The Opt2In MCP connector

The connector lets an AI assistant read your own saved Instagram reports. It works with Claude today, and we built it for Meta's Muse too. Any app that speaks MCP (the Model Context Protocol) can use it.

It only reads. It only sees your reports, and only after you say yes on an Opt2In page. You can switch it off at any time.

Connect it to Claude

  1. In Claude, open Settings, then Connectors.
  2. Choose Add custom connector and paste https://opt2in.com/mcp.
  3. An Opt2In page opens. Sign in with the email that holds your saved report, then choose Allow.
  4. Ask Claude something like "Which brands showed me the most ads on Instagram?"

You need a saved Opt2In report first. Without one there is nothing for Claude to read. Claude uses your own Claude plan to answer.

The endpoint

https://opt2in.com/mcp

  • Transport: Streamable HTTP. Send JSON-RPC with POST.
  • Replies are plain JSON. There is no event stream.
  • Stateless: no session to open or keep. Every request carries its own token.
  • Every request needs Authorization: Bearer <access token>. Without one, the reply is 401 with a WWW-Authenticate header that points to the metadata below.

Sign-in and consent

OAuth 2.1, the authorization code flow, as the MCP authorization spec describes.

  • PKCE is required, with S256 only.
  • Clients are public. There is no client secret.
  • Register a client yourself with dynamic client registration (RFC 7591).
  • The only scope is reports.read. It is also the default.
  • Access tokens last 1 hour.
  • Refresh tokens rotate. Each refresh returns a new one. Reusing an old one ends the whole connection.
PurposeAddress
Resource metadata (RFC 9728)https://opt2in.com/.well-known/oauth-protected-resource
Server metadata (RFC 8414)https://opt2in.com/.well-known/oauth-authorization-server
Client registrationhttps://opt2in.com/mcp/oauth/register
Consent pagehttps://opt2in.com/auth/mcp/authorize/
Tokenhttps://opt2in.com/mcp/oauth/token
Token revocation (RFC 7009)https://opt2in.com/mcp/oauth/revoke

Redirect URIs must use https. Loopback addresses on http (localhost, 127.0.0.1, [::1]) are allowed for local clients. A redirect URI must match a registered one exactly. If it does not, the consent page shows an error and sends nobody anywhere.

On the consent page the person signs in to Opt2In with an emailed code. Then they see your app's name, where it will send them back, and what it can read. Allow returns a code to your redirect URI. Don't allow returns error=access_denied.

The six tools

All six are read-only. Each one answers from the person's newest saved report, unless they name another one.

ToolWhat it answers
list_reportsWhich reports the person has saved, with their dates.
top_advertisersThe advertisers that showed them the most ads.
ads_fromThe ads they saw from one advertiser, by date.
who_has_my_dataThe advertisers that uploaded a list with them on it.
attention_valueOur estimate of what their ad attention is worth to advertisers.
ad_interestsThe interest categories used to reach them with ads.

If a number was not measured in the report, it is left out with a short reason. It is never sent as 0.

What is never returned

  • The person's email address, name, phone number, birthday or home address.
  • Location history or map coordinates.
  • Messages, contacts, followers or who they follow.
  • Comments, story interactions or anything else they posted.
  • Anyone else's reports.

The tools cannot change, add or delete anything.

How we handle the data

  • We do not store the questions you ask, or what the tools send back.
  • Connector traffic is not used to build a profile of you, and it does not feed our panel, our ad pricing or our offers.
  • We keep a record that the app is connected: which account, which app and when. Tokens are stored only as hashes.
  • To disconnect, a person removes Opt2In in their assistant, emails privacy@opt2in.com, or deletes their Opt2In account. Revoking a token at /mcp/oauth/revoke or deleting the account ends access at once.

The full policy: Privacy Policy and Terms of Use.

Support

Questions or problems: support@opt2in.com. Security reports: our security page.