Back to Browse

Sendseven MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Unified messaging MCP server: WhatsApp, Instagram, Telegram, SMS, Messenger & email support inbox

About

Unified messaging MCP server: WhatsApp, Instagram, Telegram, SMS, Messenger & email support inbox

Remote endpoints: streamable-http: https://mcp.sendseven.com/mcp

Security Report

4.2
Use Caution4.2High Risk

The SendSeven MCP server is a well-structured OAuth 2.0-authenticated messaging platform integration with proper scope-based access control and minimal security concerns. Code quality is generally good with appropriate error handling and input validation. Two informational findings regarding token refresh patterns and broad exception handling are noted but do not warrant concern given the server's purpose and category baseline. Supply chain analysis found 10 known vulnerabilities in dependencies (2 critical, 3 high severity).

4 files analyzed · 13 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

SendSeven MCP Server

License: MIT MCP Node.js Cloudflare Workers

The official Model Context Protocol (MCP) server for SendSeven - the unified messaging API platform for WhatsApp, Instagram DMs, Telegram, SMS, Messenger, Live Chat, and Email.

Connect your SendSeven account to Claude, ChatGPT, Gemini, Cursor, or any MCP-compatible AI assistant to manage your unified inbox, send omnichannel messages (WhatsApp, Instagram private replies, Telegram, SMS, Messenger, email), run marketing campaigns, staff a team chat bot, and search your knowledge base using natural language — all through your existing customer support and messaging API platform.

Quick Start

Option 1: Remote Server (Recommended)

No installation needed. Add to your AI client:

Claude Desktop (claude_desktop_config.json):

{
  "mcpServers": {
    "sendseven": {
      "url": "https://mcp.sendseven.com/mcp",
      "auth": {
        "type": "oauth2",
        "authorizationUrl": "https://mcp.sendseven.com/authorize",
        "scopes": ["conversations:read", "messages:create", "contacts:read"]
      }
    }
  }
}

Claude Code (.claude/settings.json):

{
  "mcpServers": {
    "sendseven": {
      "url": "https://mcp.sendseven.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_TOKEN"
      }
    }
  }
}

ChatGPT (Settings > Connectors > Add custom connector):

MCP Server URL: https://mcp.sendseven.com/mcp
Authentication: OAuth

ChatGPT walks you through the OAuth consent + capability picker automatically — no config file needed.

Option 2: API Token (Developer Setup)

For developers and CI/CD pipelines, use a static API token:

  1. Generate an API token in SendSeven: Settings > API Tokens
  2. Configure your MCP client with the token as a Bearer header

Option 3: Self-Hosted

git clone https://github.com/SendSeven-GmbH/sendseven-mcp-server.git
cd sendseven-mcp-server
npm install
npm run dev  # Runs on localhost:8787

What Can It Do?

Support Operations

  • "Show me open conversations" - List and filter conversations
  • "What's the conversation with John about?" - View conversation details
  • "Close ticket #123 with notes: refund issued" - Close conversations
  • "Assign this to Sarah" - Route to team members

Messaging

  • "Send a WhatsApp to +49 170 1234567: Your order is ready" - Multi-channel messaging
  • "Email john@example.com about the meeting" - Auto-detect best channel
  • "Find all VIP customers" - Contact search

Marketing

  • "Create a push notification campaign about our flash sale" - Campaign creation
  • "Send an email newsletter to our enterprise list" - Email campaigns
  • "How much would a WhatsApp campaign cost?" - Cost estimation

Knowledge Base

  • "What does our FAQ say about refunds?" - AI-powered KB search
  • "How do I set up WhatsApp integration?" - Self-service answers

Available Tools

Tools are registered based on the capabilities selected during the OAuth connection. The table below groups tools by function for readability; the OAuth consent screen groups the same 42 tools into 8 coarser capability groups (Conversations, Messaging, Email, Contacts, Campaigns, Knowledge Base, Webhooks, Team Chat Bots) — granting a group grants every tool listed under it below. Full parameter reference: docs/TOOLS.md.

CategoryTools
Conversationslist_conversations, get_conversation, send_reply, close_conversation, reopen_conversation, snooze_conversation, assign_conversation, add_internal_note, email_conversation_transcript
Messagingsend_message_to_contact, send_whatsapp_template, send_email, upload_attachment
Contactssearch_contacts, create_contact, update_contact
Tagslist_tags, create_tag, tag_conversation, untag_conversation, tag_contact, untag_contact
Campaignslist_contact_lists, list_campaigns, get_campaign_status, create_and_send_campaign, list_email_campaigns, get_email_campaign_analytics
Knowledge Basequery_knowledge_base, list_knowledge_base_folders
Channelslist_channels, list_email_mailboxes, list_verified_email_domains, list_whatsapp_templates, get_whatsapp_template
Teamlist_team_members
Team Chat Botslist_team_chat_channels, send_team_chat_channel_message, send_team_chat_direct_message
Webhooks (Developer)list_webhooks, create_webhook, delete_webhook

Authentication

OAuth 2.0 + PKCE (Recommended)

The server is a full OAuth 2.0 authorization server for MCP clients, with Dynamic Client Registration (DCR) so you don't need to pre-register an app:

EndpointURL
MCP endpointhttps://mcp.sendseven.com/mcp (Streamable HTTP)
Authorizationhttps://mcp.sendseven.com/authorize
Tokenhttps://mcp.sendseven.com/token
Dynamic Client Registrationhttps://mcp.sendseven.com/register

Most MCP clients (Claude, Cursor, etc.) discover these automatically from https://mcp.sendseven.com/mcp and only need the base URL — see the claude-desktop.json example above and the examples/ directory. For a client that needs the flow spelled out:

  1. The client registers itself via DCR (POST /register) and receives a client_id.
  2. The client sends the user to /authorize with a PKCE code_challenge and the requested scopes.
  3. The user logs in with their SendSeven account and approves the requested scopes on the consent screen.
  4. The authorization code is redeemed at /token (with the PKCE code_verifier) for an access + refresh token.
  5. The access token is sent as a Bearer token on every MCP request; the server refreshes it automatically using the refresh token.

Users can only grant scopes their SendSeven role already has - a Support Agent without campaign permissions never sees campaign tools, regardless of what the client requests.

API Tokens (Developer)

Generate a token in SendSeven's dashboard (Settings > API Tokens) and pass it as a Bearer header — simpler for CI/CD and scripts, but it doesn't auto-refresh and must be rotated manually.

Claude Skills

The repository includes workflow guides (Skills) that teach AI assistants best practices:

  • Campaign Creation - Step-by-step campaign workflow
  • Conversation Management - Triage, respond, and resolve
  • Contact Messaging - Find contacts and message them
  • Team Chat Bots - Post bot messages to Team Chat channels and users

Configuration Examples

See the examples/ directory for configuration files:

  • claude-desktop.json - Claude Desktop
  • claude-code.json - Claude Code CLI
  • cursor.json - Cursor IDE

Pricing

Free for all SendSeven customers. MCP server access is included in every plan.

  • Read operations: unlimited (within rate limits)
  • Write operations: billed as regular API usage
  • Rate limits: 20-500 req/min depending on plan

Development

# Install dependencies
npm install

# Run locally
npm run dev

# Run tests
npm test

# Type check
npm run typecheck

# Deploy to Cloudflare Workers
npm run deploy

Security

  • OAuth 2.0 with PKCE (no client secret in browser)
  • All tokens encrypted at rest
  • Scope-based access control (27 granular OAuth scopes, grouped into 8 capability groups for consent)
  • Tenant isolation (no cross-tenant data access)
  • Rate limiting per plan
  • Token revocation via SendSeven settings

License

MIT - see LICENSE

Links

Reviews

No reviews yet

Be the first to review this server!