Source
Analytics, data export & integrations — found from sitemap — OptiMonk
Checked for OptiMonk on 1 Oct 2026
- Page
- https://support.optimonk.com/en/articles/api-keys-and-the-mcp-endpoint
- Checked
- 1 Oct 2026, 10:38 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:41da66e9f26129405c83d15258962bd909817eb382348c8dce50b01b9e3cdde2
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Mcp server Report an error
“The builder exposes an MCP (Model Context Protocol) server, so an AI agent — Claude, Cursor, ChatGPT/Codex, or your own client — can drive it: start a build from a reference image, iterate on the popup, and turn the result into a campaign.”
-
API key creation Report an error
“Go to Settings → API keys. The panel opens with: Connect the OptiMonk MCP server to AI agents like Claude or Cursor.”
-
API key security Report an error
“Secrets are stored as a SHA-256 hash, never in plaintext, so there is no way to recover one — mint a new key instead.”
-
API key revocation Report an error
“Revoke kills a key immediately: "Any agent using this key loses access immediately. This can't be undone."”
-
API key format Report an error
“Keys look like omk_live_<43 base64url chars>.”
-
Oauth connected apps Report an error
“The same page also lists Connected apps — the OAuth equivalent, for clients that can run a browser consent flow: "Apps you approved with Connect. They act on this account until you disconnect them."”
-
Mcp endpoint Report an error
“POST https://<your-host>/mcp Authorization: Bearer omk_live_…”
-
Mcp transport Report an error
“Transport is streamable HTTP and stateless — the server creates a fresh session per request, so GET /mcp and DELETE /mcp both answer 405 method not allowed (stateless).”
-
Mcp server identity Report an error
“The server identifies itself as optimonk-popup-builder version 1.0.0.”
-
Mcp error handling Report an error
“A missing, malformed, revoked or expired credential gets 401 with a WWW-Authenticate header.”
-
Mcp scopes Report an error
“Both credential kinds carry the same four scopes: build:read, build:write, campaign:read, campaign:write. A key created from the settings UI gets the full set.”
-
Whoami tool Report an error
“Call whoami first — it returns the account id, the credential label, the scopes and canPublish”
-
Mcp tool count Report an error
“26 tools are exposed. Grouped by job:”
-
Mcp tool groups Report an error
“Identity:whoami.”
-
Build tools Report an error
“Build:build_popup, get_build_status, watch_build, upload_reference_image, get_popup_html, get_popup_preview.”
-
Campaign tools Report an error
“Campaign:list_campaigns, get_campaign, create_campaign, set_campaign_name, get_campaign_settings, set_campaign_settings, publish_campaign.”
-
Build popup async Report an error
“build_popup takes a publicly fetchable PNG/JPG/WEBP plus the target store hostname and returns a runId. Builds are asynchronous”
-
Create campaign requirements Report an error
“create_campaign makes a DRAFT campaign and needs a designer-session-backed build: start_design_thread creates one, a standalone build_popup run does not.”
-
Publish campaign Report an error
“publish_campaign publishes to OptiMonk and activates the campaign.”
-
Mcp not analytics Report an error
“It is not the analytics or subscriber API. There is no tool for reports, leads or submits — the tool list above is the whole surface.”
-
Mcp not integrations Report an error
“It cannot configure ESP/CRM integrations. No tool connects Klaviyo, Mailchimp or a webhook; that is UI-only, in the campaign hub.”
-
Mcp not account admin Report an error
“It cannot manage the account. No user, domain, billing or API-key administration”
-
Mcp tool refusals Report an error
“MCP tool refusals — including scope errors and exhausted budgets — come back as isError: true with prose in content, inside a JSON-RPC HTTP 200 response.”
-
Idempotency Report an error
“Pass idempotencyKey to build_popup (the REST equivalent is an Idempotency-Key header, honoured for 24 hours per account)”
-
Rest API Report an error
“The same credentials work against a REST surface described by an OpenAPI 3.1 document. Both GET /.well-known/openapi.json and GET /llms.txt are readable without a credential.”
-
Rest rate limit headers Report an error
“rate-limited responses carry X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset, and a budget refusal is a 429 with Retry-After.”
-
Rest error format Report an error
“REST errors are typed (type + code + request_id; branch on those, not on message)”
1 fact read from this page is not shown because it could not be confirmed on the page as captured.
Scores citing this record
- The CRO Consultant Analytics, data export & integrations
- The Data Protection Officer Analytics, data export & integrations
- The E-Commerce Manager Analytics, data export & integrations
- The Growth Lead Analytics, data export & integrations
- The Product Engineer Analytics, data export & integrations
- The Skeptic Analytics, data export & integrations