An open source Flodesk MCP server and shared CLI with 32 tools and exact reviewed subscriber workflows.
Key takeaways
This free Flodesk MCP server and CLI gives your AI real access to current subscribers, native batch upserts, draft campaigns, workflows, custom fields and webhooks. Read the intended audience, review exact ordered subscriber requests and apply only approved native API work.
It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 32 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.
Here's what the Flodesk MCP server and CLI is, how to set it up in each app, and every tool it has.
What is the Flodesk MCP server & CLI?
The Flodesk MCP server & CLI is a free, open source program that lets AI agents read and change requested Flodesk account data with explicit approval for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.
You ask in plain language. Your AI picks the right tool, and the server makes the call to the fixed Flodesk API origin using the selected private API key or externally minted OAuth token.
The CLI is the same program as commands. flodesk-cli list-subscribers runs the same code your AI runs when you deliberately read one intended subscriber page, whether an agent like Claude Code runs it or you do.
What can you ask it?
Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:
Try askingRead these subscribers and their exact native statuses.
Upsert only the subscriber records and opt-in data I approve.
Inspect these workflows and enroll only the requested subscriber.
Review these ordered native requests and show the exact hash.
Apply only that matching batch and keep partial receipts.
Publish the approved Canva or Studio export as a draft.
Flodesk already offers an official MCP with analytics, cohort filtering, CSV export and robust bulk confirmation tokens. This companion adds verified local CLI/stdio workflows for the current native public API, including drafts, custom fields, webhooks, explicit workflow enrollment and 50-subscriber upserts.
How to install the Flodesk MCP server
Choose the shared CLI, local stdio MCP or versioned desktop bundle. Codex comes first, followed by every declared client and operating system.
Watch out: Installation does not authenticate an account. Subscriber upserts, opt-ins and workflow actions can send email; they are unsuitable smoke tests.
Set up Flodesk access
Private integration API key
- Sign into the intended Flodesk account. Open Account → Integrations → API, or the API key settings. Check which account owns the audience before creating/copying a key.
- Use a private integration API key for your own account. The native docs describe full API access; this package does not invent per-operation key scopes or guarantee provider read-only keys. Local read-only policy is a separate control.
- Save FLODESK_API_KEY only in private user/client environment settings, or use FLODESK_TOKEN_FILE as an absolute token-only file outside repositories. On macOS/Linux use a private 0700 directory and owner-private 0600 regular non-symlink file, at most 64 KiB. On Windows restrict file/parent ACLs to yourself; POSIX mode checks do not establish Windows ACLs.
- Run flodesk-cli doctor for local settings. Deliberately run doctor --network to read one subscriber page with per_page=1; output reports only count, not the subscriber record. That verifies one read, not account-owner identity, campaign/webhook access or all native permissions.
- Inspect exact native fields and IDs, then approve only requested work. Double opt-in, segment additions and workflow enrollment can trigger actual messages. Do not create subscribers, opt-ins, workflow entries, drafts or webhooks merely to test installation.
The API key is an HTTP Basic username, with an empty password. The client constructs Authorization: Basic base64(key:), sends a descriptive User-Agent and uses only the allowlisted https://api.flodesk.com origin. No API key goes into a URL, prompt, Git file or log. It refuses redirects and unknown routes.
Externally minted partner OAuth
Native partner OAuth requires a provider-approved integration with its own client ID/secret and redirect flow. This package accepts an externally minted FLODESK_ACCESS_TOKEN or named access_token profile as Authorization: Bearer. It does not register an app, start login, exchange authorization codes, refresh tokens or import official connector sessions.
Access tokens are documented as 24 hours; refresh tokens are single-use and rotate. Refreshing belongs to your approved private integration and must store its newly issued refresh token securely. This runtime never holds that client secret/refresh token. Restart after replacing its access token. get_oauth_userinfo makes only the fixed /oauth2/userinfo GET and refuses API-key profiles before any request.
For a token file containing an OAuth access token, set FLODESK_AUTH_TYPE=oauth for a direct profile, or auth_type:"oauth" in that named profile. File credentials otherwise default to API key. Never configure api_key and access_token together. A selected file overrides only its own profile's inline credential; profiles never inherit a global key/token or another account.
Several private accounts
FLODESK_ACCOUNTS is a private JSON array of unique {name,api_key,access_token,token_file,auth_type} entries. Choose exactly one credential type in each. FLODESK_DEFAULT_ACCOUNT and --account select exact labels. Labels and review hashes are not verified provider ownership. Token files cache until process restart. list_accounts returns only labels/default/auth type/credential source, without token paths or provider reads.
Official MCP connection
Flodesk already supplies its official MCP and setup help. Its production field reference currently lists 35 tools, including email/form/checkout/workflow analytics, cohort filters, subscriber actions, CSV export and bulk archive/unarchive/segment changes. Its previews issue single-use confirmation tokens expiring after 120 seconds. Those capabilities and safeguards already exist.
The September 11 help article describes an earlier 24-tool/individual-action phase and says bulk work is upcoming; the current production catalog describes 35 tools and bulk workflows. Treat that as documented source drift. Marketing's broad future-control examples do not establish current send/schedule support. This local public-REST package does not call private MCP-only analytics/cohort routes or accept the hosted connector's confirmation tokens.
Quotas and effects
The AGPL wrapper is free; Flodesk subscription/API eligibility and account policies remain separate. Native REST limits are 100 requests/minute normally and 20/minute for POST /subscribers/batch, up to 50 subscribers per request. X-Fd-RateLimit headers report remaining capacity. Our process spacing defaults 650 ms, plus a separate 3100 ms batch window. Other processes/apps share account quota; local pacing is not provider enforcement or a guaranteed distributed limiter.
No automatic retries, including reads, 429, 5xx, redirects or timeouts. A failed write can leave an unknown result, duplicate webhook/segment or triggered message. Inspect provider state before deliberately repeating. JSON requests cap 1 MiB and responses 5 MiB. Each native list returns one page with its own meta/page semantics, not an all-pages backup. Workflow statuses use native CSV and perPage; campaign query names retain native capitalization.
Canva and Studio publish draft campaign exports, not send/schedule emails. Subscriber upsert can create or update by id/email; up to 50 segment IDs are supported. double_optin applies only to newly created subscribers and can send a confirmation message. Workflow re-entry needs prior completion and Allow repeat subscribers; abandoned-cart workflows cannot be enrolled through this route. Unsubscribe changes subscription state without pretending to delete the record. Removing segment membership is distinct and sends the required native DELETE JSON body.
Revocation and retained data
Revoke the intended key at Flodesk, replace private settings/files and restart. Revoke partner OAuth/official connector authorization separately. Package/client removal does not undo audience changes, sent opt-ins/workflow effects, drafts, webhooks or private audience-page files. Retain receipts and investigate unknown outcomes before explicitly requested cleanup.
Check that it works
Begin with local discovery and settings, then deliberately opt into one subscriber read.
flodesk-cli --version
flodesk-cli doctor
flodesk-cli list-accounts --agent
flodesk-cli doctor --networkflodesk-cli --version
flodesk-cli tools
flodesk-cli list-accounts --agent
flodesk-cli doctor
flodesk-cli doctor --network
flodesk-cli list-subscribers --per-page 1 --agent --select meta,data.idThe release validates shared full/read-only discovery and native request fixtures. Actual authenticated provider reads/writes, desktop GUI installation and matched successful Codex task/token measurements require their own evidence. doctor without --network checks local configuration only. One successful subscriber read does not prove ownership or every permission; never trigger opt-ins/workflows to test installation.
Use the Flodesk CLI
The CLI is the same 32 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.
Every tool name becomes a command with dashes, so list_subscribers runs as flodesk-cli list-subscribers.
flodesk-cli tools
flodesk-cli list-subscribers --help
flodesk-cli schema batch-create-or-update-subscribers
flodesk-cli list-subscribers --per-page 5 --account work --agent
flodesk-cli get-subscriber --id-or-email YOUR_SUBSCRIBER_ID --account work --agentThe bare flodesk-cli lists every command, and flodesk-cli <command> --help shows what a command takes. All 16 mutations/private-file operations require --confirm. --agent/--yes never approve work. Repeat --tasks once per JSON object; complete native bodies may use an absolute private payload_file.
These flags work on every command:
| Flag | What it does |
|---|---|
| --agent | Compact JSON, never approval |
| --select a,b.c | Local result field selection |
| --confirm | Only the requested mutation/private-file write |
| --account LABEL | Exact private account profile |
| --payload / --payload-file | Exclusive complete native body |
| --tasks JSON | Repeat each ordered subscriber task |
| --review-sha256 HASH | Exact current local preview hash |
| --output-file PATH | New exclusive private single-page JSON file |
A script can branch on the exit code:
| Exit code | What it means |
|---|---|
| 0 | It worked |
| 2 | The command was typed wrong, or a write needed --confirm |
| 3 | It wasn't found |
| 4 | Flodesk rejected the credentials |
| 5 | Flodesk's API failed |
| 7 | You hit a rate limit, so wait and try again |
| 10 | Nothing is set up yet |
MCP server or CLI: which one?
Both surfaces call the same tools. Codex can connect to the local MCP server or run the CLI directly. Neither requires Claude Code.
MCP provides structured tool discovery; the CLI supports scripts, compact JSON, field selection and command/schema discovery. Official hosted MCP connection and local CLI authentication have different setup requirements.
Codex-specific token measurements are pending. Record the actual client/model versions, discovery configuration, input/output usage, caching, latency and equivalent successful outcomes. Standing definitions and full task cost are separate measurements; CLI commands, selected help, results and reasoning still consume tokens.
No efficiency percentage or Claude-derived figure is presented as a Codex result. Other-client benchmarks can be added separately.
Subscriber, draft and workflow examples
Start with one intended account and exact IDs. Read current subscriber status/membership, segment colors and available workflow IDs before approving changes. Do not infer consent or enroll all matching rows from a display name. Native upsert accepts id or email; optional optin_ip/optin_timestamp preserve supplied provenance rather than inventing it. Its status filter now includes unconfirmed, cleaned and archived.
Use native batch upsert for 1–50 explicit subscribers. It is distinct from the official MCP's dynamic-cohort archive/export actions. Inspect every successes/failures item and repeat only an explicitly reviewed correction after resolving unknown outcomes.
Segment removal changes membership and retains the subscriber record; unsubscribe changes subscription state. Workflow addition can trigger real automation messages and is refused until confirmed. Provider re-entry/completion/abandoned-cart restrictions still apply; the wrapper does not circumvent them.
Create a webhook only for the explicitly chosen HTTPS receiver and requested native events. No receiver is called by this local client. Event delivery is provider behavior after configuration; a creation response is not a receiver/test-delivery success. Native public REST does not expose a signing-key creation/rotation endpoint, and none is invented.
Publish reviewed native HTML via publish_studio_email, or an approved exported bundle_url via publish_canva_email. These create/update draft campaigns; sending/scheduling remains outside this API. The old blanket statement that no campaign creation exists is corrected. Never treat a returned draft URL as a sent campaign receipt.
flodesk-cli get-subscriber --id-or-email YOUR_SUBSCRIBER_ID --account work --agent
flodesk-cli list-workflows --agent
flodesk-cli get-operation-schema --operation publish_studio_email --agent
flodesk-cli create-or-update-subscriber --help
flodesk-cli save-subscriber-page --per-page 1 --output-file /absolute/private/page-001.json --account work --confirm --agentExact ordered batch review and pagination
preview_subscriber_batch is fully local: validate 1–20 ordered subscriber/segment/workflow/custom-field tasks against current packaged schemas and native semantics. It loads no key/file and makes no provider read. SHA-256 binds ordered exact requests/tasks, selected profile label/auth type and snapshot. It is not a real-cohort preview, final recipient count, cryptographic approval, current provider-state lock or verified account ownership. A changed key can keep the same label.
submit_subscriber_batch requires explicit confirmation and the matching hash. Every task is validated before the first request. Native batch-upsert tasks may each affect 50 subscribers:20 tasks is not a 20-recipient budget. Stop on first failure, partial native HTTP 200 result or incomplete native receipt, returning knownResults/failedIndex/unattemptedIndices without automatic retry, replay, rollback or implicit continuation. Earlier subscriber/workflow effects can persist.
Official preview_bulk_change and preview_segment_count already count real filtered audiences, issue single-use 120-second tokens and validate cohort growth. Our exact local ordered REST review has a different purpose and cannot replace those safeguards. Hosted tokens are not accepted here.
Native lists return one meta page. Carry the actual route's page/per_page or workflow page/perPage with unchanged filters/account. list_all_custom_fields is a named native all-fields route, not a generic automatic all-pages loop. Local perPage cap 100 is explicit. No full-audience export or all_pages option is invented.
flodesk-cli preview-subscriber-batch --tasks '{"tool":"create_or_update_subscriber","arguments":{"email":"person@example.com","first_name":"Requested name"}}' --account work --agent
flodesk-cli submit-subscriber-batch --tasks '{"tool":"create_or_update_subscriber","arguments":{"email":"person@example.com","first_name":"Requested name"}}' --account work --review-sha256 YOUR_REVIEW_SHA256 --confirm --agentEvery Flodesk tool
Actual discovery exposes 32 tools: 16 reads and 16 confirmed operations. All 26 current public-v1 native routes and six helper/account/file tasks share handlers. All 20 legacy tool names remain with deliberate 2.0 native argument corrections. Every native argument follows below.
Campaigns
list_campaigns- What it does
- List campaigns.
- Kind
- Read/helper
publish_canva_email- What it does
- Publish a Canva email design as a draft campaign.
- Kind
- Confirmed operation
get_canva_design_state- What it does
- Get the latest Canva design state for auto-selecting campaigns.
- Kind
- Read/helper
publish_studio_email- What it does
- Publish a Studio email export as a draft campaign.
- Kind
- Confirmed operation
Custom Fields
list_custom_fields- What it does
- List all custom fields (pagination).
- Kind
- Read/helper
create_custom_field- What it does
- Create a custom field.
- Kind
- Confirmed operation
list_all_custom_fields- What it does
- List all custom fields.
- Kind
- Read/helper
Segments
list_segments- What it does
- List all segments.
- Kind
- Read/helper
create_segment- What it does
- Create a segment.
- Kind
- Confirmed operation
list_segment_colors- What it does
- List all segment colors.
- Kind
- Read/helper
get_segment- What it does
- Retrieve a segment.
- Kind
- Read/helper
Subscribers
list_subscribers- What it does
- List all subscribers.
- Kind
- Read/helper
create_or_update_subscriber- What it does
- Create or update a subscriber.
- Kind
- Confirmed operation
batch_create_or_update_subscribers- What it does
- Create or update up to 50 subscribers in a single request.
- Kind
- Confirmed operation
get_subscriber- What it does
- Retrieve a subscriber.
- Kind
- Read/helper
remove_subscriber_from_segments- What it does
- Remove the subscriber from segments.
- Kind
- Confirmed operation
add_subscriber_to_segments- What it does
- Add the subscriber to segments.
- Kind
- Confirmed operation
unsubscribe- What it does
- Unsubscribe from all lists.
- Kind
- Confirmed operation
Webhooks
list_webhooks- What it does
- List all webhooks.
- Kind
- Read/helper
create_webhook- What it does
- Create a webhook.
- Kind
- Confirmed operation
delete_webhook- What it does
- Delete a webhook.
- Kind
- Confirmed operation
get_webhook- What it does
- Retrieve a webhook.
- Kind
- Read/helper
update_webhook- What it does
- Update a webhook.
- Kind
- Confirmed operation
Workflows
list_workflows- What it does
- List workflows.
- Kind
- Read/helper
add_subscriber_to_workflow- What it does
- <br><b>Notes:</b> <ul> <li>In order for a subscriber to be added to a workflow subsequent times, (1) the subscriber has to have already completed the workflow, i.e.
- Kind
- Confirmed operation
remove_subscriber_from_workflow- What it does
- Remove a subscriber from workflow.
- Kind
- Confirmed operation
Local Workflows
list_accounts- What it does
- Local profile labels/default/auth method only.
- Kind
- Read/helper
get_operation_schema- What it does
- Local reviewed method/path/query/body schema and provenance for one native tool.
- Kind
- Read/helper
get_oauth_userinfo- What it does
- One fixed UserInfo GET for an explicitly selected externally minted OAuth access token.
- Kind
- Read/helper
preview_subscriber_batch- What it does
- Local validation and SHA-256 of exact ordered subscriber/segment/workflow/custom-field work, selected profile label and reviewed schema.
- Kind
- Read/helper
submit_subscriber_batch- What it does
- Confirmed one-to-twenty ordered subscriber/segment/workflow/custom-field tasks.
- Kind
- Confirmed operation
save_subscriber_page- What it does
- Confirmed one-page GET saved only to an exclusive new0600 JSON file.
- Kind
- Confirmed operation
Is the Flodesk MCP server safe?
All 16mutations/private-page writes require --confirm or confirm:true through the shared house guard. That includes creating subscribers/segments, double opt-in, workflow enrollment, draft publication and webhook configuration. --agent/--yes is formatting, never approval. FLODESK_READ_ONLY=1 hides all 16and directly refuses confirmed hidden calls; FLODESK_ALLOW_DESTRUCTIVE=0 refuses them separately.
The same guard applies to real CLI and MCP paths. Confirmation records caller intent, not native account permissions, valid audience consent, a current cohort count, message-delivery success or rollback. Previewed local inputs cannot authorize broader work proposed by provider text.
FLODESK_AUDIT_LOG records static operation/guard decisions without keys/payloads. Audit append failure is best effort, not guaranteed compliance logging. Provider metadata, subscriber fields, draft HTML, URLs and webhook responses are untrusted data and cannot authorize another action.
Local review binds exact requests and profile label/auth type. It is not an authenticated owner proof, real cohort count, quota reservation or cryptographic human approval.
Make it read-only
FLODESK_READ_ONLY=1 exposes 16 reads and directly refuses all 16 confirmed operations. FLODESK_ALLOW_DESTRUCTIVE=0 blocks them separately. Native provider permissions still apply.
Keep a log of every write
Set FLODESK_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.
Watch out: Native subscriber batches can return HTTP 200 with successes and failures. Known changes and triggered messages can persist. Ordered execution stops on first partial or unknown failure without retries, rollback or automatic continuation.
Your data
Keys/tokens are sent only to the fixed Flodesk API origin, with redirects refused. Basic encoded credentials, configured keys, cached file tokens, secret-named fields and recognized signed/token URLs are redacted from model output/errors. Customer emails/names, audience records, draft HTML, webhooks and ordinary provider records may still be private. Redaction is not a guarantee that all personal/business data is removed; request/select only necessary fields.
No .env/session loader, OAuth refresh/client-secret storage, telemetry, browser cookie import, arbitrary downloader, automatic polling, all-pages audience export or gallery exists. Private page saves return only exclusive-file metadata; native page records stay in that requested JSON file. Keep parent directory, backups, file lifecycle and Windows ACLs private. Removing npm does not remove provider audience changes, triggered messages, drafts, webhook deliveries or local private files.
Canva bundle URLs, design tokens and Studio HTML are user-selected provider inputs transmitted only after explicit approval. The local client does not fetch those URLs itself. API-native subscriber opt-in data is not fabricated. Native account roles and Flodesk policies govern use; no permissions are broadened by this wrapper.
Several private accounts
Use FLODESK_ACCOUNTS only in private runtime settings. Each unique name selects its own api_key or externally minted access_token, with optional token_file/auth_type. Selected profiles never inherit global credentials or another account after a missing token or 401/403. Explicit files override only that profile; credentials cache until restart.
list_accounts shows safe labels/default/auth type/source. It does not authenticate or establish the key owner's identity. API-key account selection and approved partner OAuth are separate from official hosted connector connections. Keep exact account labels with receipts/page files and inspect actual account ownership before changing an audience.
flodesk-cli list-accounts --agent
flodesk-cli list-subscribers --account work --per-page 1 --agentFlodesk MCP server settings
Keep keys, tokens, files and profile JSON outside repositories. GUI and remote runtimes have separate settings and filesystems. No automatic .env, OAuth refresh or hosted-session import occurs.
- Default
- Credentials
- What it does
- Private integration Basic username key; empty password. No fallback with named profiles.
- Default
- Credentials
- What it does
- Externally minted partner Bearer token, never alongside api_key; no refresh.
- Default
- Credentials
- What it does
- Absolute owner-private regular token-only file overriding only selected direct credential.
- Default
- Credentials
- What it does
- oauth for Bearer token files; blank infers inline credential or defaults file to api_key.
- Default
- Credentials
- What it does
- Private unique {name,api_key,access_token,token_file,auth_type} profiles.
- Default
- Credentials
- What it does
- Exact selected private profile label, not provider owner proof.
- Default
- Safety
- What it does
- 1/true hides and directly refuses all16confirmed operations.
- Default
- Safety
- What it does
- 0/false refuses confirmed operations too.
- Default
- Safety
- What it does
- Optional best-effort static guard log without payload/key.
- Default
- Tuning
- What it does
- Default30000; allowed100–300000; no automatic retries.
- Default
- Tuning
- What it does
- Default650; allowed0–10000; process-wide ordinary spacing.
- Default
- Tuning
- What it does
- Default3100; allowed0–60000; separate native batch-upsert window.
Troubleshooting
Run the doctor first. It names the step that failed and the fix.
| What you see | What to do |
|---|---|
| Missing/invalid profile | Check exact unique labels and private key/token/file settings. |
| 401/403 | Check the intended account and API eligibility; an expired OAuth token needs external refresh. |
| 429 | Respect ordinary and native batch quota; no automatic retry. |
| Subscriber batch fails partly | Inspect every native successes/failures entry; do not replay known successes. |
| Review mismatch | Preview exact changed inputs/order/profile/schema again. |
| Native request rejected | Read current schema and native names/capitalization/CSV arguments. |
| Existing output file | Choose a new private path; no overwrite. |
| Accepted workflow action | Inspect actual provider outcomes separately; the receipt is not proof of completion. |
If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.
Every tool argument and native input
list_campaigns
List campaigns.
Kind: Read. Native account permissions and local semantics still apply.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
Search- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter.
OrderBy- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter.
Sort- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter.
Status- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter. enum:
["draft", "pending", "scheduled", "composing", "sending", "done", "failed"].
SharedAsTemplate- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Exact native query parameter.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
publish_canva_email
Publish a Canva email design as a draft campaign.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
bundle_url- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
title- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
design_token- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
page_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
campaign_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.payload
bundle_url- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
title- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
design_token- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
page_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
campaign_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
get_canva_design_state
Get the latest Canva design state for auto-selecting campaigns.
Kind: Read. Native account permissions and local semantics still apply.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
publish_studio_email
Publish a Studio email export as a draft campaign.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
html- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
title- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
campaign_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
asset_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.payload
html- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
title- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
campaign_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
asset_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
list_custom_fields
List all custom fields (pagination).
Kind: Read. Native account permissions and local semantics still apply.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
create_custom_field
Create a custom field.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
label- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- A friendly display label of the custom field.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.payload
label- Required
- Yes
- Type
- string
- Details
- A friendly display label of the custom field.
list_all_custom_fields
List all custom fields.
Kind: Read. Native account permissions and local semantics still apply.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
list_segments
List all segments.
Kind: Read. Native account permissions and local semantics still apply.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
create_segment
Create a segment.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
color- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The color of the segment using a hex code.
Use GET List all segment colors. to view available colors.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.payload
name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Native field; use the reviewed provider reference.
color- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The color of the segment using a hex code.
Use GET List all segment colors. to view available colors.
list_segment_colors
List all segment colors.
Kind: Read. Native account permissions and local semantics still apply.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
get_segment
Retrieve a segment.
Kind: Read. Native account permissions and local semantics still apply.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
list_subscribers
List all subscribers.
Kind: Read. Native account permissions and local semantics still apply.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
status- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Optional. The subscriber's status.
active: The subscriber is currently active to receive marketing emails.unsubscribed: The subscriber has opted out of marketing emails.unconfirmed: The subscriber is pending for double opt-in confirmation.bounced: The subscriber's address is undeliverable due to a hard bounce.complained: The subscriber marked an email as spam.cleaned: The subscriber was cleaned, learn more here.archived: The subscriber was archived. enum:["active", "unsubscribed", "unconfirmed", "bounced", "complained", "cleaned", "archived"].
segment_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Optional. The segment's id. When included, returns only subscribers who were added to the given segment.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
create_or_update_subscriber
Create or update a subscriber.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
id. Eitheremailoridmust be included.
email- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
email. Eitheremailoridmust be included.
first_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's first name.
last_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's last name.
custom_fields- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- An object containing custom field data. E.g. ``
"favorite_color": "Lavender"``.
segment_ids- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- The segments this subscriber will be added to. Cap at
50.
double_optin- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Whether or not to require the subscriber to confirm subscription via email. This option is only available to set with new subscriber creation. Default to
falseif not indicated.
optin_ip- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- IP address from which the subscriber confirmed their opt-in.
optin_timestamp- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The date and time the subscribers confirmed their opt-in in ISO 8601 format. E.g.
2023-01-02T15:04:05.999Z.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.custom_fields
input.custom_fields.{key}
Native JSON value; inspect the full schema for validation.
input.segment_ids
input.segment_ids[]
Native JSON value; inspect the full schema for validation.
input.payload
id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
id. Eitheremailoridmust be included.
email- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
email. Eitheremailoridmust be included.
first_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's first name.
last_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's last name.
custom_fields- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- An object containing custom field data. E.g. ``
"favorite_color": "Lavender"``.
segment_ids- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- The segments this subscriber will be added to. Cap at
50.
double_optin- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Whether or not to require the subscriber to confirm subscription via email. This option is only available to set with new subscriber creation. Default to
falseif not indicated.
optin_ip- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- IP address from which the subscriber confirmed their opt-in.
optin_timestamp- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The date and time the subscribers confirmed their opt-in in ISO 8601 format. E.g.
2023-01-02T15:04:05.999Z.
input.payload.custom_fields
input.payload.custom_fields.{key}
Native JSON value; inspect the full schema for validation.
input.payload.segment_ids
input.payload.segment_ids[]
Native JSON value; inspect the full schema for validation.
batch_create_or_update_subscribers
Create or update up to 50 subscribers in a single request.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
subscribers- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- List of subscribers to create or update. Maximum 50 items.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.subscribers
input.subscribers[]
id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
id. Eitheremailoridmust be included.
email- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
email. Eitheremailoridmust be included.
first_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's first name.
last_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's last name.
custom_fields- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- An object containing custom field data. E.g. ``
"favorite_color": "Lavender"``.
segment_ids- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- The segments this subscriber will be added to. Cap at
50.
double_optin- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Whether or not to require the subscriber to confirm subscription via email. This option is only available to set with new subscriber creation. Default to
falseif not indicated.
optin_ip- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- IP address from which the subscriber confirmed their opt-in.
optin_timestamp- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The date and time the subscribers confirmed their opt-in in ISO 8601 format. E.g.
2023-01-02T15:04:05.999Z.
input.subscribers[].custom_fields
input.subscribers[].custom_fields.{key}
Native JSON value; inspect the full schema for validation.
input.subscribers[].segment_ids
input.subscribers[].segment_ids[]
Native JSON value; inspect the full schema for validation.
input.payload
subscribers- Required
- Yes
- Type
- array
- Details
- List of subscribers to create or update. Maximum 50 items.
input.payload.subscribers
input.payload.subscribers[]
id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
id. Eitheremailoridmust be included.
email- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
email. Eitheremailoridmust be included.
first_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's first name.
last_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's last name.
custom_fields- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- An object containing custom field data. E.g. ``
"favorite_color": "Lavender"``.
segment_ids- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- The segments this subscriber will be added to. Cap at
50.
double_optin- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Whether or not to require the subscriber to confirm subscription via email. This option is only available to set with new subscriber creation. Default to
falseif not indicated.
optin_ip- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- IP address from which the subscriber confirmed their opt-in.
optin_timestamp- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The date and time the subscribers confirmed their opt-in in ISO 8601 format. E.g.
2023-01-02T15:04:05.999Z.
input.payload.subscribers[].custom_fields
input.payload.subscribers[].custom_fields.{key}
Native JSON value; inspect the full schema for validation.
input.payload.subscribers[].segment_ids
input.payload.subscribers[].segment_ids[]
Native JSON value; inspect the full schema for validation.
get_subscriber
Retrieve a subscriber.
Kind: Read. Native account permissions and local semantics still apply.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
remove_subscriber_from_segments
Remove the subscriber from segments.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
segment_ids- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- An array of identifiers of the segments.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.segment_ids
input.segment_ids[]
Native JSON value; inspect the full schema for validation.
input.payload
segment_ids- Required
- Yes
- Type
- array
- Details
- An array of identifiers of the segments.
input.payload.segment_ids
input.payload.segment_ids[]
Native JSON value; inspect the full schema for validation.
add_subscriber_to_segments
Add the subscriber to segments.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
segment_ids- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- An array of identifiers of the segments.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.segment_ids
input.segment_ids[]
Native JSON value; inspect the full schema for validation.
input.payload
segment_ids- Required
- Yes
- Type
- array
- Details
- An array of identifiers of the segments.
input.payload.segment_ids
input.payload.segment_ids[]
Native JSON value; inspect the full schema for validation.
unsubscribe
Unsubscribe from all lists.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
list_webhooks
List all webhooks.
Kind: Read. Native account permissions and local semantics still apply.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
create_webhook
Create a webhook.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The webhook name.
post_url- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The url that the webhook will post to.
events- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- An array specifying which events are enabled for webhook notifications.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.events
input.events[]
Native JSON value; inspect the full schema for validation.
input.payload
name- Required
- Yes
- Type
- string
- Details
- The webhook name.
post_url- Required
- Yes
- Type
- string
- Details
- The url that the webhook will post to.
events- Required
- Yes
- Type
- array
- Details
- An array specifying which events are enabled for webhook notifications.
input.payload.events
input.payload.events[]
Native JSON value; inspect the full schema for validation.
delete_webhook
Delete a webhook.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
get_webhook
Retrieve a webhook.
Kind: Read. Native account permissions and local semantics still apply.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
update_webhook
Update a webhook.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The webhook name.
post_url- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The url that the webhook will post to.
events- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- An array specifying which events are enabled for webhook notifications.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.events
input.events[]
Native JSON value; inspect the full schema for validation.
input.payload
name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The webhook name.
post_url- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The url that the webhook will post to.
events- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- An array specifying which events are enabled for webhook notifications.
input.payload.events
input.payload.events[]
Native JSON value; inspect the full schema for validation.
list_workflows
List workflows.
Kind: Read. Native account permissions and local semantics still apply.
statuses- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- filter by workflow statuses e.g. statuses=active,paused. Default is all statuses
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- Default = 1 minimum:
1. maximum:9007199254740991. format:"int64".
perPage- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- Default = 10 Local positive integer validation; perPage has a local 100-item cap. minimum:
1. maximum:100. format:"int64".
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
input.statuses
input.statuses[]
Native JSON value; inspect the full schema for validation.
add_subscriber_to_workflow
<br><b>Notes:</b> <ul> <li>In order for a subscriber to be added to a workflow subsequent times, (1) the subscriber has to have already completed the workflow, i.e. they cannot currently be active in the workflow, and (2) the "Allow repeat subscribers" setting for the workflow must be toggled on.</li> <li>Subscribers cannot be added to abandoned cart workflows using this endpoint.</li> </ul>
Kind: Confirmed operation. Native account permissions and local semantics still apply.
workflow_id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
idis required ifemailis not present
email- Required
- No; body/guard requirements still apply
- Type
- string
- Details
emailis required ifidis not present
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
payload- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- Complete native JSON body; do not mix with body flags or payload_file. Arrays use repeated JSON object flags or a whole native array in a private file.
payload_file- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Absolute regular non-symlink JSON body file, at most 1 MiB. Cannot mix with payload/body flags. minLength:
1.
input.payload
id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
idis required ifemailis not present
email- Required
- No; body/guard requirements still apply
- Type
- string
- Details
emailis required ifidis not present
remove_subscriber_from_workflow
Remove a subscriber from workflow.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
workflow_id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Must be true for the requested mutation or exclusive private output file.
list_accounts
Local profile labels/default/auth method only. No keys, token paths, provider identity or network request.
Kind: Read. Native account permissions and local semantics still apply.
Native JSON value; inspect the full schema for validation.
get_operation_schema
Local reviewed method/path/query/body schema and provenance for one native tool. No credentials or provider request.
Kind: Read. Native account permissions and local semantics still apply.
operation- Required
- Yes
- Type
- string
- Details
- Exact native tool name, e.g. batch_create_or_update_subscribers or publish_studio_email. enum:
["list_campaigns", "publish_canva_email", "get_canva_design_state", "publish_studio_email", "list_custom_fields", "create_custom_field", "list_all_custom_fields", "list_segments", "create_segment", "list_segment_colors", "get_segment", "list_subscribers", "create_or_update_subscriber", "batch_create_or_update_subscribers", "get_subscriber", "remove_subscriber_from_segments", "add_subscriber_to_segments", "unsubscribe", "list_webhooks", "create_webhook", "delete_webhook", "get_webhook", "update_webhook", "list_workflows", "add_subscriber_to_workflow", "remove_subscriber_from_workflow"].
get_oauth_userinfo
One fixed UserInfo GET for an explicitly selected externally minted OAuth access token. API keys refuse; no refresh, OAuth login or fallback.
Kind: Read. Native account permissions and local semantics still apply.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact selected private account profile; binds label, not key ownership.
preview_subscriber_batch
Local validation and SHA-256 of exact ordered subscriber/segment/workflow/custom-field work, selected profile label and reviewed schema. No provider reads, key load, identity check, price or rollback guarantee.
Kind: Read. Native account permissions and local semantics still apply.
tasks- Required
- Yes
- Type
- array
- Details
- One to twenty exact ordered supported subscriber/segment/workflow/custom-field operations. Native batch upserts may affect up to50 subscribers per task; not a20-person budget. minItems:
1. maxItems:20.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact selected private account profile; binds label, not key ownership.
input.tasks
input.tasks[]
tool- Required
- Yes
- Type
- string
- Details
- Native field; use the reviewed provider reference. enum:
["create_custom_field", "create_segment", "create_or_update_subscriber", "batch_create_or_update_subscribers", "remove_subscriber_from_segments", "add_subscriber_to_segments", "unsubscribe", "add_subscriber_to_workflow", "remove_subscriber_from_workflow"].
arguments- Required
- Yes
- Type
- object
- Details
- Actual native tool arguments without account, confirm, payload_file or output_file.
submit_subscriber_batch
Confirmed one-to-twenty ordered subscriber/segment/workflow/custom-field tasks. Prevalidate all and verify exact hash before first request. Stop on first failure with known results/failed index/unattempted indices; no retries, rollback or implicit continuation.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
tasks- Required
- Yes
- Type
- array
- Details
- One to twenty exact ordered supported subscriber/segment/workflow/custom-field operations. Native batch upserts may affect up to50 subscribers per task; not a20-person budget. minItems:
1. maxItems:20.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact selected private account profile; binds label, not key ownership.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Explicit approval for this exact requested ordered batch.
review_sha256- Required
- Yes
- Type
- string
- Details
- Exact preview_subscriber_batch hash for identical requests, profile label, schema and order. pattern:
"^[a-f0-9]{64}$".
input.tasks
input.tasks[]
tool- Required
- Yes
- Type
- string
- Details
- Native field; use the reviewed provider reference. enum:
["create_custom_field", "create_segment", "create_or_update_subscriber", "batch_create_or_update_subscribers", "remove_subscriber_from_segments", "add_subscriber_to_segments", "unsubscribe", "add_subscriber_to_workflow", "remove_subscriber_from_workflow"].
arguments- Required
- Yes
- Type
- object
- Details
- Actual native tool arguments without account, confirm, payload_file or output_file.
save_subscriber_page
Confirmed one-page GET saved only to an exclusive new0600 JSON file. No CSV/cohort export, all-pages loop, overwrite, automatic upload or browser preview.
Kind: Confirmed operation. Native account permissions and local semantics still apply.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
status- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Optional. The subscriber's status.
active: The subscriber is currently active to receive marketing emails.unsubscribed: The subscriber has opted out of marketing emails.unconfirmed: The subscriber is pending for double opt-in confirmation.bounced: The subscriber's address is undeliverable due to a hard bounce.complained: The subscriber marked an email as spam.cleaned: The subscriber was cleaned, learn more here.archived: The subscriber was archived. enum:["active", "unsubscribed", "unconfirmed", "bounced", "complained", "cleaned", "archived"].
segment_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Optional. The segment's id. When included, returns only subscribers who were added to the given segment.
account- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact configured private account profile label; not a tenant or provider account ID.
confirm- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Explicit approval for this exact requested ordered batch.
output_file- Required
- Yes
- Type
- string
- Details
- Absolute new file in an existing private directory. Restrict Windows ACLs separately. minLength:
1.
##### Native list_campaigns: GET /campaigns
List campaigns.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
Search- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter.
OrderBy- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter.
Sort- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter.
Status- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Exact native query parameter. enum:
["draft", "pending", "scheduled", "composing", "sending", "done", "failed"].
SharedAsTemplate- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Exact native query parameter.
No JSON body.
##### Native publish_canva_email: POST /campaigns/canva
Publish a Canva email design as a draft campaign.
Native JSON value; inspect the full schema for validation.
Native body: | Argument | Required | Type | Details |
title- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- Native field; use the reviewed provider reference.
design_token- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- Native field; use the reviewed provider reference.
page_id- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- Native field; use the reviewed provider reference.
campaign_id- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- Native field; use the reviewed provider reference.
##### Native get_canva_design_state: GET /campaigns/canva/design-state
Get the latest Canva design state for auto-selecting campaigns.
Native JSON value; inspect the full schema for validation.
No JSON body.
##### Native publish_studio_email: POST /campaigns/studio
Publish a Studio email export as a draft campaign.
Native JSON value; inspect the full schema for validation.
Native body: | Argument | Required | Type | Details |
title- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- Native field; use the reviewed provider reference.
campaign_id- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- Native field; use the reviewed provider reference.
asset_id- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- Native field; use the reviewed provider reference.
##### Native list_custom_fields: GET /custom-fields
List all custom fields (pagination).
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
No JSON body.
##### Native create_custom_field: POST /custom-fields
Create a custom field.
Native JSON value; inspect the full schema for validation.
Native body: | Argument | Required | Type | Details |
##### Native list_all_custom_fields: GET /custom-fields/all
List all custom fields.
Native JSON value; inspect the full schema for validation.
No JSON body.
##### Native list_segments: GET /segments
List all segments.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
No JSON body.
##### Native create_segment: POST /segments
Create a segment.
Native JSON value; inspect the full schema for validation.
Native body: | Argument | Required | Type | Details |
color- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- Native field; use the reviewed provider reference.
- The color of the segment using a hex code.
Use GET List all segment colors. to view available colors.
##### Native list_segment_colors: GET /segments/colors
List all segment colors.
Native JSON value; inspect the full schema for validation.
No JSON body.
##### Native get_segment: GET /segments/{id}
Retrieve a segment.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
No JSON body.
##### Native list_subscribers: GET /subscribers
List all subscribers.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
status- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Optional. The subscriber's status.
active: The subscriber is currently active to receive marketing emails.unsubscribed: The subscriber has opted out of marketing emails.unconfirmed: The subscriber is pending for double opt-in confirmation.bounced: The subscriber's address is undeliverable due to a hard bounce.complained: The subscriber marked an email as spam.cleaned: The subscriber was cleaned, learn more here.archived: The subscriber was archived. enum:["active", "unsubscribed", "unconfirmed", "bounced", "complained", "cleaned", "archived"].
segment_id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- Optional. The segment's id. When included, returns only subscribers who were added to the given segment.
No JSON body.
##### Native create_or_update_subscriber: POST /subscribers
Create or update a subscriber.
Native JSON value; inspect the full schema for validation.
Native body: | Argument | Required | Type | Details |
email- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- The subscriber's `id`. Either `email` or `id` must be included.
- The subscriber's
email. Eitheremailoridmust be included.
first_name- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- The subscriber's `id`. Either `email` or `id` must be included.
- The subscriber's first name.
last_name- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- The subscriber's `id`. Either `email` or `id` must be included.
- The subscriber's last name.
custom_fields- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- object
- The subscriber's `id`. Either `email` or `id` must be included.
- An object containing custom field data. E.g. ``
"favorite_color": "Lavender"``.
segment_ids- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- array
- The subscriber's `id`. Either `email` or `id` must be included.
- The segments this subscriber will be added to. Cap at
50.
double_optin- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- boolean
- The subscriber's `id`. Either `email` or `id` must be included.
- Whether or not to require the subscriber to confirm subscription via email. This option is only available to set with new subscriber creation. Default to
falseif not indicated.
optin_ip- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- The subscriber's `id`. Either `email` or `id` must be included.
- IP address from which the subscriber confirmed their opt-in.
optin_timestamp- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- The subscriber's `id`. Either `email` or `id` must be included.
- The date and time the subscribers confirmed their opt-in in ISO 8601 format. E.g.
2023-01-02T15:04:05.999Z.
input.custom_fields
input.custom_fields.{key}
Native JSON value; inspect the full schema for validation.
input.segment_ids
input.segment_ids[]
Native JSON value; inspect the full schema for validation.
##### Native batch_create_or_update_subscribers: POST /subscribers/batch
Create or update up to 50 subscribers in a single request.
Native JSON value; inspect the full schema for validation.
Native body: | Argument | Required | Type | Details |
input.subscribers
input.subscribers[]
id- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
id. Eitheremailoridmust be included.
email- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's
email. Eitheremailoridmust be included.
first_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's first name.
last_name- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The subscriber's last name.
custom_fields- Required
- No; body/guard requirements still apply
- Type
- object
- Details
- An object containing custom field data. E.g. ``
"favorite_color": "Lavender"``.
segment_ids- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- The segments this subscriber will be added to. Cap at
50.
double_optin- Required
- No; body/guard requirements still apply
- Type
- boolean
- Details
- Whether or not to require the subscriber to confirm subscription via email. This option is only available to set with new subscriber creation. Default to
falseif not indicated.
optin_ip- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- IP address from which the subscriber confirmed their opt-in.
optin_timestamp- Required
- No; body/guard requirements still apply
- Type
- string
- Details
- The date and time the subscribers confirmed their opt-in in ISO 8601 format. E.g.
2023-01-02T15:04:05.999Z.
input.subscribers[].custom_fields
input.subscribers[].custom_fields.{key}
Native JSON value; inspect the full schema for validation.
input.subscribers[].segment_ids
input.subscribers[].segment_ids[]
Native JSON value; inspect the full schema for validation.
##### Native get_subscriber: GET /subscribers/{id_or_email}
Retrieve a subscriber.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
No JSON body.
##### Native remove_subscriber_from_segments: DELETE /subscribers/{id_or_email}/segments
Remove the subscriber from segments.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
Native body: | Argument | Required | Type | Details |
input.segment_ids
input.segment_ids[]
Native JSON value; inspect the full schema for validation.
##### Native add_subscriber_to_segments: POST /subscribers/{id_or_email}/segments
Add the subscriber to segments.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
Native body: | Argument | Required | Type | Details |
input.segment_ids
input.segment_ids[]
Native JSON value; inspect the full schema for validation.
##### Native unsubscribe: POST /subscribers/{id_or_email}/unsubscribe
Unsubscribe from all lists.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
No JSON body.
##### Native list_webhooks: GET /webhooks
List all webhooks.
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The page number. Defaults to 1. minimum:
1. maximum:9007199254740991. format:"int64".
per_page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- The number of records to be returned on each page. Defaults to 20. Maximum 100. minimum:
1. maximum:100. format:"int64".
No JSON body.
##### Native create_webhook: POST /webhooks
Create a webhook.
Native JSON value; inspect the full schema for validation.
Native body: | Argument | Required | Type | Details |
post_url- Yes
- Yes
- string
- string
- The webhook name.
- The url that the webhook will post to.
events- Yes
- Yes
- string
- array
- The webhook name.
- An array specifying which events are enabled for webhook notifications.
input.events
input.events[]
Native JSON value; inspect the full schema for validation.
##### Native delete_webhook: DELETE /webhooks/{id}
Delete a webhook.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
No JSON body.
##### Native get_webhook: GET /webhooks/{id}
Retrieve a webhook.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
No JSON body.
##### Native update_webhook: PUT /webhooks/{id}
Update a webhook.
id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
Native body: | Argument | Required | Type | Details |
post_url- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- The webhook name.
- The url that the webhook will post to.
events- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- array
- The webhook name.
- An array specifying which events are enabled for webhook notifications.
input.events
input.events[]
Native JSON value; inspect the full schema for validation.
##### Native list_workflows: GET /workflows
List workflows.
statuses- Required
- No; body/guard requirements still apply
- Type
- array
- Details
- filter by workflow statuses e.g. statuses=active,paused. Default is all statuses
page- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- Default = 1 minimum:
1. maximum:9007199254740991. format:"int64".
perPage- Required
- No; body/guard requirements still apply
- Type
- integer
- Details
- Default = 10 Local positive integer validation; perPage has a local 100-item cap. minimum:
1. maximum:100. format:"int64".
input.statuses
input.statuses[]
Native JSON value; inspect the full schema for validation.
No JSON body.
##### Native add_subscriber_to_workflow: POST /workflows/{workflow_id}/subscribers
<br><b>Notes:</b> <ul> <li>In order for a subscriber to be added to a workflow subsequent times, (1) the subscriber has to have already completed the workflow, i.e. they cannot currently be active in the workflow, and (2) the "Allow repeat subscribers" setting for the workflow must be toggled on.</li> <li>Subscribers cannot be added to abandoned cart workflows using this endpoint.</li> </ul>
workflow_id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
Native body: | Argument | Required | Type | Details |
email- No; body/guard requirements still apply
- No; body/guard requirements still apply
- string
- string
- `id` is required if `email` is not present
emailis required ifidis not present
##### Native remove_subscriber_from_workflow: DELETE /workflows/{workflow_id}/subscribers/{id_or_email}
Remove a subscriber from workflow.
workflow_id- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
id_or_email- Required
- Yes
- Type
- string
- Details
- Exact native path parameter. minLength:
1.
No JSON body.
Complete client, OS and desktop setup
# Install Flodesk MCP Server & CLI
One npm package includes both binaries and all 32 tools. Requires Node.js 22 or newer for CLI/manual MCP installs. Discovery works before account authentication. Account operations need intended Flodesk account REST API access; provider account plans, key permissions and API quota apply.
- Program
- flodesk-cli
- Use
- Scripts and agents with a shell
- Program
- flodesk-mcp
- Use
- AI clients supporting stdio
- Program
- flodesk-2.0.1.mcpb
- Use
- Compatible Claude Desktop custom extensions
- Program
- https://flodesk.com/mcp
- Use
- Official remote provider-hosted access
Contents
Requirements · CLI · Private account setup · Claude Code · Codex · Claude Desktop · Cursor · VS Code and Copilot · Windsurf · Zed · Gemini CLI · Docker · Verify · Multiple accounts · Updates and removal · Troubleshooting · Development
Requirements
Install Node from nodejs.org. Open a new terminal and check node --version and npm --version. The desktop host needs a compatible Node runtime; dependencies are bundled. A GUI app may not inherit your terminal's environment. Check your account's current API access and quota with Flodesk instead of assuming npm installation provides it.
CLI
On macOS/Linux, use Terminal. On Windows, use PowerShell or Command Prompt:
npm install -g @thenavidm/flodesk-mcp-cli@latest
flodesk-cli --version
flodesk-cli
flodesk-cli list-subscribers --help
flodesk-cli schema create-or-update-subscriber
flodesk-cli loginIf PowerShell blocks npm.ps1, use npm.cmd or Command Prompt according to your policy. If a binary is missing, check npm prefix -g, ensure its executable directory is on PATH and open a new terminal. Avoid sudo as a workaround for PATH problems.
For one command without a global install:
npx -y --package @thenavidm/flodesk-mcp-cli@latest flodesk-cli toolsMake SKILL.md available in your agent's supported skill location. The installed file is <npm root -g>/@thenavidm/flodesk-mcp-cli/SKILL.md. npm does not automatically register client skills. Your agent should read the actual schema and use --agent/--select for compact output.
Private account setup
Private integration API key
- Sign into the intended Flodesk account. Open Account → Integrations → API, or the API key settings. Check which account owns the audience before creating/copying a key.
- Use a private integration API key for your own account. The native docs describe full API access; this package does not invent per-operation key scopes or guarantee provider read-only keys. Local read-only policy is a separate control.
- Save FLODESK_API_KEY only in private user/client environment settings, or use FLODESK_TOKEN_FILE as an absolute token-only file outside repositories. On macOS/Linux use a private 0700 directory and owner-private 0600 regular non-symlink file, at most 64 KiB. On Windows restrict file/parent ACLs to yourself; POSIX mode checks do not establish Windows ACLs.
- Run flodesk-cli doctor for local settings. Deliberately run doctor --network to read one subscriber page with per_page=1; output reports only count, not the subscriber record. That verifies one read, not account-owner identity, campaign/webhook access or all native permissions.
- Inspect exact native fields and IDs, then approve only requested work. Double opt-in, segment additions and workflow enrollment can trigger actual messages. Do not create subscribers, opt-ins, workflow entries, drafts or webhooks merely to test installation.
The API key is an HTTP Basic username, with an empty password. The client constructs Authorization: Basic base64(key:), sends a descriptive User-Agent and uses only the allowlisted https://api.flodesk.com origin. No API key goes into a URL, prompt, Git file or log. It refuses redirects and unknown routes.
Externally minted partner OAuth
Native partner OAuth requires a provider-approved integration with its own client ID/secret and redirect flow. This package accepts an externally minted FLODESK_ACCESS_TOKEN or named access_token profile as Authorization: Bearer. It does not register an app, start login, exchange authorization codes, refresh tokens or import official connector sessions.
Access tokens are documented as 24 hours; refresh tokens are single-use and rotate. Refreshing belongs to your approved private integration and must store its newly issued refresh token securely. This runtime never holds that client secret/refresh token. Restart after replacing its access token. get_oauth_userinfo makes only the fixed /oauth2/userinfo GET and refuses API-key profiles before any request.
For a token file containing an OAuth access token, set FLODESK_AUTH_TYPE=oauth for a direct profile, or auth_type:"oauth" in that named profile. File credentials otherwise default to API key. Never configure api_key and access_token together. A selected file overrides only its own profile's inline credential; profiles never inherit a global key/token or another account.
Several private accounts
FLODESK_ACCOUNTS is a private JSON array of unique {name,api_key,access_token,token_file,auth_type} entries. Choose exactly one credential type in each. FLODESK_DEFAULT_ACCOUNT and --account select exact labels. Labels and review hashes are not verified provider ownership. Token files cache until process restart. list_accounts returns only labels/default/auth type/credential source, without token paths or provider reads.
Official MCP connection
Flodesk already supplies its official MCP and setup help. Its production field reference currently lists 35 tools, including email/form/checkout/workflow analytics, cohort filters, subscriber actions, CSV export and bulk archive/unarchive/segment changes. Its previews issue single-use confirmation tokens expiring after 120 seconds. Those capabilities and safeguards already exist.
The September 11 help article describes an earlier24-tool/individual-action phase and says bulk work is upcoming; the current production catalog describes35 tools and bulk workflows. Treat that as documented source drift. Marketing's broad future-control examples do not establish current send/schedule support. This local public-REST package does not call private MCP-only analytics/cohort routes or accept the hosted connector's confirmation tokens.
Quotas and effects
The AGPL wrapper is free; Flodesk subscription/API eligibility and account policies remain separate. Native REST limits are 100 requests/minute normally and 20/minute for POST /subscribers/batch, up to 50 subscribers per request. X-Fd-RateLimit headers report remaining capacity. Our process spacing defaults 650 ms, plus a separate 3100 ms batch window. Other processes/apps share account quota; local pacing is not provider enforcement or a guaranteed distributed limiter.
No automatic retries, including reads,429,5xx, redirects or timeouts. A failed write can leave an unknown result, duplicate webhook/segment or triggered message. Inspect provider state before deliberately repeating. JSON requests cap 1 MiB and responses 5 MiB. Each native list returns one page with its own meta/page semantics, not an all-pages backup. Workflow statuses use native CSV and perPage; campaign query names retain native capitalization.
Canva and Studio publish draft campaign exports, not send/schedule emails. Subscriber upsert can create or update by id/email; up to50 segment IDs are supported. double_optin applies only to newly created subscribers and can send a confirmation message. Workflow re-entry needs prior completion and Allow repeat subscribers; abandoned-cart workflows cannot be enrolled through this route. Unsubscribe changes subscription state without pretending to delete the record. Removing segment membership is distinct and sends the required native DELETE JSON body.
Revocation and retained data
Revoke the intended key at Flodesk, replace private settings/files and restart. Revoke partner OAuth/official connector authorization separately. Package/client removal does not undo audience changes, sent opt-ins/workflow effects, drafts, webhooks or private audience-page files. Retain receipts and investigate unknown outcomes before explicitly requested cleanup.
export FLODESK_TOKEN_FILE='/absolute/private/flodesk.txt'
flodesk-cli doctor --networkAgent-guided installation
Help me install Flodesk MCP Server & CLI with INSTALL.md. Check Node and the binary, let me configure my account credentials privately, then run discovery and doctor --network. Do not change or mutate accounts during setup.
Codex
Codex is the current validation priority. Private token paths must exist in the process or remote environment where the server runs.
codex mcp add flodesk -- npx -y @thenavidm/flodesk-mcp-cli@latest
codex mcp listAccount credentials must reach the server through private environment settings. codex mcp add --env NAME=value stores values in your local config, so never commit that config or put secrets in a shared command. In TOML, the equivalent server is:
[mcp_servers.flodesk]
command = "npx"
args = ["-y", "@thenavidm/flodesk-mcp-cli@latest"]
env_vars = ["FLODESK_API_KEY", "FLODESK_ACCESS_TOKEN", "FLODESK_TOKEN_FILE", "FLODESK_AUTH_TYPE", "FLODESK_ACCOUNTS", "FLODESK_DEFAULT_ACCOUNT", "FLODESK_READ_ONLY", "FLODESK_ALLOW_DESTRUCTIVE"]env_vars forwards those names from the environment available to Codex. If that environment does not contain them, configure private env settings locally. Codex can also call the CLI directly with SKILL.md and --agent output.
Claude Code
For a user-scoped connection, after privately configuring credentials:
claude mcp add --scope user flodesk -- npx -y @thenavidm/flodesk-mcp-cli@latest
claude mcp listUse the client's private local environment settings for the account variable if they are not inherited. Claude's -e NAME=value registration option writes values into its config; only use it locally through your secret manager, with no shared command transcript. Never place credentials in a project .mcp.json. Reconnect and ask Claude to verify credentials.
Alternatively install the CLI, make SKILL.md available to Claude, and use shell commands. Registering both surfaces is optional.
Claude Desktop
Install the .mcpb extension
- Download
flodesk-2.0.1.mcpbfrom GitHub Releases. - In a supported Claude Desktop build, open Settings > Extensions > Advanced settings > Install Extension… and select it.
- Enter a private API key in the sensitive setting, or an absolute private token-file path. Leave the unused credential method empty. API-key requests use HTTP Basic with the key as username and an empty password. Externally minted OAuth access tokens use Bearer; select the matching auth type for a token file. Use the intended account API key; named profiles are configured separately in private client environments.
- Enable read-only if you want only the 16 read operations. Reconnect and ask for account verification.
The bundle includes production dependencies and no credentials. Use a regular private token-only file if you prefer file-based credentials. The manifest requires Node 22 or newer from a compatible host. Organization policy may restrict custom extensions. Manual bundle updates require installing the new version; no automatic directory updates are promised. GUI installation remains unverified separately from archive/protocol checks.
Manual config
Open Settings > Developer > Edit Config, or use your platform's config file:
| OS | Typical config path |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json |
| Linux | ~/.config/Claude/claude_desktop_config.json; confirm the location through Edit Config in your installed build |
{
"mcpServers": {
"flodesk": {
"command": "npx",
"args": ["-y", "@thenavidm/flodesk-mcp-cli@latest"],
"env": {
"FLODESK_API_KEY": "YOUR_PRIVATE_API_KEY",
"FLODESK_TOKEN_FILE": ""
}
}
}
}Replace the placeholders only in your private file. Merge the server entry into an existing mcpServers object instead of replacing other integrations. Fully quit and reopen Claude Desktop. Do not enable an extension and a manual entry with the same name; choose one route.
If a Windows launcher cannot execute npx directly, use "command": "cmd" with "args": ["/c", "npx", "-y", "@thenavidm/flodesk-mcp-cli@latest"]. An absolute node executable and installed dist/index.js path also avoids launcher/PATH problems.
Cursor
Use private user settings at ~/.cursor/mcp.json, or Settings > Tools & MCP. Cursor documents environment interpolation and envFile support.
{
"mcpServers": {
"flodesk": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/flodesk-mcp-cli@latest"],
"env": {
"FLODESK_API_KEY": "${env:FLODESK_API_KEY}",
"FLODESK_TOKEN_FILE": "${env:FLODESK_TOKEN_FILE}"
}
}
}
}The environment values must exist for the Cursor process. If you use envFile, keep that file private and outside version control. A project's .cursor/mcp.json must not contain actual credentials. Reconnect the server after saving.
VS Code and Copilot
Use MCP: Open User Configuration. VS Code uses servers and secure inputs, rather than a mcpServers root:
{
"inputs": [
{"type": "promptString", "id": "flodesk-api-token", "description": "Flodesk API key (leave empty for a private token file)", "password": true},
{"type": "promptString", "id": "flodesk-token-file", "description": "Optional private token-file path (leave empty for API key)"}
],
"servers": {
"flodesk": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@thenavidm/flodesk-mcp-cli@latest"],
"env": {
"FLODESK_API_KEY": "${input:flodesk-api-token}",
"FLODESK_TOKEN_FILE": "${input:flodesk-token-file}"
}
}
}
}Start Flodesk through the MCP controls, approve trust if prompted, and enter credentials in the private input prompts. Workspace .vscode/mcp.json may contain this placeholder-only structure, but never resolved secret values. Remote development runs the server in the selected remote environment, so local file paths refer to that environment.
Windsurf
Open Cascade's MCP settings or edit the private user file ~/.codeium/windsurf/mcp_config.json. Use the Claude Desktop manual mcpServers block above with your locally configured env values. See Windsurf's current MCP documentation. Restart or reconnect Flodesk in Cascade; project files must not contain secrets.
Zed
Open Settings > AI > MCP Servers > Add Server > Add Local Server, or your user settings file. Zed uses context_servers:
{
"context_servers": {
"flodesk": {
"command": "npx",
"args": ["-y", "@thenavidm/flodesk-mcp-cli@latest"],
"env": {
"FLODESK_API_KEY": "YOUR_PRIVATE_API_KEY",
"FLODESK_TOKEN_FILE": ""
}
}
}
}Enter actual values only in private user settings. Check the active-server indicator before prompting. Do not wrap command and args inside a nested command object from older Zed examples.
Gemini CLI
Merge the Claude Desktop manual mcpServers block into your private ~/.gemini/settings.json. Configure the private credential values locally, then restart Gemini CLI and inspect /mcp. See Gemini CLI's MCP configuration. Its project settings must not contain real credentials. You can instead use the CLI from an agent shell.
Other local stdio clients use the same command and arguments, adapted to their config format. A client that only accepts a remote MCP URL cannot connect directly: this package does not ship a public HTTP listener. ChatGPT's remote connector setup is not a substitute for local stdio installation.
Docker
Build locally from the reviewed source; no prebuilt registry image is claimed:
git clone https://github.com/thenavidm/flodesk-mcp-cli.git
cd flodesk-mcp-cli
docker build -t flodesk-mcp-cli .
docker run --rm -i -e FLODESK_API_KEY flodesk-mcp-cliCline and other local MCP clients
Use the client's Add MCP server flow with command npx, arguments -y and @thenavidm/flodesk-mcp-cli@latest, stdio transport, and private local FLODESK_API_KEY or FLODESK_TOKEN_FILE settings. UI names depend on the installed client. Reconnect and discover tools before an account call. Browser-only clients need a remote HTTPS connector; use Flodesk's official server rather than this local stdio command.
Verify
flodesk-cli --version
flodesk-cli tools
flodesk-cli list-accounts --agent
flodesk-cli doctor
flodesk-cli doctor --network
flodesk-cli list-subscribers --per-page 1 --agent --select meta,data.idThe release validates shared full/read-only discovery and native request fixtures. Actual authenticated provider reads/writes, desktop GUI installation and matched successful Codex task/token measurements require their own evidence. doctor without --network checks local configuration only. One successful subscriber read does not prove ownership or every permission; never trigger opt-ins/workflows to test installation.
Multiple accounts
Use FLODESK_ACCOUNTS only in private runtime settings. Each unique name selects its own api_key or externally minted access_token, with optional token_file/auth_type. Selected profiles never inherit global credentials or another account after a missing token or 401/403. Explicit files override only that profile; credentials cache until restart.
list_accounts shows safe labels/default/auth type/source. It does not authenticate or establish the key owner's identity. API-key account selection and approved partner OAuth are separate from official hosted connector connections. Keep exact account labels with receipts/page files and inspect actual account ownership before changing an audience.
flodesk-cli list-accounts --agent
flodesk-cli list-subscribers --account work --per-page 1 --agentUpdates and removal
Use npx -y @thenavidm/flodesk-mcp-cli@latest for fresh process launches and restart/reconnect existing clients. Global installs require npm update -g; versioned desktop bundles require a new bundle installation. Read major changes first and preserve intended account configuration.
Remove only the requested MCP registration, skill/global package or desktop extension. Revoke private keys/partner OAuth/official connector access separately, and review provider webhooks/workflows/private audience files. Uninstalling does not unsend opt-in/automation messages or undo subscriber/draft changes.
npm update -g @thenavidm/flodesk-mcp-cli
flodesk-cli --version
# Removal only when requested
codex mcp remove flodesk
npm uninstall -g @thenavidm/flodesk-mcp-cliTroubleshooting
| Symptom | Check and resolution |
|---|---|
| Node/binary missing | Node 22+ and npm executable PATH; reopen terminal, npm.cmd if Windows policy needs it. |
| Mixed key/token config | Choose one api_key or access_token per profile. |
| File treated as Basic | Explicit auth_type:oauth/FLODESK_AUTH_TYPE=oauth for a Bearer token file. |
| 401/403 | Check intended key/token/account access; expired OAuth requires private partner renewal and process restart. |
| 429 | Respect 100/minute standard and 20/minute native-batch limits; other clients share quota. |
| Empty upsert or workflow identity | Provide nonempty id/email and exact requested native fields. |
| Segment removal fails | Use actual id_or_email/segment_ids; required JSON body is sent on DELETE. |
| Native batch HTTP 200 failures | Inspect successes and failures individually, without replaying successes. |
| Workflow enrollment rejected | Check completed/repeat-subscriber setting and abandoned-cart restriction. |
| Review mismatch | Preview exact inputs/order/profile label/auth type/snapshot again. |
| Unknown write outcome | Inspect provider state before any explicit retry. |
| Existing page file | Choose a new absolute file; no overwrite. |
| Analytics/archive/export missing | Those are official MCP-only tools, outside current public REST. |
| Draft URL but no sent mail | Canva/Studio publication creates a draft; no send/schedule endpoint is provided. |
| GUI/remote environment differs | Configure private settings/files/Node in that actual runtime and restart. |
Development
git clone https://github.com/thenavidm/flodesk-mcp-cli.git
cd flodesk-mcp-cli
npm ci
npm run typecheck
npm run build
npm test
npm run check:counts
npm run build:mcpbSource mode: configure private env, then register node /absolute/path/flodesk-mcp-cli/dist/index.js as the MCP command. Build before registration and after source changes. No local credentials are packaged. CONTRIBUTING.md, SECURITY.md and THIRD_PARTY_NOTICES.md cover contributions, disclosures and licensing.
Desktop authentication options
The bundled settings accept an API key or externally minted OAuth access token, never both. A selected token file overrides only that credential. Leave token-file auth type blank for an API key; enter oauth when the file contains a Bearer token. Named profiles use manual private runtime settings; no partner registration/login/refresh or hosted-session import occurs. Restart after replacing settings.
Output, flags and exit codes
Native provider JSON/meta is preserved after recognized credential redaction. Audience records, draft HTML and emails can still contain private data. --select filters only the needed fields locally. save_subscriber_page writes one confirmed page exclusively into a private JSON file and returns saved-file metadata, not customer rows.
Native batch upserts can return HTTP 200 with successes and failures. Inspect both arrays; a 2xx transport status is not complete success. Workflow enrollment returns native acceptance/data; it does not prove messages completed. All requests happen once; provider state must resolve unknown outcomes before any repeat.
Use --payload or an absolute private --payload-file for full native bodies, mutually exclusive with flat body flags and each other. Primitive array flags repeat one value at a time; --subscribers and --tasks repeat individual JSON objects. The house bridge derives flag names from actual schema, including native campaign query capitalization and workflow perPage.
flodesk-cli list-subscribers --per-page 5 --agent --select meta,data.id
flodesk-cli list-workflows --help
flodesk-cli schema publish-studio-email| Flag | Behavior |
|---|---|
| --agent | Compact JSON/no input/color; never approval |
| --confirm | Explicit requested-operation approval |
| --account LABEL | Exact private key/token profile |
| --select a,b.c | Local field selection |
| --payload / --payload-file | Complete exclusive native body input |
| --subscribers JSON | Repeat native batch-upsert item objects |
| --tasks JSON | Repeat ordered local review objects |
| --review-sha256 HASH | Exact matching ordered preview hash |
| --output-file PATH | New exclusive private page file |
| Exit | Meaning |
|---|---|
| 0 | Handler/receipt success; still inspect partial native failures |
| 2 | Invalid arguments or refused/unapproved operation |
| 3 | Not found |
| 4 | Auth/permission |
| 5 | API/network/unknown write outcome |
| 7 | Provider rate limit |
| 10 | Missing/invalid private configuration |
Official and community comparisons
- Current reviewed evidence
- Production field reference 35 tools, format 3, catalog 7c6870e8b9c66a4d366fc4c0abc53504721dd7c85cf3de9e3c5a202ef50d05f0, checked 2026-10-03
- Capabilities and boundaries
- Analytics, campaign content/performance, audience engagement/cohort filters, forms/checkouts/workflows, CSV export and bulk archive/unarchive/segment actions. Previews already have exact compiled-filter bindings, single-use 120-second tokens and cohort-growth checks. Public docs count is not authenticated tools/list or a tested account outcome.
- Current reviewed evidence
- Updated September 11, 2026; earlier individual-action phase
- Capabilities and boundaries
- Documents OAuth connections and destructive-operation confirmation. It still says bulk actions are unavailable; current production catalog documents them. Read current field reference rather than using old absence as our advantage.
- Current reviewed evidence
- OpenAPI 3.0.3, API 1.0.0, 26 operations, 19 paths
- Capabilities and boundaries
- API keys or approved partner OAuth; subscriber batch upsert, native workflow enrollment/removal, custom fields, webhook CRUD and Canva/Studio draft publication. This public API does not expose the official MCP's analytics/cohort/export/archive routes.
- Current reviewed evidence
- Pinned main source, checked 2026-10-03
- Capabilities and boundaries
- The repository description advertises Rails, OAuth 2.1 and encrypted per-user keys, but this public main tree contains only a five-line Gemfile. No implemented tools/client/README are available at this revision, so advertised functionality is unverified; no runtime account test was run.
- Current reviewed evidence
- Pinned source checked 2026-10-03, package 0.0.0/private
- Capabilities and boundaries
- Its actual server declares Authless Calculator with only add and calculate. No Flodesk API client or subscriber workflow exists in this revision. No runtime deployment was tested.
- Current reviewed evidence
- Shared local stdio MCP, task CLI and versioned desktop bundle
- Capabilities and boundaries
- 32 tasks: 16 reads, 16 confirmed operations. All 26 public-v1 native routes, OAuth UserInfo, local profile/schema helpers, exact ordered subscriber review and exclusive private single-page files. Native REST draft/custom-field/webhook/workflow operations and repeatable terminal automation add useful scope. No hosted analytics/cohort filter engine, CSV export, native archive/unarchive, OAuth login/refresh or token-saving claim.
No official task CLI is identified in the reviewed vendor docs/current registry results. That is a scoped research finding, not proof that no CLI exists anywhere. Provider @flodesk/grain is a component/design package, not a task CLI. A command spelling or 32 versus 35 tools does not establish superiority.
Build criterion: useful repeatable terminal/local-stdio access to native public REST work absent from the current 35-tool hosted catalog, including draft exports, custom-field management, webhook CRUD, explicit workflow enrollment/removal and 50-subscriber upsert. Verified local guards and exact ordered request review support that companion. Official analytics, engagement, cohort counting and two-minute provider-side confirmation tokens remain strengths; our local preview is not an equivalent real-cohort count or replacement for their safeguards.
Versions and legacy migration
| Component | Reviewed version |
|---|---|
| Package/desktop manifest | 2.0.0 |
| Node runtime | >=22 |
| MCP SDK | 1.32.0 |
| Ajv / formats | 8.20.0 / 3.0.1 |
| TypeScript / Vitest | 7.0.2 / 5.0.3 |
| Desktop builder | 2.1.2 |
| Native API snapshot | OpenAPI 3.0.3/API1.0.0;26operations checked 2026-10-03 |
| Official MCP production catalog | Format 3; 35 listed tools, checked 2026-10-03 |
2.0.0 is a major refresh of the private 1.0 MCP. All 20legacy names remain. Added batch_create_or_update_subscribers, list_campaigns, publish_canva_email, get_canva_design_state, publish_studio_email and list_all_custom_fields. Legacy segment/workflow/webhook aliases keep their tool names but use exact current native fields: get_segment/get_webhook/delete_webhook/update_webhook use id, enrollment accepts id or email, webhook configuration uses post_url, workflows use perPage and statuses CSV. The old server omitted DELETE bodies and misnamed some fields; these are corrected rather than keeping broken requests.
Subscriber statuses now include unconfirmed/cleaned/archived; upserts accept native id/email, optin_ip/optin_timestamp and 50 segment IDs. Native upsert permits 50 subscribers and preserves partial successes/failures. All mutations/private-page files require approval and isolated credentials. Mixed private credential types fail instead of silently prioritizing Bearer/global values. All automatic/inherited auth fallbacks, source-saved credentials and thin clone-only setup are removed. The complete CLI/MCP/desktop/client framework, policy, current comparison and dated update history ships together.
Private legacy history/settings remain separate and are never imported into public history. See CHANGELOG.md, api-provenance.json and RELEASE-CHECKLIST.md.
Updates and removal
Use npx -y @thenavidm/flodesk-mcp-cli@latest for fresh process launches and restart/reconnect existing clients. Global installs require npm update -g; versioned desktop bundles require a new bundle installation. Read major changes first and preserve intended account configuration.
Remove only the requested MCP registration, skill/global package or desktop extension. Revoke private keys/partner OAuth/official connector access separately, and review provider webhooks/workflows/private audience files. Uninstalling does not unsend opt-in/automation messages or undo subscriber/draft changes.
npm update -g @thenavidm/flodesk-mcp-cli
flodesk-cli --version
# Removal only when requested
codex mcp remove flodesk
npm uninstall -g @thenavidm/flodesk-mcp-cliValidation and remaining evidence
Typecheck/build, 51 behavior/shared CLI tests, 18 actual CLI process checks and full/read-only discovery pass. Native request construction and guards were tested with intercepted fixtures without real audience reads or changes. Real Codex configuration parsing passed without changing persistent settings. Public source/tag CI, npm/desktop installation and CMS outcomes are recorded separately. Authenticated provider outcomes, desktop GUI installation, fresh matched Codex task/API-usage measurements and private site scene/shared-helper deployment remain pending.
More tools for your audience workflow
Connect the tools needed for your requested audience and business work.
Flodesk MCP Server & CLI FAQs
Official MCP differences, private API keys and OAuth tokens, native batches, draft exports, subscriber side effects and maintenance.
A shared 32-task CLI, local stdio MCP and versioned desktop extension for current public Flodesk REST operations, exact ordered reviews and private account files.
Yes.
Its current production field reference lists 35 tools with useful analytics, cohort filters, subscriber actions, CSV export and bulk controls.
This companion does not replace those capabilities.
Yes. preview_bulk_change/preview_segment_count bind real filtered audiences to single-use confirmation tokens that expire after 120 seconds.
Local exact REST request review has a different purpose.
Repeatable terminal/local-stdio workflows cover native custom fields, webhook CRUD, explicit workflow enrollment/removal,50-subscriber upsert and Canva/Studio draft exports absent from the reviewed hosted catalog.
Node 22+ CLI/local stdio on macOS, Windows and Linux.
INSTALL covers Codex, Claude Code/Desktop, Cursor, VS Code, Windsurf, Zed, Gemini, Cline and Docker; each runtime needs its private settings.
No.
Codex registers the same npm package directly.
Claude-specific benchmarks are optional and do not block Codex setup.
No.
Current native Canva/Studio publish routes create/update drafts.
No public send/schedule endpoint is invented or called.
Yes.
A new-subscriber double opt-in can send confirmation, and workflow/segment actions can trigger automation.
They require approval and are unsuitable installation smoke tests.
It accepts 1–50 explicit id/email records.
HTTP 200 may contain successes and failures; inspect each.
Native batch limits are separate from ordinary REST quota.
All 20remain, with major native argument corrections: id,post_url,id/email enrollment, perPage and statuses CSV.
The dropped DELETE segment-removal body is fixed.
Private integrations use the API key as a Basic username with an empty password.
Approved partner integrations may supply externally minted Bearer tokens.
Choose exactly one per profile; no OAuth login/refresh occurs here.
Yes.
Unique private profiles select only their own key/token/file, with exact labels and no global/cross-account fallback.
A label is not authenticated owner proof.
API key by default; set FLODESK_AUTH_TYPE=oauth or profile auth_type:"oauth" for a Bearer token file.
The file overrides only that selected profile and caches until restart.
Exact ordered inputs/requests, packaged schemas and selected profile label/auth type.
It reads no provider data and does not establish current cohort size, real ownership, final side effects or cryptographic human approval.
Execution stops with knownResults,failedIndex and unattemptedIndices.
Earlier changes/messages may persist; no retry, replay, rollback or automatic continuation occurs.
Yes.
FLODESK_READ_ONLY hides all 16confirmed operations and the shared guard directly refuses confirmed calls. --agent/--yes never approve work.
One selected subscriber page is written exclusively into a new private JSON file.
It is not a CSV/cohort/all-pages export; console output contains file metadata rather than customer records.
No.
Known credentials are redacted, but names/emails/HTML/native records can still be private.
Select only necessary fields and keep private files/parents/Windows ACLs restricted.
Fresh equivalent successful Codex task/API-usage measurements remain pending.
Tool counts, character estimates, fixtures or another service/client’s old metrics do not establish savings.
Reconnect/restart npm@latest processes; update global installs and desktop bundles explicitly.
Remove only the requested registration, then revoke exact keys/OAuth separately and review retained files/provider effects.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More MCP servers & CLIs
Related free tools
Free AI newsletterThe most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.













