Klaviyo
by Klaviyo
Report on campaigns and flows, query profiles and events, and create campaigns and templates from your AI assistant. OAuth sign-in, read-only mode available, works with any MCP client.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Connect Klaviyo via MCP
https://mcp.klaviyo.com/mcp?include-mcp-app=trueWorks in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.
Klaviyo Tools & Capabilities (27)
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
Limits
- This connector writes to a marketing account, and it is on by default. Klaviyo's documented default for
read-onlyisfalse. Eight of the 27 directory-named tools create campaigns, create and update profiles, upload images, create templates, and change marketing subscription status. Setread-only=truebefore you let an assistant loose on a live account. - Klaviyo warns about prompt injection through your own data. Its documentation flags tools that read user-generated content as interpretable by your model, and tells you to review each tool call so the client does not act on malicious instructions. That warning is Klaviyo's.
- Owner, Admin or Manager only. Klaviyo states the remote-hosted server is unavailable to its other five user roles, including Analyst, Campaign Coordinator and Content Creator.
- Query parameters do not work through the listed connector. Klaviyo states that neither the listed Claude connector nor the listed ChatGPT app can carry them, so read-only mode and tool filtering require a custom connector.
- The tool surface is far bigger than the directory suggests, and the extra tools include sending. Klaviyo's table documents 262 tools against the directory snapshot's 27 names, and 75 of those rows are marked "(Beta)" behind a
beta=trueparameter Klaviyo describes as enabling "new, potentially unstable tools". Among the remote-available tools Klaviyo documents but the snapshot omits issend_campaign— sending a campaign to its configured audience — pluscancel_campaign_sendandrequest_profile_deletion. Do not size the risk of this connector from the 27-name listing. include-mcp-app=trueis undocumented by Klaviyo. Anthropic's directory publishes the endpoint with that parameter and its entry setshas_mcp_app: true, but Klaviyo's MCP page never mentions it and lists five other parameters without it. We could not list resources to check for a widget, because the server requires OAuth. Treat an interactive widget as plausible but unconfirmed. The Klaviyo ChatGPT App that Klaviyo does document is a separate, ChatGPT-specific product.- We did not read the tools and never called one. Our only contact was an anonymous handshake that returned HTTP 401. Every statement above about what a tool does comes from Klaviyo's documentation or Anthropic's directory listing, each dated below.
- No published rate limit for the MCP server. Klaviyo's MCP page states none, and we did not probe for one.
Frequently asked questions
Which Klaviyo role do you need to connect the MCP server?
Owner, Admin or Manager. Klaviyo's documentation states the remote-hosted server is only available to users holding one of those three roles, and lists the wrong role as a cause of failed connections. Klaviyo's roles article adds that only Owner and Admin can manage integrations, so a Manager may still hit narrower limits.
Can the Klaviyo connector send a campaign to your customers?
Yes. Klaviyo's tool table documents send_campaign, described as sending a campaign to its configured audience, as a write tool available on the remote server, alongside a tool to cancel a send. That name is absent from Anthropic's 27-name directory snapshot, so the connector reaches further than that listing implies. Use read-only mode to prevent it.
How do you stop an AI assistant from writing to your Klaviyo account?
Add read-only=true to the server URL. Klaviyo documents that this query parameter disables every tool capable of a write action on your account. On the local server the same control is the READ_ONLY environment variable. Klaviyo notes the parameter cannot be set through the listed Claude connector, so use a custom connector.
Why does the Klaviyo connector load too many tools for your client?
The default surface is large. Klaviyo documents a core-tools-only=true parameter that limits the server to roughly 40 core tools, and says it helps clients with smaller context windows and improves tool-selection accuracy. Klaviyo defaults this parameter to true for ChatGPT clients and false everywhere else.
Can an AI assistant be misled by content inside your Klaviyo account?
Klaviyo says yes, and ships a switch for it. Its documentation flags specific tools as reading user-generated content that your model could interpret, and warns you to review each tool call so your client does not act on malicious instructions. Setting disable-tools-with-user-generated-content=true turns those tools off.
Why can't your MCP client find any Klaviyo tools after connecting?
Usually a stale client process. Klaviyo's troubleshooting tells you to terminate all processes and relaunch the app to refresh the client, and to re-check the configuration first. For the remote server it also says to confirm the URL has no trailing slash and that your account role is Owner, Admin or Manager.
Can you connect more than one Klaviyo account at once?
Yes, through custom connectors rather than the listed one. Klaviyo documents adding one custom connector per account, distinguishing them by name and by a company query parameter on the URL. It advises enabling only the relevant connector in each new chat so the assistant does not query the wrong account.
Sources
- Klaviyo MCP server documentation (retrieved 2026-08-18 via the
.mdvariant this ReadMe-hosted site serves; ~6,700 words). Source for setup, query parameters, troubleshooting, the per-tool Read Only table and the role requirement. · retrieved 2026-08-18 - Klaviyo user roles (retrieved 2026-08-18). Source for what Owner, Admin and Manager can do relative to Klaviyo's other roles. · retrieved 2026-08-18
- Anonymous MCP
initializeagainsthttps://mcp.klaviyo.com/mcp?include-mcp-app=true— HTTP 401 withWWW-Authenticate: Bearer realm="OAuth", retrieved 2026-08-18. This is the authentication challenge that establishes the OAuth posture. · retrieved 2026-08-18 - Klaviyo's RFC 9728 protected-resource descriptor — — HTTP 200, retrieved 2026-08-18, naming Klaviyo's own host as the authorization server. It publishes no
scopes_supportedfield, so we make no claim about OAuth scopes. The matching authorization-server metadata confirms dynamic client registration. · retrieved 2026-08-18 - Anthropic Connectors Directory entry — — the 27 tool names,
partnertier, endpoint and categories above are read from our committed directory snapshot dated 2026-08-16; the directory page itself blocks automated fetches, so we did not retrieve it directly. · retrieved 2026-08-16 - Klaviyo support (redirects to a Klaviyo login; we did not sign in) · Privacy (HTTP 200, retrieved 2026-08-18) · retrieved 2026-08-18
developers.klaviyo.com/robots.txtpermits this path and carries noContent-Signaldirective (retrieved 2026-08-18). Nollms.txtis published; the.mdsuffix on page URLs is the machine-readable route. · retrieved 2026-08-18
Use in Agentman
Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.
Open in Agentman StudioServer Info
- Category
- Sales & CRM
- Developer
- Klaviyo
- Tools
- 27
- Domain
- mcp.klaviyo.com
Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.