through OAuth holds a key too, listed with the others, and no refresh token is issued, so there is no second path in and no session that outlives the key. Revoking it is the whole of switching the integration off.
It is already included in your seat.
Once your workspace is set up, create an API key in settings and point your client at it. Your assistant reads live records in minutes. The platform page shows everything it can reach.
In this topic