# MCP

Use HeyCrust tools through authenticated MCP without mixing scopes or side effects.

## Server and authentication

The HeyCrust MCP endpoint is `https://heycrust.com/api/mcp`. It accepts authenticated JSON-RPC messages over HTTP POST. The current transport is stateless. Use a bearer credential; keep it out of public source and URL query strings.

## Available tools

An owner workspace credential can access analytics, app setup, Flow and affiliate-report tools. An app-scoped affiliate credential exposes the partner-quality report only when its required read scopes are present. That credential does not expose general merchant analytics, app setup mutations or Flow actions.

## Start by discovering tools

Inspect the actual `tools/list` result for your credential. Analytics tools inspect existing data. Setup and Flow tools can change configuration, create drafts, activate automation or send a message, depending on the operation. Review the requested action and permissions before using them.

## App setup

Use `list_apps` to select the app, then `get_setup_guide` for its snippets and observed source status. The guide explains the identify-hook and token-free paths and their confirmation steps. Connection instructions do not replace verification of the app's actual received events and source coverage.

## Financial interpretation

The partner-quality report keeps currency-specific collection and accrued-commission figures separate and discloses coverage. It does not issue payouts, measure profit or establish causal revenue lift.

## Continue

Read [Developer integration](/docs/developers), [API reference](/docs/api) and [Help](/docs/help) for the corresponding interfaces and diagnostic steps.
