Assembly MCP Server

Assembly's Model Context Protocol (MCP)

The MCP server lets AI assistants like ChatGPT and Claude take action inside an Assembly workspace on behalf of a signed-in workspace admin. It exposes a curated set of tools that map directly to the public Assembly Platform API — so the same operations available to an API integration are available to an AI assistant, with the same authentication, the same permissions, and the same rate limits.

What the MCP server can do

Once connected, the assistant can read and write across these workspace areas:

The server does not expose billing configuration, workspace provisioning, role and permission editing, or anything outside the public Platform API surface.

Example prompts

Type Example prompt
Simple actions "Create a task assigned to myself called 'Quarterly review'. Include a summary of what we just talked about in the description."
"Create an invoice for John Doe for marketing services, $5,000 total, due in 30 days."
Bulk actions "Send a message to all clients who have the tier custom field set to 'Advanced'."
"Create a task 'Upload tax documents' for all clients who have plan custom field set to 'Starter'."
Analysis "How responsive has my team been in replying to clients this past month?"
"What are the most common pain points we've heard from clients this past week?"
Search "Can you figure out which clients I talked to about 'Form 941-X'?"
Audit "Show me everything that changed on the Acme Corp account in the last week and who did it."

Authentication and permissions

How you connect

  1. The MCP client (ChatGPT, Claude, etc.) opens the OAuth authorization URL on https://mcp.assembly.com.
  2. You are redirected to Assembly's branded login page and sign in with email and password, Google SSO, or TOTP-based MFA if enabled on your account.
  3. After you consent, an access token (about 1 hour) and a long-lived refresh token are issued. The MCP client stores them; Assembly stores only the encrypted refresh token server-side.

An access token auto-refreshes via the MCP client when it expires. The refresh token is long-lived and is revoked by your action. A connection that is created but never used is cleaned up after about 48 hours.

Who can connect

What data the AI can access

Request intent logging

Each tool call carries a short rationale — a one-sentence description of what you are trying to accomplish, generated by the assistant. Assembly logs the rationale alongside the tool name and workspace for product analytics and abuse monitoring. It is derived from your request; no additional data is collected. Access tokens and refresh tokens are never logged.

Tool safety

Every tool carries a safety hint derived from its underlying HTTP method: read-only actions (GET) are safe to call without confirmation, write actions (POST/PUT/PATCH) create or modify data, and delete actions are destructive. All workspace-data operations are scoped to your workspace.

Read-only (safe to call without confirmation)

Tool Actions
assembly_overview reference (returns Assembly product glossary)
dashboard_links reference (returns dashboard URL patterns)
list_workspaces list
workspaces retrieve
search search (across ~20 entity types; supports paging)
events list (audit log; filter by date, event type, actor)
internal_users list, retrieve
forms list, list_responses, retrieve
task_templates list, retrieve
contract_templates list, retrieve
invoice_templates list
subscription_templates list
payments list

Write (creates or modifies; confirm before calling)

Tool Actions Notes
invoices create, list, retrieve Created invoices are drafts unless otherwise specified.
subscriptions create, list, retrieve, cancel cancel is a non-destructive POST; the subscription record is preserved.
contracts create, list, retrieve
products create, list, retrieve
prices create, list, retrieve
custom_fields create, list, list_options
forms create, list, list_responses, retrieve
form_responses create
messages create, list Sends a message visible to the channel's members.
message_channels create, list, retrieve, unread unread returns unread counts.
file_channels create, list, retrieve
internal_users list, retrieve, update update changes a teammate's company access.
installs list, retrieve, list_connections, create_connection create_connection wires a marketplace app credential.

Destructive (irreversible; require explicit confirmation)

Tool Actions Recovery
clients create, update, replace, list, retrieve, delete delete is not recoverable from within Assembly.
companies create, update, list, retrieve, delete delete is not recoverable from within Assembly.
files create (upload), download, download_url, set_permissions, list, retrieve, delete delete is not recoverable from within Assembly.
tasks create, update, list, retrieve, delete delete is not recoverable from within Assembly.
task_comments list, retrieve, delete delete is not recoverable from within Assembly.
notes create, update, list, retrieve, delete delete is not recoverable from within Assembly.
notifications create, list, mark_read, mark_unread, delete delete is not recoverable; affects the in-product notification feed.

Privacy and data handling

See our full AI policy and privacy policy for details.

Data categories returned by tools:

What tools do not return:

How the assistant handles different requests

Known limits

Last updated July 17, 2026.