# Customer.io MCP connector

Connect Customer.io to Elaichi and Claude, ChatGPT, Cursor, and the Elaichi Agent can look up people, segments, campaigns, and broadcasts, update attributes, and trigger messages, all inside the access of whoever signed in.

Source: https://elaichi.ai/connectors/customer-io/

## Facts

| | |
| --- | --- |
| Application | Customer.io |
| Category | Marketing Automation |
| AI tools | 8 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. Customer.io builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | customer.io/support |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Customer.io is connected

- Which people in the trial segment have not opened the onboarding campaign?
- Show me every broadcast sent to enterprise customers this month.
- Set the plan attribute to pro for dana@acme.com.

## Connect Customer.io in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Customer.io.
2. Optionally set Share with, then press Connect.
3. Approve it in Customer.io. Customer.io's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Customer.io tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Customer.io MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Customer.io MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Customer.io MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Customer.io to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Customer.io tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Customer.io through Elaichi

### Check a campaign before it goes out

Marketing. Ask which people a segment will reach and what each step of the campaign does, then fix the segment in Customer.io before the send.

### Catch a profile up after a conversation

Lifecycle. Update a person's attributes in Customer.io after a call so the right onboarding flow picks them up without anyone opening the app.

### See what a customer was sent

Support. Look up a person in Customer.io and see which campaigns and broadcasts reached them before you reply to their ticket.

### Record an event when something ships

Product. Track an event against a person in Customer.io so the welcome or upgrade sequence starts without a manual hand-off.

### Move a lead into the right segment

Sales. After a demo, update the lead's plan and stage attributes so Customer.io drops the nurture sequence and starts the trial one.

### Remove people who asked to be deleted

Operations. Find people who requested deletion and remove them from Customer.io, with every removal recorded in the audit log.

## Elaichi vs Zapier MCP vs Composio for Customer.io

All three can connect Customer.io to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Customer.io tools | Allow or restrict single Customer.io tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Customer.io call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Customer.io to Claude?

Connect Customer.io in Elaichi, which signs you in over OAuth with your own Customer.io login, so there is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude then sees Customer.io alongside anything else you have connected.

### Does Customer.io work with ChatGPT and Cursor as well as Claude?

Yes. Customer.io is connected once in Elaichi, and the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client, and the Elaichi Agent. You do not repeat the Customer.io sign-in for each client.

### What can an AI agent actually do with my Customer.io data?

An agent can look up a person in Customer.io and see their attributes, which segments they belong to, and which campaigns and broadcasts reached them. It can update attributes, record events, add people to segments, and trigger a message, and it can remove a person when asked. Short asks such as 'show me the trial segment' work better than long sentences.

### Does connecting Customer.io give the AI access to my whole workspace?

No. Everything runs under the Customer.io login of the person who connected, so the agent sees only the workspaces, segments, and campaigns that person can already see. Elaichi can narrow that further, for example to reading only, but it can never widen access beyond what Customer.io already grants.

### Can my team share one Customer.io connection?

Yes. One person connects Customer.io in Elaichi and shares the connection with a team, and nobody else handles a Customer.io credential. Each teammate still signs in to Elaichi as themselves, so the audit log names who looked up a person or sent a broadcast.

### Can I stop an agent from deleting or changing things in Customer.io?

Yes. Restrictions in Elaichi apply per action, so you can allow reading people and campaigns in Customer.io while blocking updates, sends, or deletions. A restricted action is never advertised to Claude or any other client, so no prompt can reach it.

### What happens to a Customer.io connection when someone leaves?

Offboarding someone in Elaichi ends their access to Customer.io at once, with no change needed in Customer.io itself. A connection shared with a team keeps working for everyone else. If you disconnect Customer.io in Elaichi, it disappears from Claude, ChatGPT, Cursor, and every other client in one step.

### Does the Customer.io MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Customer.io is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Customer.io?

Yes. Both let Claude, ChatGPT or Cursor use Customer.io. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Customer.io call.

### How is Elaichi different from Composio for Customer.io?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Customer.io: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 8 Customer.io tools

Every tool below is callable through https://api.elaichi.ai/mcp once Customer.io is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Cio prime** (Action). Loads the AI-ready reference for the Customer.io API. Your AI tool should call this at the start of a task.
- **Cio schema** (Action). Discovers API endpoints—list resources, find endpoints, and inspect parameters before making calls.
- **Cio read API** (Action). Makes authenticated GET requests. Use for listing, reading, and inspecting resources. Supports filtering, pagination, and dry-run previews.
- **Cio write API** (Action). Makes authenticated POST, PUT, and PATCH requests. Use for creating and editing resources. Supports dry-run previews.
- **Cio delete API** (Delete). Makes authenticated DELETE requests. Use for removing resources. Supports dry-run previews.
- **Cio skills list** (List). Lists available agent skills—task-specific instructions for multi-step operations like creating automations.
- **Cio skills read** (Action). Reads the full content of a specific skill so the AI tool can follow step-by-step workflows.
- **Cio auth status** (Action). Shows the current authentication state, including which workspaces the token can access.
