MCP server
Remote Model Context Protocol server for Peak Answer. OAuth 2.0, one brand per connection, seventeen tools.
Endpoint
https://peakanswer.com/api/mcpStreamable HTTP. There is nothing to install and no local process: the server runs on our infrastructure and a client connects to it over the URL.
Connecting
Claude Code
claude mcp add --transport http peak-answer https://peakanswer.com/api/mcpCursor, VS Code and other clients that read mcp.json
{
"mcpServers": {
"peak-answer": {
"url": "https://peakanswer.com/api/mcp"
}
}
}Claude.ai and ChatGPT: add the URL under Settings, Connectors. A step-by-step walkthrough with screenshots is at /tools/claude-mcp.
Authentication
OAuth 2.0 with dynamic client registration, discovered automatically. An unauthenticated request returns 401 carrying the discovery header:
WWW-Authenticate: Bearer resource_metadata="https://peakanswer.com/.well-known/oauth-protected-resource/api/mcp", scope="mcp"The client follows it, the user approves access in Peak Answer, and the client holds the token. Both discovery documents are public: /.well-known/oauth-protected-resource/api/mcp and /.well-known/oauth-authorization-server.
A client that would rather hold a static credential can send an API key from Peak Answer Settings as a bearer token instead. Keys are revocable from the same screen, and revoking one ends every session using it.
Scope of access
A connection is scoped to one brand, which is the website the account tracks. It cannot read another customer’s data, and it cannot reach brands in the same account that the authorising user does not have access to. Call my_brand to find out which domain a connection is pointed at rather than assuming.
Tools
Seventeen tools: nine that read and eight that change something. Every tool carries MCP behaviour annotations, so a client knows without being told which calls need the user’s permission first.
Reading
Annotated readOnlyHint: true. None of these writes to the account, publishes anything, or changes a setting.
| Tool | What it does | What it reads |
|---|---|---|
audit_site | Answer readiness, AI crawler access, robots.txt, sitemap, structured data, headings, meta description, readability and entities for one URL, in one call | The public URL you pass it |
generate | Produces an llms.txt, FAQPage JSON-LD, a content brief, a prompt set or semantic keywords | The public URL or topic you pass it |
geo_audit | Asks a model ten real buying questions about a category and reports who is named. Starts a background run and returns immediately; call again with the same domain to collect it | The public domain you pass it |
my_brand | Which domain this connection is scoped to | The connected account |
my_visibility | Measured visibility history for that brand, rather than a one-off check | The connected account |
my_questions | Tracked questions, with only_losing for the ones where a competitor is named and the brand is not | The connected account |
my_question_history | One tracked question over time | The connected account |
my_actions | The ranked backlog of recommended work for that brand | The connected account |
my_search_console | Search Console queries sitting near the top of page two | The connected account, and only if Search Console was connected by the customer |
audit_site, generate and geo_audit work on any public URL. The my_* tools read the customer’s own measured history and return nothing for an account with no tracking data yet.
Writing
Annotated readOnlyHint: false. These exist so the product can be run from the assistant the customer already has open, rather than read there and acted on somewhere else. Each is addressed by the words a person would use, not by an internal id, and an ambiguous reference is refused with the candidates listed rather than guessed at.
| Tool | What it changes | Annotations |
|---|---|---|
track_question | Starts tracking a buying question. Subject to the plan’s question limit | idempotent |
untrack_question | Stops tracking one. History is kept and it can be added back | destructive, idempotent |
mark_action_done | Marks a recommended action finished, which releases the next one | idempotent |
skip_action | Turns a recommended action down | destructive, idempotent |
add_competitor | Tracks a competitor, so answers are checked for whether it is named | idempotent |
remove_competitor | Stops tracking one, keeping the reason so discovery does not re-add it | destructive, idempotent |
save_context | Saves something about the business the crawl cannot see. The content engine reads it | not idempotent |
approve_article | Publishes a drafted article to the connected website. The only tool that changes anything outside Peak Answer | destructive, open world, not idempotent |
Plan limits are enforced on the write path exactly as they are on the screen: the same code runs for both, so an assistant cannot add a twenty-first question to a plan that allows twenty.
What the server cannot do
- It cannot change billing, plan, team membership, connected websites or credentials.
- It cannot delete anything. Removals deactivate and keep the history.
- It cannot read or change another brand’s data, or another customer’s.
- It cannot publish anywhere except a website the customer has already connected, and only through
approve_article, which is marked destructive so the client asks first. - It cannot reach a private URL. Every page it fetches, it fetches as a public visitor.
- It does not accept file uploads and returns no executable content.
Data handling
The API behind these tools is our own. A tool call reads the account’s existing data or fetches a public page; it does not send the conversation, the prompt, or anything else from the client to a third party beyond the providers already named in our privacy policy. Calls are logged with the account, the tool and the timestamp, for rate limiting and support, and no conversation content is stored.
Data returned to the client is the customer’s own measured data and the public pages they asked about. Nothing about other customers is ever returned, including in the cross-customer aggregates the product computes internally.
Limits
Calls count against the account’s plan in the same way work started in the app does. geo_audit is the expensive one: it asks a real model ten real questions, takes minutes, and is rate limited per brand. Call it once and collect the result later rather than polling. audit_site returns in seconds and is the right default.
Requirements
A Peak Answer account. MCP access is included on every plan, and the free tools at peakanswer.com/tools need no account at all. Sign up at peakanswer.com/signup.
Source and registry
The server.json this server is published with, and its connection instructions, are public at github.com/peakanswer/peak-answer-mcp. It is listed in the official MCP Registry as io.github.peakanswer/peak-answer.
Support
Email hello@peakanswer.com. Security reports go to the same address, and security.txt carries the current contact.