Skip to main content

Announcing StackOne Defender: leading open-source prompt injection guard for your agent Read More

Customer.io MCP Server
for AI Agents

Production-ready Customer.io MCP server with 48 extensible actions — plus built-in authentication, security, and optimized execution.

Customer.io logo
Customer.io MCP Server
Built by StackOne StackOne

Coverage

48 Agent Actions

Create, read, update, and delete across Customer.io — and extend your agent's capabilities with custom actions.

Authentication

Agent Tool Authentication

Per-user OAuth in one call. Your Customer.io MCP server gets session-scoped tokens with zero credentials stored on your infra.

Agent Auth →

Security

Agent Protection

Every Customer.io tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.

Prompt Injection Defense →

Performance

Max Agent Context. Min Cost.

Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Customer.io call.

Tools Discovery →

What is the Customer.io MCP Server?

A Customer.io MCP server lets AI agents read and write Customer.io data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Customer.io MCP server ships with 48 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, and optimized agent context. Connect it from MCP clients like Claude Desktop, Cursor, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.

All Customer.io MCP Tools and Actions

Every action from Customer.io's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.

Broadcasts

  • List Broadcasts

    List all broadcasts in the workspace

  • Get Broadcast

    Retrieve a specific broadcast by ID

Campaigns

  • List Campaigns

    List all campaigns in the workspace

  • Get Campaign

    Retrieve a specific campaign by ID

Messages

  • List Messages

    List all messages in the workspace

  • Get Message

    Retrieve a specific message by ID

Newsletters

  • List Newsletters

    List all newsletters in the workspace

  • Get Newsletter

    Retrieve a specific newsletter by ID

Segments

  • List Segments

    List all segments in the workspace

  • Get Segment

    Retrieve a specific segment by ID

Snippets

  • Create Snippet

    Create a new snippet

  • List Snippets

    List all snippets in the workspace

  • Update Snippet

    Create or update a snippet

  • Delete Snippet

    Delete a snippet

Other (34)

  • Add Or Update A Customer

    Add or update a customer

  • Add Or Update A Customer Device

    Add or update a customer device

  • Add Customers To Segment

    Add customers to a manual segment

  • List Activities

    List all activities in the workspace

  • Get Broadcast Metrics

    Get metrics for a broadcast

  • List Broadcast Actions

    List all actions in a broadcast

  • Get Broadcast Triggers

    Get trigger history for a broadcast

  • Get Campaign Metrics

    Get metrics for a campaign

  • List Campaign Actions

    List all actions in a campaign

  • Get Customers By Email

    Get customers by email address

  • Search For Customers

    Search for customers using advanced filters

  • List Customers, Attributes, And Devices

    List customers with their attributes and devices

  • Get Newsletter Metrics

    Get metrics for a newsletter

  • Get Newsletter Link Metrics

    Get link click metrics for a newsletter

  • Get A Segment Customer Count

    Get the total number of customers in a segment

  • List Customers In A Segment

    List all customers in a specific segment

  • List Sender Identities

    List all sender identities in the workspace

  • Get Sender Identity

    Retrieve a specific sender identity by ID

  • Get Account Region

    Find your account region

  • Delete A Newsletter

    Delete a specific newsletter

  • Delete A Segment

    Delete a specific segment

  • Delete A Customer

    Delete a customer

  • Delete A Customer Device

    Delete a customer device

  • Remove Customers From Segment

    Remove customers from a manual segment

  • Lookup A Customer's Attributes

    Get attributes for a specific customer

  • Lookup A Customer's Segments

    Get segments a customer belongs to

  • Lookup Messages Sent To A Customer

    Get messages sent to a customer

  • Lookup A Customer's Activities

    Get activities for a customer

  • Lookup A Customer's Relationships

    Get relationships for a specific customer

  • Merge Duplicate People

    Merge duplicate customers

  • Track Customer Event

    Track an event for a customer

  • Track Anonymous Event

    Track an event for an anonymous user

  • Suppress A Customer Profile

    Suppress a customer profile

  • Unsuppress A Customer Profile

    Unsuppress a customer profile

Set Up Your Customer.io MCP Server in Minutes

One endpoint. Any framework. Your agent is talking to Customer.io in under 10 lines of code.

MCP Clients

Agent Frameworks

Claude Desktop
{
  "mcpServers": {
    "stackone": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote@latest",
        "https://api.stackone.com/mcp?x-account-id=<account_id>",
        "--header",
        "Authorization: Basic <YOUR_BASE64_TOKEN>"
      ]
    }
  }
}

More Marketing Automation MCP Servers

Klaviyo

162+ actions

Zoho CRM

126+ actions

Intercom

123+ actions

SendGrid

99+ actions

Braze

98+ actions

Mailchimp

80+ actions

Campaign Monitor

73+ actions

Customer.io MCP Server FAQ

Customer.io MCP server vs direct API integration — what's the difference?
A Customer.io MCP server and direct API integration serve different use cases. Direct API integration is for software-to-software — backend code calling Customer.io. A Customer.io MCP server is for AI agents — MCP clients like Claude and Cursor, plus framework agents built with OpenAI, LangChain, or Vercel AI — discovering and calling Customer.io at runtime. StackOne provides both.
How does Customer.io authentication work for AI agents?
Customer.io authentication for AI agents works through a StackOne Connect Session. Create one via the dashboard or the SDK — you get an auth link and ready-to-paste config for Claude Desktop, Cursor, and other MCP clients. Your user authenticates their own Customer.io account; StackOne handles token exchange, storage, and refresh. Credentials never reach the LLM, and each user is isolated via origin_owner_id.
Are Customer.io MCP tools vulnerable to prompt injection?
Yes — Customer.io MCP tools can be vulnerable to indirect prompt injection. Any tool that reads user-written content — documents, messages, tickets, records, or free-text fields — is a potential vector. StackOne Defender scans every tool response before it enters the agent's context — regex patterns in ~1ms, then a MiniLM classifier in ~4ms. 88.7% accuracy, CPU-only.
What is the context bloat of a Customer.io agent and how do I avoid it?
Context bloat happens when Customer.io tool schemas and API responses eat your Customer.io agent's memory, preventing it from reasoning effectively. A single Customer.io query can return a massive JSON response, and connecting multiple tools compounds the problem. Tools Discovery and Code Mode reduce context bloat — loading only relevant tools per query and keeping raw responses out of the agent's context.
Can I limit which actions my Customer.io agent can access?
Yes — you can limit which actions your Customer.io agent can access directly from the StackOne dashboard. Toggle actions on or off, or restrict them to specific accounts, with no code changes to your agent. Session tokens can be scoped to exact actions so if one leaks, exposure stays contained.
Can I create custom agent actions for my Customer.io MCP server?
Yes — you can create custom agent actions for your Customer.io MCP server using Connector Builder. It's an integration agent your coding assistant (Claude Code, Cursor, or Copilot) can invoke to research Customer.io's API, generate production-ready connector YAML, test against the live API, and validate before you ship.
When should I NOT use a Customer.io MCP server?
Skip a Customer.io MCP server if your integration is purely software-to-software — direct Customer.io API integration is simpler when no AI agent is involved. For deterministic, compliance-critical operations (financial transactions, regulatory reporting), direct API gives you predictable behavior without agent-driven decision-making. MCP shines when AI agents need to dynamically discover and call Customer.io actions at runtime.
What AI frameworks and AI clients does the StackOne Customer.io MCP server support?
The StackOne Customer.io MCP server supports both. MCP clients (paste-and-go apps): Claude Desktop, Claude Code, Cursor, VS Code, Goose. Agent frameworks (code SDKs you build with): OpenAI Agents SDK, Anthropic, Vercel AI, Google ADK, CrewAI, Pydantic AI, LangChain, LangGraph, Azure AI Foundry.

Put your AI agents to work

All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.