Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Run a security-awareness platform from your assistant: recipients, simulation templates, SSO, admins.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Phished MCP server connects Claude, ChatGPT or any MCP client to Phished, a security-awareness platform that mails simulated phishing to a company's own staff. Ninety-six tools manage recipients, simulation templates, landing pages, SSO configurations and administrators. Thirteen delete things. Anthropic's directory record carries no permissions label at all.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
mcp:use, over all 96 tools. Consent cannot be narrowed to reads. Phished's REST API has per-operation scopes; the MCP grant does not expose them.send-simulation-template-test mails up to 50 real employees per call. Phished documents it as a test send that does not launch a campaign; it still delivers simulated phishing to colleagues.delete-recipient-by-email and update-recipient-by-email act on a typed address, with no identifier-resolution step in between.create-administrator can grant access immediately, without an invitation, when the email already administrates another organisation of the same partner.create-administrator calls silently update permissions rather than failing — safe for bulk import, quiet about privilege changes.It cannot launch a campaign, but one tool does put simulated phishing mail in real inboxes. Phished documents the test-send endpoint as delivering a template to up to fifty existing recipients, and states plainly that it does not launch a real campaign. No tool creates or schedules a campaign — the REST API has a create-manual-campaign operation and the MCP list omits it.
Thirty-nine act, and thirteen of those delete. Counted mechanically from Anthropic's directory snapshot: thirteen create, thirteen delete, thirteen update, plus one send, one validate and one access-limiting tool. The remaining fifty-four read — twenty get and thirty-four list. So roughly two in five tools write, and one in seven destroys something.
They manage who administers your security-awareness tenant. Phished documents the create endpoint as adding an administrator with per-area permissions, including an owner flag and a permission to view reports containing personal data. An existing Phished user at a sibling partner organisation gains access immediately; anyone else receives an invitation. The delete and update tools reach the same accounts.
No. The OAuth metadata advertises exactly one scope, and it is not split by verb. Every grant that reaches the read tools also reaches the thirteen deletes and the test-send. Phished's underlying REST API does use granular per-operation scopes, but nothing in the MCP consent flow lets a user hold back write access at authorisation time.
Staff directory records. Phished's API reference shows a recipient carrying first name, last name, email address, phone number, job function, language and active status, plus department and location identifiers. Phished's privacy policy describes itself as a processor acting for the customer organisation, which remains the controller of that employee data.
No. The directory record has no permissions field at all — not a read-only label, not a read-and-write one. That absence sits over ninety-six tools including administrator and SSO management, which makes it the largest unlabelled surface in this catalogue. Read the verb census on this page rather than relying on the listing.
An active Phished plan and an organisation token. Phished's API reference states that an organisation needs an active plan to use the API at all, and that requests authenticate with an organisation-level bearer token. Token creation is documented in Phished's help centre, which sits behind a login wall we did not pass, so we could not verify which admin role mints one.
documentation URL in Anthropic's directory. A Stoplight-hosted SPA publishing three separate API references: Legacy Phished API, Phished API, Phished Power BI API) · retrieved 2026-08-19https://api.phished.io, bearer organisation token, active plan required. Group list used for the coverage comparison, including the manual-campaign operations absent from MCP) · retrieved 2026-08-19sent / recipient_not_found / send_failed results, required scope simulation-templates:send, documented as not launching a real campaign) · retrieved 2026-08-19is_owner and per-area permissions including can_view_reports_with_pii; immediate access for a sibling partner organisation, invitation otherwise; repeat calls update permissions; required scope administrators:create) · retrieved 2026-08-19idp_x509_cert, application_type of ACADEMY or CLIENT; required scope sso-configurations:create) · retrieved 2026-08-19recipients:read) · retrieved 2026-08-19developer.phished.io/robots.txt is User-agent: * with no disallow rules and no Content-Signal header (fetched 2026-08-19). llms.txt and sitemap.xml both return the SPA shell with HTTP 404, so the page inventory came from the rendered portal navigation · retrieved 2026-08-19www-authenticate header. Authorization server https://app.phished.io, scopes_supported is ["mcp:use"]. The root form also returns 200 with the same scope and a different resource value; the path-insert form returns an HTML 404) · retrieved 2026-08-19https://app.phished.io, authorization_code and refresh_token grants, PKCE S256, a registration_endpoint for dynamic client registration, scopes_supported ["mcp:use"]) · retrieved 2026-08-19https://mcp.phished.io/mcp returned HTTP 401 with www-authenticate: Bearer realm="mcp", resource_metadata="https://mcp.phished.io/.well-known/oauth-protected-resource/mcp". No tool was ever called and no authentication was attempted · retrieved 2026-08-19Connect Phished once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.