Docs

AI agents (MCP)

Connect Claude to your organization with OAuth and manage sites, consent statements, webhooks, the vault and cookies from a conversation.

Tripticonsent exposes a remote MCP (Model Context Protocol) server so AI assistants like Claude can read and configure your organization directly, instead of your team switching to the console. The connection is authorized with OAuth 2.1: every connection is bound to a single organization and to a specific set of permissions you explicitly approve — never to a shared API key.

What it can do

Access is split into independent permissions (scopes); only the ones you check when connecting are granted:

ResourceReadWrite
Sitessites:read — list and view sitessites:write — create and edit sites
Consent statementspurposes:readpurposes:write — create, edit, publish
Webhookswebhooks:read — endpoints and deliverieswebhooks:write — create, edit, rotate the secret, replay
Consent vaultvault:read — stats, search, timeline— (not available through this channel)
Cookiescookies:read — inventory and review queuecookies:write — classify, request scans
Cookie bannerbanner:read — design and saved presetsbanner:write — edit and translate the draft · banner:preview — screenshot the draft · banner:publish — make it live
Policies & campaignspolicies:read — expiry, rulesets, campaignspolicies:write — create and edit
Regulatory documentsregulatory-documents:read — documents and versionsregulatory-documents:write — create, edit, translate, publish
Preference centerpreference-templates:read — channels, topics, fieldspreference-templates:write — create, edit, publish
IAB TCFtcf:read — configuration and cached vendor listtcf:write — edit configuration, refresh the vendor list
Analyticsanalytics:read — aggregated consent analytics (no individual data)—
Data requestsdsar:read — requests and the identity policy (not identity documents)— (approving and processing stay in the console)
Site accesssite-access:read — who has access and their role— (roles change in the console)
API keysapi-keys:read — TEST-mode keys only, never the secretapi-keys:write — create TEST-mode keys (the key is shown once); LIVE keys, rotation and revocation stay console-only
A full personal-data export for a subject, and management of API keys, team members, billing or SSO, are not exposed through this channel under any permission — they stay reserved to a console session under your own user.

Reference tools

Three read-only tools help an agent write correct integration code. They read no data of your organization, so they need no permission:

  • rotate_webhook_secret — replace an endpoint’s signing secret (shown once), optionally keeping the old one valid for up to 72 h. Needs webhooks:write.
  • list_webhook_events — every webhook event type with when it fires and what its data carries, plus the delivery contract (headers, signature scheme, retries). Use it before creating an endpoint or writing a receiver.
  • list_identifier_types — the subject identifier types (EMAIL, PHONE, EXTERNAL_ID, DEVICE_ID, COOKIE_ID, CUSTOM), which ones a pk_ key can only use with an identity token, and the reference prefixes.
  • get_api_reference — looks up the public /v1 integrator API (the one used with pk_ / sk_ keys) from the live OpenAPI document, filtered by tag or path. It documents /v1, not the administrative operations the other tools wrap.

When creating or editing a webhook endpoint, enabledEvents is a validated list of event names: an unknown or misspelled event is rejected instead of being silently accepted.

How to connect it

Claude.ai or Claude Desktop: Settings → Connectors → Add custom connector, then paste your organization’s MCP server URL. Claude walks you through the authorization flow: sign in (or you already are), pick the organization, and check which permissions to grant.

Claude Code:

claude mcp add --transport http tripticonsent https://mcp.tripticonsent.tripticode.com/mcp

The first call opens a browser to complete the same authorization flow.

Example prompts

You don’t need to know the API — just ask Claude in plain language. Name Tripticonsent explicitly in the prompt: if you also have other connectors active (Firebase, GitHub…), a generic word like "sites" or "projects" is ambiguous and Claude may reach for the wrong tool. A few things to try once it’s connected:

  • “In Tripticonsent, list the sites in this organization and which ones are live.”
  • “In Tripticonsent, add a new consent purpose called Product analytics, off by default.”
  • “Using Tripticonsent, has subject email:jane@acme.com consented to marketing emails?”
  • “In Tripticonsent, queue a cookie scan for our marketing site and tell me what shows up in the review queue.”
  • “In Tripticonsent, show me the last 10 failed webhook deliveries and retry them.”
  • “Using Tripticonsent, which webhook events exist, and which should I subscribe to so my ESP suppresses people who withdraw?”
  • “Using Tripticonsent, draft copy for a cookie banner in Spanish and English, matching our current one.”
  • “In Tripticonsent, what consent-expiry policy is set for the marketing purpose?”

How the grant works

  • Each connection is bound to one organization — the one you pick on the authorization screen. It can never read or write another organization you also belong to, even from the same account.
  • The access token lasts 15 minutes and renews automatically while the connection stays active; the refresh token expires after 90 days of inactivity.
  • Every call still goes through your organization’s member roles (viewer, editor, admin…) — a write permission granted to the connector never grants more access than the authorizing user already had.

Privacy & data access

This section describes, with technical precision, exactly what the MCP connector can touch and under what conditions — as a reference for security or compliance review. It does not replace your organization’s data processing agreement or general privacy policy with Tripticonsent.

  • Org-scoped. An access token is cryptographically bound (signed) to a single organization; a call against any other org gets 403, with no exception, regardless of the user’s role.
  • Scope-scoped, explicit. Every administrative operation requires a specific permission (sites:write, cookies:read, …). A permission not granted on the authorization screen is unreachable — not "hidden," literally not exposed by the server.
  • No access to raw subject identifiers. vault:read lets you search and view a subject’s consent state, never decrypt their underlying identifier or export a full personal-data dump.
  • No LIVE secrets. With api-keys:write the connector can create TEST-mode keys for development (the new key is returned once, like in the console) and with api-keys:read list TEST keys — never LIVE keys, never an existing key's secret, never rotation or revocation. It cannot touch identity secrets, SSO, MFA, team membership, or billing configuration under any permission.
  • Audit trail. Authorizing a connector is recorded in the organization’s Audit log (action oauth.connector_authorized), like any other configuration change.
  • Revocation. You can withdraw access at any time from Claude’s connector settings; the refresh token stops working immediately, and the access token within 15 minutes at most.

Revoking access

From Claude: Settings → Connectors, remove the connection. If you need to invalidate it immediately on your side (for example, suspected misuse), contact support to revoke the associated refresh token from the server.