An open source Kit API v4 MCP server and task CLI with 85 tools, private account settings and a Claude Desktop extension.
This free Kit MCP server and CLI gives your AI real access to Kit API v4 account operations. It reads newsletters and email statistics, drafts broadcasts, manages subscribers and tags, edits sequences and snippets, and configures webhooks.
It's one install with 2 ways in. Claude, Codex, Cursor or any other MCP app calls its 85 tools for you, and the same tools work as a CLI that agents like Claude Code, Codex and OpenCode run, or that you type yourself.
Here's what the Kit MCP server and CLI is, how to set it up in each app, and every tool it has.
What is the Kit MCP server & CLI?
The Kit MCP server & CLI is a free, open source program that lets AI agents work with email newsletters, subscribers and automation through Kit’s documented API for you, in 2 ways. The MCP server is what an AI app like Claude, Codex or Cursor connects to, through MCP (Model Context Protocol), the open standard AI apps use to call outside tools.
You ask in plain language. Your AI picks the right tool, and the server makes the call directly to Kit’s API v4.
The CLI is the same program as commands. kit-cli list-broadcasts runs the same code your AI runs when you ask for your recent newsletters, whether an agent like Claude Code runs it or you do.
What can you ask it?
Once it's set up, you ask the way you'd ask an assistant. These are real prompts it handles:
Try askingShow my latest five broadcasts and their statistics.
Draft my next newsletter privately and leave it unscheduled.
Find this subscriber by exact email and show their tags.
Add this subscriber to the requested tag after I confirm.
List my sequences and their emails.
Show account growth without changing anything.
Inspect my signed webhook endpoints.
Kit already offers an official hosted account MCP with reads and writes across API v4. This package adds a standalone task CLI and local desktop/account setup. It does not claim more API coverage or measured token savings over Kit’s server.
How to install the Kit MCP server
Choose your AI client in the install box. The npm package contains the MCP and CLI binaries; the versioned desktop bundle is attached to the GitHub release. Keep account credentials in private local settings.
Watch out: Do not use a v3 API secret, browser cookies or your Kit password. npm installation does not supply Kit API access or perform OAuth consent.
Set up your private Kit account
Personal v4 API key
Open Kit's Developer settings, click Add a new key, name it and save the value privately when shown. Kit does not let you view that value again afterwards. Set KIT_API_KEY in your local shell or client settings. The server sends it in X-Kit-Api-Key, never a URL query string. Old v3 API secrets are not interchangeable.
Kit documents 120 requests over a rolling 60 seconds per API key and 600 for OAuth API access. The official hosted MCP separately documents 120/minute per token. This wrapper spaces calls per account by 550 ms for keys and 110 ms for OAuth. Other processes using the same credential also count against Kit's limits.
OAuth for full endpoint eligibility
Bulk and purchase endpoints in the tool table are marked OAuth-only. Create your own Kit app and enable API access, then implement the official OAuth authorization flow or Kit's Node example. Keep the app's secret on a private confidential backend. Use the callback URI exactly as registered, a cryptographically random state verified on callback, and HTTPS for a hosted callback.
The current authorization and token endpoints are https://api.kit.com/v4/oauth/authorize and https://api.kit.com/v4/oauth/token. There is no built-in OAuth consent service in this package. The old source's app.kit.com/oauth/token examples are obsolete. Follow Kit's current registered-app instructions; do not invent unsupported fine-grained OAuth scopes from operation-schema security labels.
A private token file can contain:
{
"access_token": "YOUR_OAUTH_ACCESS_TOKEN",
"refresh_token": "YOUR_OAUTH_REFRESH_TOKEN",
"client_id": "YOUR_OWN_KIT_APP_CLIENT_ID",
"client_secret": "YOUR_OWN_KIT_APP_CLIENT_SECRET",
"created_at": 1790899200,
"expires_in": 7200
}These are placeholders; use actual issued expiry metadata. Point KIT_TOKENS_FILE at an absolute private path outside the checkout. It must be a regular JSON file, at most 64 KB; symlinks are refused. Restrict access to your OS user. If expiry metadata is available, refresh happens one minute before expiry. Concurrent refreshes within the same process are deduplicated. Updated tokens are written atomically with mode 0600. On Windows, protect the enclosing folder using user-only ACLs; POSIX mode bits are not a complete Windows access policy.
Alternatively set KIT_ACCESS_TOKEN, KIT_REFRESH_TOKEN, KIT_CLIENT_ID and KIT_CLIENT_SECRET privately. Without a token file, refresh state lasts only in that process. Without refresh credentials, renew an expired access token yourself. An OAuth access token takes precedence over an API key for the selected account.
Check that it works
Local doctor checks configuration. The network check reads the default account without returning its private details or sending email.
npx -y @thenavidm/kit-mcp-cli@latest doctor --networkA successful account read does not prove every endpoint’s plan/OAuth permissions, template compatibility or actual email delivery. Live account testing of this version remains pending.
Use the Kit CLI
The CLI is the same 85 tools as commands. AI agents that run commands, like Claude Code, Codex and OpenCode, use it on their own, and you can type the same commands in a terminal or a script.
Every tool name becomes a command with dashes, so list_broadcasts runs as kit-cli list-broadcasts.
npm install -g @thenavidm/kit-mcp-cli@latest
kit-cli --version
kit-cli
kit-cli list-broadcasts --help
kit-cli schema create-broadcast
kit-cli list-broadcasts --per-page 5 --agent --select broadcasts.id,broadcasts.subject,pagination
kit-cli get-broadcast-stats --broadcast-id 123 --agentThe bare kit-cli lists every command, and kit-cli <command> --help shows what a command takes. The 40 audience, delivery, deletion and signing-secret operations require --confirm. --agent and --yes never authorize a write. Tagging or form/sequence enrollment can trigger existing automations.
These flags work on every command:
| Flag | What it does |
|---|---|
--json | Structured JSON |
--compact | One-line JSON |
--agent | Compact JSON, no prompts/color |
--select a,b.c | Keep selected fields |
--confirm | Authorize the user-requested guarded operation |
--account NAME | Select a configured private account |
--payload JSON | Complete body, including null/nested fields |
--payload-file PATH | Validated regular local JSON body, max 5 MB |
A script can branch on the exit code:
| Exit code | What it means |
|---|---|
| 0 | Success |
| 2 | Usage, validation or guard refusal |
| 3 | Not found |
| 4 | Authentication or endpoint permission |
| 5 | API/network error; inspect writes before repeating |
| 7 | Rate limit; wait rather than blindly retrying writes |
| 10 | Missing/invalid private configuration |
MCP server or CLI: which one?
Both surfaces call the same server tools. MCP connects them directly to an AI chat; the CLI gives an agent with a terminal the same operations as commands.
The token comparison is pending. We measure four real Claude Code usage differences: every tool loaded, default tool search, the skill read once, and its recurring description line. Commands, help, selected schemas, results and reasoning also contribute to complete task cost.
There is no measured efficiency percentage for this version yet. Standing context and the total cost of a successful task will be reported separately.
Draft, review and schedule
Draft privately, review, then schedule
A create call defaults to public:false and send_at:null. It creates a private unscheduled draft. It still requires confirmation because it changes account content and can accept delivery fields when explicitly supplied.
kit-cli list-email-templates --agent
kit-cli create-broadcast --subject "This week's creator notes" --content '<p>Write the actual newsletter here.</p>' --confirm --agent --select broadcast.id,broadcast.subject,broadcast.send_at
kit-cli get-broadcast --broadcast-id BROADCAST_ID_FROM_RESULT --agentPositive IDs are returned by Kit; replace illustrative markers with real IDs. For an existing draft, validate the intended audience and delivery time before the separate confirmed update:
kit-cli update-broadcast --broadcast-id 123 --payload-file /absolute/private/path/schedule.json --confirm --agentYour private schedule.json contains the ISO timestamp and the audience fields from the current schema, for example send_at with a timezone offset or UTC Z. published_at controls web publication metadata; it is not the email send time. Neither successful creation nor a local confirmation proves delivery. Read the broadcast and statistics afterwards.
Template HTML needs care
The API's content is HTML; it is not Kit's visual editor block tree. Preserve the full email wrapper and required Liquid unsubscribe/address markup when replacing content. Retrieve an existing example and inspect the selected template before updating. Do not replace a whole template with one paragraph if you need its existing branding and legal footer.
Kit's current OpenAPI prose contradicts itself around Starting point templates and required fields. This wrapper accepts a subject plus either content or email_template_id, allows nonempty partial broadcast updates, and exposes the documented allow_starting_point flag. These reviewed corrections are recorded with the snapshot. Starting point behavior remains unverified against a live account, so test with a private unscheduled draft and inspect it in Kit before any send.
Existing broadcasts and click reports
kit-cli list-broadcasts --per-page 10 --agent --select broadcasts.id,broadcasts.subject,pagination
kit-cli get-broadcast-stats --broadcast-id 123 --agent
kit-cli get-broadcast-clicks --broadcast-id 123 --agentThe client does not automatically retry POST, PUT, PATCH or DELETE requests. A timeout can have an unknown outcome. Check the existing draft or scheduled broadcast before repeating a write; sending twice cannot be undone by a retry wrapper.
Subscribers and sequences
Find an exact email or read a bounded list, then choose a requested audience change:
kit-cli search-subscribers --email-address reader@example.com --agent
kit-cli list-tags --agent
kit-cli tag-subscriber --tag-id 123 --email-address reader@example.com --confirm --agent
kit-cli list-subscriber-tags --subscriber-id 456 --agentThe .example address is illustrative. Do not add or tag real people without the requested account action. Tagging and form/sequence enrollment may trigger existing Kit automations.
filter_subscribers is a read-only POST with nested all/any filters. Use its current schema and a private JSON body; it is not a v3 page-number endpoint. search_subscribers is an exact-email compatibility alias, not a fuzzy search engine.
Sequences now have their own create/update/delete endpoints and individual email operations. Read their schemas and current delay units before using them. Sequence enrollment can deliver email through existing automation, so it is confirmed even if the API call itself merely adds a subscriber.
Custom field and tag creation are reversible configuration writes, so they do not require --confirm; they still disappear in read-only mode. Deletions, audience changes, snippets that can affect email and purchases are guarded. The tool table labels every operation.
Cursors and bulk work
Cursor pages
Kit v4 uses after, before, start_cursor and end_cursor, not old v3 numeric page arguments. Default per_page is 500, maximum 1000. Ask for a small page when you only need a sample:
kit-cli list-subscribers --per-page 25 --include-total-count --agent
kit-cli list-subscribers --after END_CURSOR_FROM_RESULT --per-page 25 --agent
kit-cli list-subscribers --all-pages --max-items 1000 --agentDo not supply both before and after. all_pages traverses forward and refuses before. It stops at max_items (default 1000, maximum 10000) or 100 pages, and refuses repeated cursors. It reduces each page size to the remaining cap so the returned end cursor does not skip unseen records. Aggregated output includes collected, pages, the last pagination object and truncated.
include_total_count must be requested where supported; total count can add API work. max_items without all_pages is a usage error. This is bounded retrieval, not a backup/export guarantee for an entire large account.
OAuth-only bulk
The full API snapshot supplies nested request schemas and endpoint-specific limits. Discover the body and put private batches outside the checkout:
kit-cli schema bulk-create-subscribers
kit-cli bulk-create-subscribers --payload-file /absolute/private/path/subscribers.json --confirm --agentSome bulk operations require a callback URL. Use HTTPS on a receiver you control and inspect its actual completion notification. The wrapper does not deploy or listen for callbacks. Split payloads according to Kit's current per-endpoint limits and the local 5 MB request cap. Do not retry an asynchronous submission merely because its completion has not arrived yet.
Signed webhook endpoints
The current signed webhook_endpoints family and older webhooks are separate APIs. Prefer signed endpoints for new setups. Discover the accepted event enum from the current schema:
kit-cli schema create-webhook-endpoint
kit-cli create-webhook-endpoint --url https://your-receiver.example/kit --events EVENT_FROM_SCHEMA --secret-name newsletter-hook --confirm --agentReplace both placeholders with your own endpoint and a supported event. Creation and secret rotation require a new secret_name. Before the remote call, the server reserves that filename exclusively under KIT_PRIVATE_DIR (default ~/.config/kit-mcp-cli/secrets) with mode 0600. Existing files are never overwritten.
Returned signing secrets are redacted from model/CLI output and saved to the private file. The result exposes secret_file, not the secret itself. Configure your own receiver's signature verification privately. The package does not provide a receiver or claim that the endpoint is reachable. Protect private folders with Windows ACLs where applicable.
When rotating, update and verify your receiver before revoking the previous secret. If Kit changed the endpoint but local secret storage failed, inspect the remote endpoint before attempting rotation again. Do not paste signing secrets in an AI chat or public issue.
Official and community alternatives
- Surface
- Remote MCP, Kit OAuth
- What the reviewed source establishes
- v4 account reads and writes; paid Creator/Creator Pro; 120 requests/min/token
- Tradeoff
- Hosted consent/setup; standalone task CLI not identified there
- Surface
- Documentation MCP
- What the reviewed source establishes
- Read documentation
- Tradeoff
- No account operations
- Surface
- Local stdio, CLI, desktop archive
- What the reviewed source establishes
- 83 pinned operations + 2 helpers, private account settings and guards
- Tradeoff
- You maintain local credentials; live writes pending
- Surface
- PHP/Laravel integration and Artisan commands
- What the reviewed source establishes
- Kit integration with framework commands
- Tradeoff
- Requires the Laravel application environment
- Surface
- Provider data-access CLI
- What the reviewed source establishes
- JDBC-backed data access from a CLI
- Tradeoff
- Different provider/license and data-oriented scope
COMPARISON.md records dated primary sources, scope and limitations. Counts are package discovery results, not evidence that the official server has fewer endpoints. No competitor latency, success rate or total token cost has been measured here.
Every Kit tool
All 85 tools, grouped the way the repo groups them. 38 only read, and 47 change something in your Kit account.
Account
get_account- What it does
- Get current account.
- Kind
- Reads
list_colors- What it does
- List colors.
- Kind
- Reads
update_colors- What it does
- Update colors.
- Kind
- Writes
get_creator_profile- What it does
- Get Creator Profile.
- Kind
- Reads
get_email_stats- What it does
- Get email stats.
- Kind
- Reads
get_growth_stats- What it does
- Get growth stats.
- Kind
- Reads
list_accounts- What it does
- List private account labels and configured auth methods, without returning credentials or token-file paths.
- Kind
- Reads
Newsletters and statistics
list_broadcasts- What it does
- List broadcasts.
- Kind
- Reads
create_broadcast- What it does
- Create a broadcast.
- Kind
- Asks first
list_broadcast_stats- What it does
- Get stats for a list of broadcasts.
- Kind
- Reads
get_broadcast_clicks- What it does
- Get link clicks for a broadcast.
- Kind
- Reads
get_broadcast_stats- What it does
- Get stats for a broadcast.
- Kind
- Reads
delete_broadcast- What it does
- Delete a broadcast.
- Kind
- Asks first
get_broadcast- What it does
- Get a broadcast.
- Kind
- Reads
update_broadcast- What it does
- Update a broadcast.
- Kind
- Asks first
Custom fields
bulk_create_custom_fields- What it does
- Bulk create custom fields.
- Kind
- Writes
bulk_update_subscriber_custom_field_values- What it does
- Bulk update subscriber custom field values.
- Kind
- Asks first
list_custom_fields- What it does
- List custom fields.
- Kind
- Reads
create_custom_field- What it does
- Create a custom field.
- Kind
- Writes
delete_custom_field- What it does
- Delete custom field.
- Kind
- Asks first
update_custom_field- What it does
- Update a custom field.
- Kind
- Writes
Email templates
list_email_templates- What it does
- List email templates.
- Kind
- Reads
Forms
bulk_add_subscribers_to_forms- What it does
- Bulk add subscribers to forms.
- Kind
- Asks first
list_forms- What it does
- List forms.
- Kind
- Reads
list_subscribers_for_form- What it does
- List subscribers for a form.
- Kind
- Reads
add_subscriber_to_form- What it does
- Add subscriber to form by email address.
- Kind
- Asks first
add_subscriber_to_form_by_id- What it does
- Add subscriber to form.
- Kind
- Asks first
Published posts
list_posts- What it does
- List posts.
- Kind
- Reads
get_post- What it does
- Get a post.
- Kind
- Reads
Purchases (OAuth)
list_purchases- What it does
- List purchases.
- Kind
- Reads
create_purchase- What it does
- Create a purchase.
- Kind
- Asks first
get_purchase- What it does
- Get a purchase.
- Kind
- Reads
Segments
list_segments- What it does
- List segments.
- Kind
- Reads
Sequence emails
list_sequence_emails- What it does
- List sequence emails.
- Kind
- Reads
create_sequence_email- What it does
- Create a sequence email.
- Kind
- Asks first
delete_sequence_email- What it does
- Delete a sequence email.
- Kind
- Asks first
get_sequence_email- What it does
- Get a sequence email.
- Kind
- Reads
update_sequence_email- What it does
- Update a sequence email.
- Kind
- Asks first
Sequences
list_sequences- What it does
- List sequences.
- Kind
- Reads
create_sequence- What it does
- Create a sequence.
- Kind
- Asks first
delete_sequence- What it does
- Delete a sequence.
- Kind
- Asks first
get_sequence- What it does
- Get a sequence.
- Kind
- Reads
update_sequence- What it does
- Update a sequence.
- Kind
- Asks first
list_subscribers_for_sequence- What it does
- List subscribers for a sequence.
- Kind
- Reads
add_subscriber_to_sequence- What it does
- Add subscriber to sequence by email address.
- Kind
- Asks first
add_subscriber_to_sequence_by_id- What it does
- Add subscriber to sequence.
- Kind
- Asks first
Reusable snippets
list_snippets- What it does
- List snippets.
- Kind
- Reads
create_snippet- What it does
- Create a snippet.
- Kind
- Asks first
get_snippet- What it does
- Get a snippet.
- Kind
- Reads
update_snippet- What it does
- Update a snippet.
- Kind
- Asks first
Subscribers
bulk_create_subscribers- What it does
- Bulk create subscribers.
- Kind
- Asks first
list_subscribers- What it does
- List subscribers.
- Kind
- Reads
create_subscriber- What it does
- Create a subscriber.
- Kind
- Asks first
filter_subscribers- What it does
- Filter subscribers by engagement, sign-up date, state, and tags.
- Kind
- Reads
get_subscriber- What it does
- Get a subscriber.
- Kind
- Reads
update_subscriber- What it does
- Update a subscriber.
- Kind
- Asks first
unsubscribe- What it does
- Unsubscribe subscriber.
- Kind
- Asks first
delete_subscriber_location- What it does
- Delete a subscriber's location.
- Kind
- Asks first
update_subscriber_location- What it does
- Update a subscriber's pinned location.
- Kind
- Asks first
pin_subscriber_location- What it does
- Pin a subscriber's location.
- Kind
- Asks first
get_subscriber_stats- What it does
- List stats for a subscriber.
- Kind
- Reads
list_subscriber_tags- What it does
- List tags for a subscriber.
- Kind
- Reads
search_subscribers- What it does
- Compatibility alias for list_subscribers with a required exact email_address filter.
- Kind
- Reads
Tags
bulk_delete_tags- What it does
- Bulk delete tags.
- Kind
- Asks first
bulk_create_tags- What it does
- Bulk create tags.
- Kind
- Writes
bulk_remove_tags_from_subscribers- What it does
- Bulk remove tags from subscribers.
- Kind
- Asks first
bulk_tag_subscribers- What it does
- Bulk tag subscribers.
- Kind
- Asks first
list_tags- What it does
- List tags.
- Kind
- Reads
create_tag- What it does
- Create a tag.
- Kind
- Writes
update_tag_name- What it does
- Update tag name.
- Kind
- Writes
untag_subscriber_by_email- What it does
- Remove tag from subscriber by email address.
- Kind
- Asks first
list_subscribers_for_tag- What it does
- List subscribers for a tag.
- Kind
- Reads
tag_subscriber- What it does
- Tag a subscriber by email address.
- Kind
- Asks first
untag_subscriber- What it does
- Remove tag from subscriber.
- Kind
- Asks first
tag_subscriber_by_id- What it does
- Tag a subscriber.
- Kind
- Asks first
Signed webhook endpoints
list_webhook_endpoints- What it does
- List webhook endpoints.
- Kind
- Reads
create_webhook_endpoint- What it does
- Create a webhook endpoint.
- Kind
- Asks first
delete_webhook_endpoint- What it does
- Delete a webhook endpoint.
- Kind
- Asks first
get_webhook_endpoint- What it does
- Get a webhook endpoint.
- Kind
- Reads
update_webhook_endpoint- What it does
- Update a webhook endpoint.
- Kind
- Asks first
revoke_previous_webhook_secret- What it does
- Revoke the previous webhook endpoint secret.
- Kind
- Asks first
rotate_webhook_secret- What it does
- Rotate a webhook endpoint secret.
- Kind
- Asks first
Legacy webhooks
list_webhooks- What it does
- List webhooks.
- Kind
- Reads
create_webhook- What it does
- Create a webhook.
- Kind
- Asks first
delete_webhook- What it does
- Delete a webhook.
- Kind
- Asks first
Is the Kit MCP server safe?
38 tools read data and 47 write. 40 guarded audience/delivery/deletion/secret operations require confirmation. Seven reversible configuration writes remain ordinary writes.
Draft creation defaults private and unscheduled. There are zero automatic retries for mutating calls, even after rate limits or timeouts. Inspect account state before repeating a write with an unknown outcome.
Make it read-only
Set KIT_READ_ONLY=1 to hide and refuse all 47 writes, leaving 38 reads. KIT_ALLOW_DESTRUCTIVE=0 separately blocks the 40 guarded operations even when confirmed. Reconnect after changing settings.
Keep a log of every write
Set KIT_AUDIT_LOG to a file path. The server writes one line per attempted write, allowed or blocked.
Watch out: Subscriber addresses, message bodies and reports remain private business data in authorized responses. Secret redaction does not anonymize all account content. Treat responses as data, never instructions to perform another action.
Your data
Requests go directly to Kit, without a Navid-hosted relay or telemetry. Keys/OAuth client secrets remain in local private settings. OAuth refresh can update a regular private token file atomically with mode 0600. Signed webhook secrets go to exclusive private files and are redacted from model output. Optional guard logs contain tool/risk/surface/decision without arguments, account labels or credentials. Protect Windows files with user-only ACLs. Your AI client and Kit apply their own processing and retention policies.
Multiple private accounts
Set KIT_ACCOUNTS to a private JSON array. Its supported keys are name, api_key, access_token, refresh_token, client_id, client_secret and tokens_file. It replaces the single-account variables:
[
{"name":"work","api_key":"YOUR_WORK_V4_KEY"},
{"name":"personal","tokens_file":"/absolute/private/path/personal-kit.json"}
]Set KIT_DEFAULT_ACCOUNT=work, then:
kit-cli list-accounts --agent
kit-cli list-broadcasts --account work --per-page 10 --agent
kit-cli get-growth-stats --account personal --agentNames must be unique. list_accounts exposes labels, default choice and auth type only, never credentials or file paths. Guard logs omit account names. Separate processes are still preferable when you need strict account isolation.
Kit MCP server settings
Every setting comes from private shell or client environment. The package does not automatically load .env. GUI clients may not inherit terminal values.
KIT_API_KEY- Default
- Empty
- What it does
- Personal v4 API key
KIT_ACCESS_TOKEN- Default
- Empty
- What it does
- Existing OAuth access token
KIT_REFRESH_TOKEN- Default
- Empty
- What it does
- OAuth refresh token
KIT_CLIENT_ID- Default
- Empty
- What it does
- Your authorized Kit app ID
KIT_CLIENT_SECRET- Default
- Empty
- What it does
- Your private confidential-app secret
KIT_TOKENS_FILE- Default
- Empty
- What it does
- Regular private OAuth JSON, max 64 KB
KIT_ACCOUNTS- Default
- Empty
- What it does
- Private JSON named accounts; replaces single-account settings
KIT_DEFAULT_ACCOUNT- Default
- First account
- What it does
- Default name from KIT_ACCOUNTS
KIT_READ_ONLY- Default
- 0
- What it does
- 1 or true hides and refuses all 47 writes
KIT_ALLOW_DESTRUCTIVE- Default
- 1
- What it does
- 0 or false blocks all 40 guarded operations even with confirm
KIT_AUDIT_LOG- Default
- None
- What it does
- Local attempted-write guard log, no request fields
KIT_PRIVATE_DIR- Default
- ~/.config/kit-mcp-cli/secrets
- What it does
- Private signing-secret folder
KIT_REQUEST_TIMEOUT_MS- Default
- 30000
- What it does
- Per-request deadline, integer 100–300000
KIT_MAX_RETRIES- Default
- 2
- What it does
- GET 429 retries only, integer 0–5
KIT_MIN_REQUEST_INTERVAL_MS- Default
- 0 = automatic
- What it does
- 0 chooses 550 ms keys / 110 ms OAuth; otherwise 1–10000 ms
Troubleshooting
Run the doctor first. It names the step that failed and the fix.
| What you see | What to do |
|---|---|
| No account / exit 10 | Set a private v4 key or regular OAuth token file |
| 401/403 | Check key version, OAuth expiry/revocation and endpoint eligibility |
| Tools missing | Check read-only mode and reconnect |
| Write refused | Check requested confirmation and destructive policy |
| Invalid/null body | Read schema; use payload/payload_file for JSON null and nested fields |
| 429 or write timeout | Inspect state; mutating calls never retry automatically |
| First page only | Follow end_cursor or bounded all_pages |
| Desktop archive blocked | Check host/runtime and organization custom-extension policy |
If the server doesn't show up in your app at all, run the command your app runs, in a terminal, and read the error.
Complete client and desktop setup
INSTALL.md covers macOS, Windows and Linux, Claude Code, Codex, desktop extension/manual config, Cursor, VS Code/Copilot, Windsurf, Zed, Gemini CLI, local Cline-style clients and Docker. It includes private credential routes, OAuth prerequisites, verification and removal. The local stdio server is not an HTTPS web connector; Kit’s official remote MCP is the suitable alternative for a remote-only client.
Let your AI guide setupHelp me install Kit MCP Server & CLI using INSTALL.md. Check Node and the binary, let me configure my account credentials privately, then run discovery and doctor --network. Do not send email or change subscribers during setup.
The npm package includes SKILL.md. Make it available through your agent’s supported skills location; installing npm does not automatically register it. Discovery and schemas work without credentials.
Desktop bundle
Download kit-2.0.2.mcpb from GitHub Releases and install it through Claude Desktop’s supported custom-extension settings. Enter a sensitive v4 key or an absolute private authorized OAuth token-file path. Enable read-only for the 38 reads. The archive includes production dependencies and no credentials. Its manifest requires a compatible Node runtime; a real GUI install remains a separate check. Manually installed archives need the new release installed to update them.
JSON bodies, null and output
Every command derives its arguments from the MCP schema. Use --help and schema before building a body. Path and query flags stay separate; body flags and payload/payload_file cannot be mixed. Array flags repeat once per item. JSON null must be passed inside payload, not as the shell string null.
kit-cli update-broadcast --broadcast-id 123 --payload '{"send_at":null}' --confirm --agent
kit-cli list-subscribers --include tags --include stats --per-page 10 --agentThese IDs are illustrative. --select shapes model output without changing what Kit sends to the server. Keep subscriber and email data out of public troubleshooting transcripts.
Versions, tags and updates
Version 2.0.2 has 85 tools: 83 operations from the pinned October 2 API snapshot, plus local account selection and an exact-email search alias. CHANGELOG.md records the major migration and dated validation. GitHub annotated tags, releases and desktop archives track the npm version. The repository uses 20 platform/surface topics and the package carries 30 relevant npm keywords.
Private legacy account instructions and history stay private. Browser login and designed broadcast/visual-automation duplication helpers are not included; use Kit UI for those workflows. New API sequence/email CRUD is separate from browser feature parity. Replace v3 credentials and numeric pages with v4 keys/OAuth and cursor pagination.
npm install -g @thenavidm/kit-mcp-cli@latest
kit-cli --versionRestart an @latest MCP connection to pick up updates. Pinned versions stay pinned. Remove CLI with npm uninstall -g @thenavidm/kit-mcp-cli and remove MCP/desktop entries separately. Uninstallation does not revoke Kit credentials, unschedule newsletters or remove local private token/secret files.
Validation and remaining evidence
Build, typecheck and 40 behavior/CLI checks passed. Real local stdio discovery confirms the counts and read-only behavior. The production audit has zero findings; SECURITY.md records a dev-only MCPB/node-forge advisory excluded from production artifacts. Release artifact/source/history checks are recorded in the repository as they complete.
Live authorized Kit calls, Starting point templates, actual desktop GUI installation and the fresh standing-context/matched-task token comparison remain pending. No fabricated token figures or superiority percentages are claimed.
More tools for your creator business
Use these alongside your requested newsletter work.
Kit MCP Server FAQs
Official MCP, CLI, desktop setup, privacy, drafts and delivery.
The wrapper is free AGPL software.
Your Kit subscription and API eligibility are separate.
The official Kit MCP is available on paid Creator and Creator Pro plans; consult Kit for your account’s API access.
Yes.
Its account server supports reads and writes across v4.
Its separate developer-docs MCP reads documentation and cannot act on your account.
Use it for standalone task commands, shell automation, private named-account settings, token-file refresh, bounded pagination or a local desktop archive.
Use Kit’s official server for Kit-managed hosted OAuth.
Neither is declared universally better.
No standalone email-account task CLI was identified in the official developer surfaces reviewed on 2026-10-02.
Framework-specific and data-provider CLIs exist; see COMPARISON.md.
Discovery shows them, but OAuth-only bulk and purchase endpoints reject API-key calls before HTTP.
The tool table marks them.
Use an authorized OAuth session for those operations.
No.
Configure it privately in your shell or client settings.
Help, discovery and schemas work without it.
No.
It explains first-time key/OAuth setup.
This package does not host a consent flow or copy your browser cookies.
Yes, through local stdio configuration or the custom .mcpb release.
GUI installation of this version remains a separate host check.
This local package does not expose an HTTPS connector.
Use Kit’s official remote MCP for a compatible web connector.
The wrapper defaults create to private and unscheduled.
If you explicitly pass send_at or publication fields, they can change that behavior.
All broadcast writes require confirmation; review in Kit before delivery.
No.
Use send_at for email delivery. published_at concerns web publication.
Use update_broadcast with a JSON body containing send_at:null, then inspect the broadcast.
A shell string null is not JSON null.
Inspect existing template HTML and required Liquid/footer markup before changing content.
The API is not a visual block editor.
Starting point schema conflicts remain live-account validation pending.
Yes, existing automations can react to tagging, form subscription or sequence enrollment.
Those operations require explicit confirmation here.
No.
Mutating requests are never automatically retried.
A timeout may have an unknown outcome; inspect the account first.
Yes.
Use a private KIT_ACCOUNTS array with unique names, then --account. list_accounts returns labels/auth methods without credentials.
Use after or bounded all_pages/max_items. v4 uses cursors.
Aggregate output exposes the last cursor and truncation; it is not an unlimited export.
New signed endpoint secrets go to exclusive owner-only files under KIT_PRIVATE_DIR and are redacted from returned tool data.
Configure your own receiver privately.
That has not been measured.
Model context, discovery, skill, command help, results, cache and task length all matter.
No invented savings are advertised.
Create new private settings with a v4 key or authorized OAuth token file.
Do not copy old personal SKILL content, cookies or source history into a public repo.
See the 2.0 migration notes.
Navid.me is reader-supported. When you buy through links on this site, I may earn an affiliate commission. Learn more.
More MCP servers & CLIs
Related free tools
Free AI newsletterThe most actionable AI newsletter for founders
Every week, get proven AI strategies, curated tools, and step-by-step systems to grow your audience, create better content, and build a profitable creator business.
No fluff, no filler, no BS. Just five minutes each week that might level up your online business and life.
P.S. Sign up now to get free access to my ultimate AI tools guide for creators.











