Ninout MCP server icon

Ninout

by Ninout

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity82 tools

Design, publish and analyse Ninout forms — Ask One, CREATIVE SURVEY and Fan Fan Fan — from an AI agent. Anthropic lists 82 tools; 40 write and 10 delete. Ninout publishes no tool list. OAuth with no scopes.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Ninout via MCP

https://mcp.svy.ooo/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Ninout Tools & Capabilities (82)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • No OAuth scopes exist at all. The RFC 9728 resource descriptor at https://mcp.svy.ooo/.well-known/oauth-protected-resource/mcp declares only resource, authorization_servers and bearer_methods_supported. The authorization server metadata declares no scopes_supported either. Nothing at the OAuth grant separates reading a form from deleting its questions. Ninout's stated boundary is the signed-in user's own permissions and their tenant — so the connector inherits whatever that person can do, and the only place to narrow it is Ninout's own role settings, before you connect.
  • The scope list could not be used as a second enumeration. On other connectors an advertised scope naming a verb no tool carries is positive evidence of a hidden surface. Ninout advertises no scopes, so that cross-check was unavailable here. Its absence is not reassurance.
  • Ninout publishes no tool list. The 82 names come from Anthropic's directory. Ninout's two MCP pages describe capabilities in prose — 15 feature bullets — and name no tool. We diffed those bullets against the 82 names as sets: every bullet maps onto at least one plausible tool, and the names carry more than the bullets describe. revoke_session, upload_creative, upload_collector_image, list_guides and read_guide have no counterpart in any vendor bullet. Because the match is semantic rather than literal, a rename would be invisible to us.
  • We could not read tool schemas or safety annotations. The endpoint returned 401 to an anonymous request, so no parameter-level detail is published here. On a surface with 40 writes and 10 deletes, that is a material gap: the four hiding places for outbound capability are all parameter-level, and we could see none of them.
  • manage_collector, manage_theme and query_ninout are unspecified. Three tool names on this server describe no operation. We report them as unknown rather than guessing.
  • The help centre is behind a login wall. support.creativesurvey.com now serves only a migration notice pointing at connect.ninout.ai, which redirects every path to an SSO login and instructs readers to sign in to their service first. We did not attempt to bypass it, so any per-tool documentation Ninout publishes to customers is outside what this page could check.
  • The plan gate is real and unpriced. Both a product account and a separate Ninout MCP option contract are required, and no price is published for either.
  • Neither the privacy policy nor the terms of service mention MCP, AI or connectors. Ninout's general terms are conventional Japanese SaaS terms. The only connector-specific liability language sits on the MCP page itself, where Ninout states it is the user's own responsibility to verify the permissions granted and the results of the assistant's actions.
  • No subprocessor or AI data-handling disclosure. Ninout holds Privacy Mark and ISO 27001 certification, but publishes no statement of where response data or model prompts are sent — relevant given that selectable models include Google's Gemini.
  • The English documentation is thinner than the Japanese. Both pages exist and agree; the Japanese page is the fuller source and is cited alongside the English one below.
  • code_challenge_methods_supported includes plain. Ninout's documentation states PKCE is required, and it is — but the authorization server advertises the plain challenge method alongside S256. plain offers no protection against code interception. We did not test which a client actually negotiates.

Frequently asked questions

Yes. Ninout's own documentation lists publishing, unpublishing and duplicating a form among the connector's features, in both its Japanese and English pages. Ninout forms are public web pages with custom-domain and OGP support. So an agent holding this connector can move a form from private draft to live collection, and take it down again.

Anthropic's directory lists 82. Reading every name, 32 are reads, 40 are writes and 10 are deletes. That is one of the largest connector surfaces in the directory, and only 39 percent of it is read-only. Ninout publishes no tool list of its own, so the 82 could not be diffed against a vendor enumeration.

Not directly, but it configures the thing that does. Ninout documents the connector configuring post-completion actions and thank-you mail, and all three products ship an automatic-reply email feature. Configuring an auto-reply on a live form means the next real respondent receives mail, so the effect reaches the public even though no tool sends it.

None. Neither the RFC 9728 resource descriptor nor the authorization server metadata declares scopes_supported, checked on 2026-08-23. Ninout documents access as bounded by the signed-in user's own permissions and their tenant subdomain. So the consent screen offers no way to grant reading a form without also granting the 40 writes and 10 deletes.

Yes, by configuration. Ten tools manage webhooks and external service integrations. Ninout names Salesforce, HubSpot, Zoom, Slack, Microsoft Teams and Adobe Marketo Engage as supported destinations for its Reference Magic lookup feature. An agent configuring these changes where form data flows, and webhooks post to any URL.

It is the connector's only analytics tool and its least specified one. Ninout documents aggregating and analysing response data but publishes no schema for this tool, and its name carries no object. Ninout announced a Headless Analytics product in June 2026, which this likely fronts. Treat it as an unbounded query surface over response data.

Possibly, and nothing in the surface can tell you. The AI Autofill tools configure features Ninout sells as a separate AI Magic contract, and pricing is per order form with no public rate. No tool among the 82 carries a credit, usage, quota or billing verb, so an agent cannot check consumption before or after acting.

Two contracts. Ninout states you need an account for one of its products — Ask One, CREATIVE SURVEY or Fan Fan Fan — plus a separate contract for the Ninout MCP option. The connector is not available on a product account alone. In Claude, connect it under Customize then Connectors and complete the OAuth sign-in.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Productivity
Developer
Ninout
Tools
82
Domain
mcp.svy.ooo

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.