MCP server · included on every paid plan
Run real cold outreach from the AI you already pay for
You already have a Claude or ChatGPT subscription. What it lacks is a system that will actually find a company, write to it, call it, and tell you who answered. Connect this over MCP and your assistant gets exactly that — 25 tools, no dashboard, no second AI bill.
What is an MCP server for cold outreach?
MCP — the Model Context Protocol — is an open standard that lets an AI assistant call external tools. An MCP server for cold outreach gives your assistant the ability to run real outbound rather than only draft copy you paste somewhere else: sourcing prospects, sending the email, placing the calls, following up, and tracking what came back.
The distinction that matters is ownership of the boring parts. Drafting an email is the easy half. Domains, warm-up, SPF/DKIM/DMARC, suppression, A2P registration and calling windows are the half that decides whether anything arrives — and those live in the platform, not in the prompt.
How to connect it
Create a free account, generate a key, and add the server. In Claude Code:
claude mcp add --transport http outreach \
https://joeckel-contact-api.azurewebsites.net/api/mcp \
--header "Authorization: Bearer op_..." Claude desktop and mobile take the same URL as a custom connector, as does any other client speaking MCP over HTTP. Keys are scoped to one workspace and can be revoked, so a leaked key costs a rotation rather than an incident.
Then ask it something: “how does my pipeline look”, “who replied this week”, “pause the Phoenix campaign”, “stop emailing anyone at acme.com”.
What your assistant can do
Twenty-five tools. Thirteen read, twelve write — and every write is staged and shown to you before it takes effect.
Reading
pipeline_stats
How many prospects are waiting, contacted, replied
list_leads
The pipeline, filterable by stage, market or contact details
get_lead
Everything on one prospect
list_replies
Who wrote back
get_activity
Sends, opens, clicks and replies across the account
get_lead_activity
The full history for one prospect
list_campaigns
Campaigns, their targeting and their status
get_account
Plan, channels, current pitch, schedules, what is still missing
get_call_script
The exact words a prospect hears, and whether it is signed off
preview_call_script
How a wording change would sound, without saving it
list_visitors
Who came to your site, from where, for how long
get_billing
Current plan and every plan available
get_upgrade_link
A checkout link — charges nothing
Writing
update_account
The offer, sender name, reply-to, booking link, service area
update_voice
The words used on calls — hook, approach, what to avoid
create_campaign
Build a campaign and start outreach
update_campaign
Retarget it, rename it, pause or resume it
approve_call_script
Sign off a script so it may dial (requires reading it first)
revoke_call_script
Withdraw sign-off — applies immediately
test_call
Ring your own phone to hear the script live
suppress_contact
Stop contacting an address or domain — applies immediately
change_plan
Quote a plan change and its price
confirm_plan_change
Apply it — the only step that charges
confirm_change
Apply a staged edit
cancel_change
Discard a staged edit
What it deliberately cannot do
These are not gaps. Each one is the answer to a specific way an automated system causes damage, and each is enforced on the server rather than asked for in a prompt.
Cannot
It cannot send a message to a prospect on demand.
Pacing, recipient-local quiet hours and suppression are enforced where sending happens, on a schedule. Campaigns get switched on; individual messages do not get fired. An assistant being enthusiastic at 11pm is not hypothetical.
Cannot
It cannot change anything silently.
Edits are staged and returned as a per-field before/after. Nothing applies until a separate confirmation. Suppression is the one exception — stopping contact is never the risky direction.
Cannot
It cannot approve a call script it has not read.
Sign-off is what permits a script to dial strangers. Approving requires a fingerprint of the exact wording, obtainable only by reading the script — so the words pass through the conversation first.
Cannot
It cannot charge a card in one step.
A plan change quotes the price, then a separate call carrying that quote applies it. The amount is always stated in its own turn, where a person can stop it. Quotes are single-use and expire.
Cannot
It cannot dial a number it was handed.
The one calling tool takes no destination at all — it reads the account owner’s number. A tool that accepted a number would be a cold-calling tool under another name.
Why this instead of a second AI product
Most outreach tools now bundle an AI and charge you for it. You are already paying for a frontier model — the one in your pocket, that you know how to talk to, with your context already in it. Paying again for a worse one wrapped in someone else's UI is the part that stopped making sense.
What is genuinely hard to replicate is not the intelligence. It is the sending reputation, the warmed domains, the suppression list that agrees with itself across email, SMS and voice, and the carrier registration. That is what you are buying; the assistant is yours already.
Questions
What is an MCP server for cold outreach?
MCP (Model Context Protocol) is an open standard that lets an AI assistant call external tools. An MCP server for cold outreach gives your assistant the ability to run real outbound — source prospects, write and send email, place calls, and track replies — instead of only drafting copy you then paste somewhere else. The Outreach Platform exposes 25 such tools over MCP.
Can ChatGPT send cold emails for me?
ChatGPT on its own can write a cold email but cannot send one, source a prospect list, handle deliverability, or follow up. Connected to an outreach MCP server it can operate a system that does all of that. On The Outreach Platform the assistant starts and steers campaigns while the platform does the sending on its own schedule, which is where pacing and quiet-hours rules are enforced.
Can I run cold outreach from Claude?
Yes. Add the MCP server as a custom connector in Claude (desktop, mobile or Claude Code) and you can ask for your pipeline, see who replied, change your offer or call script, start a campaign, and suppress anyone who asks to be left alone — in plain language, without a dashboard.
Do I need a separate AI subscription?
No, and that is the point. You already pay for Claude, ChatGPT or similar. This puts the assistant you already have to work, rather than charging you for a second one bundled into a SaaS product.
Is it safe to let an AI run outreach on my account?
The safety is in what the tools refuse to do rather than in trusting the model. It cannot send to a prospect on demand, cannot change settings without showing you a before/after you confirm, cannot approve a call script it has not read back to you, and cannot charge your card in a single step. Every limit is enforced on the server, not in the prompt.
What does it cost?
MCP access is included on every paid plan at no extra charge: $29/month for email, $59 to add calling, $99 for full volume, first month $29. There is also a free tier with 10 leads a month.
Does it work with tools other than Claude?
Any client that speaks MCP over HTTP can connect, which includes Claude and a growing number of others. The server is a standard streamable-HTTP MCP endpoint with bearer-token auth, so it is not tied to one vendor.
How is this different from Zapier or a custom GPT?
A Zap fires a fixed action on a trigger and a custom GPT can only call whatever API you wire into it yourself — and neither owns deliverability, warm-up, suppression or A2P registration. This is an outreach system that already runs those, exposed as tools your assistant can drive.
Try it on a free account
Ten real companies that need what you sell, their contact details, and a written pitch — no card. Connect your assistant and ask it what it found.