iubenda MCP server icon

iubenda

by iubenda

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Data & Research28 tools

Generate privacy policies, cookie banners and terms from an AI agent. 28 tools — 12 read, 11 write, 5 delete — with iubenda's own list matching Anthropic's exactly. OAuth with two scopes: mcp-read and mcp-write.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect iubenda via MCP

https://mcp-server.iubenda.com/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

iubenda Tools & Capabilities (28)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • Write and delete share one scope. mcp-write covers all 11 writes and all 5 deletes. No OAuth grant lets an agent draft a policy without also being able to delete a published one.
  • Two actions cannot be undone, and iubenda says so. Setting owner information through update_site finalizes any draft policy on that site. delete_site deletes the site and its documents with it.
  • The confirmation gate is a client behaviour, not a server boundary. iubenda states its assistant confirms before anything final or destructive. We could not read tool annotations — the endpoint returned 401 — so we cannot show whether that confirmation is carried by a destructiveHint the client enforces or is a property of how the model was prompted. Do not rely on it as a technical control, and do not blanket-auto-approve this connector's writes.
  • Whether deleting a cookie solution destroys its consent log is unresolved. iubenda documents the Cookie and Consent Preference Log as a feature of the cookie solution and says delete_cookie_solution stops consent collection, but not what becomes of records already stored. We did not test it.
  • Consent records are not readable through this connector at all. If you want an agent to audit consent evidence, this is not the surface — the Consent Database has a separate HTTP API with its own private key.
  • Plan gates are real and the connector reports them rather than removing them. iubenda states some actions depend on the plan attached to a site; direct-link embedding requires a paying plan and direct text embedding requires the Advanced or Ultimate tier.
  • start_scan fetches a live URL and emails the account. iubenda documents the scanner as sending its report to the account email address, so a scan is not a silent read. iubenda publishes no rate limit for scans, and we found no documentation of whether the connector restricts scanning to domains you have registered.
  • get_pricing_package is the only accounting tool in the set. No tool name matches credit, balance, usage, quota or billing. iubenda's plans are subscriptions billed by site count and pageviews rather than per call, so no single tool call spends money — but nothing here observes pageview consumption either.
  • iubenda is not a law firm. Its own llms.txt states it provides compliance tools and lawyer-drafted templates and does not provide legal advice. An agent-generated policy is a draft you are publishing under your own name.
  • No prompts or resources are advertised. The directory lists no prompt names, and we could not read the server's initialize capabilities because the endpoint is gated. The entry carries no MCP app widget flag, so no user-clickable surface was found beyond the tools.

Frequently asked questions

Yes, and that is the point of it. A policy embedded on your site is served from iubenda, so a change made through the connector reaches your visitors without you touching your site. iubenda's scanner guide states that after services are saved, the legal documents on your website reflect the update within minutes. A published policy is a legal representation, so review before saving.

No tool reads an individual consent record. The 28 tools cover sites, policies, banners, scans and catalog services, and none of them lists, exports or reads a stored consent. iubenda's Cookie and Consent Preference Log lives in the dashboard, and the separate Consent Database is reached through its own HTTP API with its own private key, not through this connector.

Not directly, but delete_cookie_solution removes the object that holds them. iubenda documents the Cookie and Consent Preference Log as a fully automated feature of the Privacy Controls and Cookie Solution, and describes delete_cookie_solution as removing the banner and stopping consent collection. iubenda does not state whether existing log entries survive that deletion, so treat it as unresolved.

Twenty-eight, and yes. iubenda's connector help article carries a full tool reference naming all 28, grouped by area, and it matches Anthropic's directory listing as an exact set with no name in either source missing from the other. That two-way literal match is rare and is the strongest form of tool-list evidence this catalogue records.

Two, and only two. The server's RFC 9728 descriptor declares mcp-read and mcp-write, and its 401 challenge names the same pair. Nothing separates creating a document from deleting one, so approving write access grants all 11 writes and all 5 deletes together. There is no scope that permits generating a policy while withholding deletion.

Two, and iubenda names both. Setting the owner information through update_site finalizes any draft policy on that site, which iubenda states cannot be undone. And delete_site removes the site together with its documents. iubenda marks five tools destructive in its own reference and says the assistant confirms before anything final or destructive.

Your own account details, not your visitors'. get_user returns the account name and email used to fill the owner field on your documents, and get_site returns site configuration. Scan results describe trackers and third-party services running on a site, not the people who visited it. No tool returns a visitor identifier or IP address.

An iubenda account and an awareness of your plan. iubenda's help article lists an existing account you sign in with, Claude or ChatGPT as the client, and a plan check, because some actions depend on the plan attached to a site. get_pricing_package is the tool that reports which plan and limits apply, and it is the only accounting tool in the set.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Data & Research
Developer
iubenda
Tools
28
Domain
mcp-server.iubenda.com

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.