AI agents (MCP)
Connect Claude to your organization with OAuth and manage sites, consent statements, webhooks, the vault and cookies from a conversation.
Tripticonsent exposes a remote MCP (Model Context Protocol) server so AI assistants like Claude can read and configure your organization directly, instead of your team switching to the console. The connection is authorized with OAuth 2.1: every connection is bound to a single organization and to a specific set of permissions you explicitly approve — never to a shared API key.
What it can do
Access is split into independent permissions (scopes); only the ones you check when connecting are granted:
| Resource | Read | Write |
|---|---|---|
| Sites | sites:read — list and view sites | sites:write — create and edit sites |
| Consent statements | purposes:read | purposes:write — create, edit, publish |
| Webhooks | webhooks:read — endpoints and deliveries | webhooks:write — create, edit, rotate the secret, replay |
| Consent vault | vault:read — stats, search, timeline | — (not available through this channel) |
| Cookies | cookies:read — inventory and review queue | cookies:write — classify, request scans |
| Cookie banner | banner:read — design and saved presets | banner:write — edit and translate the draft · banner:preview — screenshot the draft · banner:publish — make it live |
| Policies & campaigns | policies:read — expiry, rulesets, campaigns | policies:write — create and edit |
| Regulatory documents | regulatory-documents:read — documents and versions | regulatory-documents:write — create, edit, translate, publish |
| Preference center | preference-templates:read — channels, topics, fields | preference-templates:write — create, edit, publish |
| IAB TCF | tcf:read — configuration and cached vendor list | tcf:write — edit configuration, refresh the vendor list |
| Analytics | analytics:read — aggregated consent analytics (no individual data) | — |
| Data requests | dsar:read — requests and the identity policy (not identity documents) | — (approving and processing stay in the console) |
| Site access | site-access:read — who has access and their role | — (roles change in the console) |
| API keys | api-keys:read — TEST-mode keys only, never the secret | api-keys:write — create TEST-mode keys (the key is shown once); LIVE keys, rotation and revocation stay console-only |
Reference tools
Three read-only tools help an agent write correct integration code. They read no data of your organization, so they need no permission:
rotate_webhook_secret— replace an endpoint’s signing secret (shown once), optionally keeping the old one valid for up to 72 h. Needswebhooks:write.list_webhook_events— every webhook event type with when it fires and what itsdatacarries, plus the delivery contract (headers, signature scheme, retries). Use it before creating an endpoint or writing a receiver.list_identifier_types— the subject identifier types (EMAIL,PHONE,EXTERNAL_ID,DEVICE_ID,COOKIE_ID,CUSTOM), which ones apk_key can only use with an identity token, and the reference prefixes.get_api_reference— looks up the public/v1integrator API (the one used withpk_/sk_keys) from the live OpenAPI document, filtered by tag or path. It documents/v1, not the administrative operations the other tools wrap.
When creating or editing a webhook endpoint, enabledEvents is a validated list of event names: an unknown or misspelled event is rejected instead of being silently accepted.
How to connect it
Claude.ai or Claude Desktop: Settings → Connectors → Add custom connector, then paste your organization’s MCP server URL. Claude walks you through the authorization flow: sign in (or you already are), pick the organization, and check which permissions to grant.
Claude Code:
claude mcp add --transport http tripticonsent https://mcp.tripticonsent.tripticode.com/mcpThe first call opens a browser to complete the same authorization flow.
Example prompts
You don’t need to know the API — just ask Claude in plain language. Name Tripticonsent explicitly in the prompt: if you also have other connectors active (Firebase, GitHub…), a generic word like "sites" or "projects" is ambiguous and Claude may reach for the wrong tool. A few things to try once it’s connected:
- “In Tripticonsent, list the sites in this organization and which ones are live.”
- “In Tripticonsent, add a new consent purpose called Product analytics, off by default.”
- “Using Tripticonsent, has subject
email:jane@acme.comconsented to marketing emails?” - “In Tripticonsent, queue a cookie scan for our marketing site and tell me what shows up in the review queue.”
- “In Tripticonsent, show me the last 10 failed webhook deliveries and retry them.”
- “Using Tripticonsent, which webhook events exist, and which should I subscribe to so my ESP suppresses people who withdraw?”
- “Using Tripticonsent, draft copy for a cookie banner in Spanish and English, matching our current one.”
- “In Tripticonsent, what consent-expiry policy is set for the marketing purpose?”
How the grant works
- Each connection is bound to one organization — the one you pick on the authorization screen. It can never read or write another organization you also belong to, even from the same account.
- The access token lasts 15 minutes and renews automatically while the connection stays active; the refresh token expires after 90 days of inactivity.
- Every call still goes through your organization’s member roles (viewer, editor, admin…) — a write permission granted to the connector never grants more access than the authorizing user already had.
Privacy & data access
This section describes, with technical precision, exactly what the MCP connector can touch and under what conditions — as a reference for security or compliance review. It does not replace your organization’s data processing agreement or general privacy policy with Tripticonsent.
- Org-scoped. An access token is cryptographically bound (signed) to a single organization; a call against any other org gets
403, with no exception, regardless of the user’s role. - Scope-scoped, explicit. Every administrative operation requires a specific permission (
sites:write,cookies:read, …). A permission not granted on the authorization screen is unreachable — not "hidden," literally not exposed by the server. - No access to raw subject identifiers.
vault:readlets you search and view a subject’s consent state, never decrypt their underlying identifier or export a full personal-data dump. - No LIVE secrets. With
api-keys:writethe connector can create TEST-mode keys for development (the new key is returned once, like in the console) and withapi-keys:readlist TEST keys — never LIVE keys, never an existing key's secret, never rotation or revocation. It cannot touch identity secrets, SSO, MFA, team membership, or billing configuration under any permission. - Audit trail. Authorizing a connector is recorded in the organization’s
Audit log(actionoauth.connector_authorized), like any other configuration change. - Revocation. You can withdraw access at any time from Claude’s connector settings; the refresh token stops working immediately, and the access token within 15 minutes at most.
Revoking access
From Claude: Settings → Connectors, remove the connection. If you need to invalidate it immediately on your side (for example, suspected misuse), contact support to revoke the associated refresh token from the server.