Skip to content
Developer docs Setup and sign-in

MCP server

https://commentgate.com/mcp is a hosted Model Context Protocol server, so Claude, ChatGPT, Cursor and other AI assistants can work the autopilot and the inbox: see how the week went, answer what is waiting, hide and reply, change what the autopilot hides, and pull your numbers. Answers there teach the autopilot exactly like answers in the app.

Updated September 26, 2026

Claude

In Claude (web or desktop), open Customize, then Connectors, choose +, then Add custom connector, and paste https://commentgate.com/mcp. Claude sends you to CommentGate to sign in. On Team and Enterprise plans an owner adds the connector first under Organization settings, then Connectors.

Claude Code

claude mcp add --transport http commentgate https://commentgate.com/mcp

Then run /mcp in Claude Code, pick commentgate and sign in. To use an API key instead of signing in:

claude mcp add --transport http commentgate https://commentgate.com/mcp \
  --header "Authorization: Bearer cg_live_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX"

ChatGPT

In ChatGPT, open Settings, then Security and login, and turn on Developer mode. Then open Plugins, choose +, and under Connection enter https://commentgate.com/mcp. ChatGPT sends you to CommentGate to sign in.

Cursor

Add it to ~/.cursor/mcp.json (or .cursor/mcp.json in a project) and sign in when Cursor asks:

{
  "mcpServers": {
    "commentgate": {
      "url": "https://commentgate.com/mcp"
    }
  }
}

Or send a key instead of signing in:

{
  "mcpServers": {
    "commentgate": {
      "url": "https://commentgate.com/mcp",
      "headers": { "Authorization": "Bearer cg_live_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX" }
    }
  }
}

Assistants that only run local servers

The command line tool includes a local bridge. Sign in once with npx commentgate login, then add this server to the assistant's config:

{
  "mcpServers": {
    "commentgate": { "command": "npx", "args": ["-y", "commentgate", "mcp"] }
  }
}

Signing in

The assistant discovers how to sign in on its own, registers itself, and sends the person to CommentGate: the usual email link or code, then Which brand? (only for people on several brands), then Allow. Access tokens last an hour and refresh for 30 days.

  • The token is for one brand and acts as that person, with their current role and account limits. A moderator can answer and hide; only owners, admins and managers can change guidance and protections.
  • Removing someone from the brand stops their tokens at the next call.
  • With an API key instead, the same rules as the REST API apply: the key's creator's role for writes, every account in the workspace for reads.

For client developers

The server speaks Streamable HTTP, stateless: every JSON-RPC request is a POST answered with JSON (no sessions and no server-sent stream; GET and DELETE answer 405). Without a token it answers 401 with WWW-Authenticate: Bearer resource_metadata="https://commentgate.com/.well-known/oauth-protected-resource/mcp".

DocumentPath
Protected resource metadata (RFC 9728)/.well-known/oauth-protected-resource/mcp
Authorization server metadata (RFC 8414)/.well-known/oauth-authorization-server/api/auth
OpenID configuration/api/auth/.well-known/openid-configuration
Dynamic client registration (RFC 7591)/api/auth/oauth2/register

The issuer is https://commentgate.com/api/auth. PKCE (S256) is required, and tokens are bound to the resource https://commentgate.com/mcp.

Results and errors

Each tool answers with a short text summary for the assistant plus structuredContent in the REST API's JSON shape. A failure is a tool error (isError: true) with the API's sentence and { "error": { "code", "message" } }, so a platform limit reaches the person in words. Tools carry readOnlyHint, destructiveHint, idempotentHint and openWorldHint annotations. Delete, like, restore, contacts and hooks are left to the REST API.

In the help center