The Opt2In MCP connector
The connector lets an AI assistant read your own saved Instagram reports. It works with Claude today, and we built it for Meta's Muse too. Any app that speaks MCP (the Model Context Protocol) can use it.
It only reads. It only sees your reports, and only after you say yes on an Opt2In page. You can switch it off at any time.
Connect it to Claude
- In Claude, open Settings, then Connectors.
- Choose Add custom connector and paste
https://opt2in.com/mcp. - An Opt2In page opens. Sign in with the email that holds your saved report, then choose Allow.
- Ask Claude something like "Which brands showed me the most ads on Instagram?"
You need a saved Opt2In report first. Without one there is nothing for Claude to read. Claude uses your own Claude plan to answer.
The endpoint
https://opt2in.com/mcp
- Transport: Streamable HTTP. Send JSON-RPC with
POST. - Replies are plain JSON. There is no event stream.
- Stateless: no session to open or keep. Every request carries its own token.
- Every request needs
Authorization: Bearer <access token>. Without one, the reply is401with aWWW-Authenticateheader that points to the metadata below.
Sign-in and consent
OAuth 2.1, the authorization code flow, as the MCP authorization spec describes.
- PKCE is required, with
S256only. - Clients are public. There is no client secret.
- Register a client yourself with dynamic client registration (RFC 7591).
- The only scope is
reports.read. It is also the default. - Access tokens last 1 hour.
- Refresh tokens rotate. Each refresh returns a new one. Reusing an old one ends the whole connection.
| Purpose | Address |
|---|---|
| Resource metadata (RFC 9728) | https://opt2in.com/.well-known/oauth-protected-resource |
| Server metadata (RFC 8414) | https://opt2in.com/.well-known/oauth-authorization-server |
| Client registration | https://opt2in.com/mcp/oauth/register |
| Consent page | https://opt2in.com/auth/mcp/authorize/ |
| Token | https://opt2in.com/mcp/oauth/token |
| Token revocation (RFC 7009) | https://opt2in.com/mcp/oauth/revoke |
Redirect URIs must use https. Loopback addresses on http
(localhost, 127.0.0.1, [::1]) are allowed for local
clients. A redirect URI must match a registered one exactly. If it does not, the consent
page shows an error and sends nobody anywhere.
On the consent page the person signs in to Opt2In with an emailed code. Then they see
your app's name, where it will send them back, and what it can read. Allow returns a
code to your redirect URI. Don't allow returns
error=access_denied.
The six tools
All six are read-only. Each one answers from the person's newest saved report, unless they name another one.
| Tool | What it answers |
|---|---|
list_reports | Which reports the person has saved, with their dates. |
top_advertisers | The advertisers that showed them the most ads. |
ads_from | The ads they saw from one advertiser, by date. |
who_has_my_data | The advertisers that uploaded a list with them on it. |
attention_value | Our estimate of what their ad attention is worth to advertisers. |
ad_interests | The interest categories used to reach them with ads. |
If a number was not measured in the report, it is left out with a short reason. It is never sent as 0.
What is never returned
- The person's email address, name, phone number, birthday or home address.
- Location history or map coordinates.
- Messages, contacts, followers or who they follow.
- Comments, story interactions or anything else they posted.
- Anyone else's reports.
The tools cannot change, add or delete anything.
How we handle the data
- We do not store the questions you ask, or what the tools send back.
- Connector traffic is not used to build a profile of you, and it does not feed our panel, our ad pricing or our offers.
- We keep a record that the app is connected: which account, which app and when. Tokens are stored only as hashes.
- To disconnect, a person removes Opt2In in their assistant, emails privacy@opt2in.com, or deletes their Opt2In account. Revoking a token at
/mcp/oauth/revokeor deleting the account ends access at once.
The full policy: Privacy Policy and Terms of Use.
Support
Questions or problems: support@opt2in.com. Security reports: our security page.