SuperProfile MCP server: developer reference
The essentials for connecting an MCP client to SuperProfile. The full, per-product guide is at https://mcp.superprofile.bio/docs.
Connection
- Endpoint
https://mcp. superprofile. bio/ mcp - Transport
- Streamable HTTP; send one MCP request per HTTP POST
- Authorization
- OAuth with dynamic client registration, S256 PKCE, rotating refresh tokens and revocation; use the exact MCP resource URL during authorization and token exchange
- OAuth metadata
https://mcp. superprofile. bio/ . well-known/ oauth-authorization-server - Revoke
- Manage or revoke access any time in Connected agents in your SuperProfile dashboard
Permissions and tool discovery
Tool discovery lists only the tools your connection's permissions allow; each get_*_context result separates supported operations from currently authorised ones. Draft/edit, publication, deletion, customer information and email activation are separate permissions. A call that needs a missing permission returns HTTP 403 with an insufficient_scope challenge, missingScopes and nextAction: reauthorize: obtain fresh consent for the advertised scopes, then refresh tool discovery. Refreshing a token does not add permissions.
Writes: idempotency, versions and operations
- Every write takes an idempotency key: the current Unix time in milliseconds, a colon, then 16 or more random letters or digits; reuse the same key and inputs after a timeout, and get_operation returns the receipt.
- Read the saved version before editing; a version conflict means re-read and review the current configuration.
- Prepare tools validate a proposal without publishing; commit the returned preview token with the matching draft, edit or publish tool.
- A committed change may still be propagating or awaiting review: poll
get_operationbefore calling it live. - Money is written as decimal major-unit strings, such as "36.14" USD.
Files
File bytes never go through MCP: upload tools return a 24-hour transfer URL or a browser file-selection link, and the server checks size, SHA-256 and content type before use. Poll get_operation until verification finishes, then use the asset in a draft.
Errors and limits
| Response | Meaning and what to do |
|---|---|
403 insufficient_scope | The connection lacks a permission. Read missingScopes, reauthorize, refresh tool discovery. |
409 / version conflict | The configuration changed since you read it. Re-read and review before editing. |
429 / 503 | Rate limited or temporarily unavailable. Limits apply across all of a creator's assistant connections; respect retry guidance on 429 and 503 responses; keep the same idempotency key for uncertain writes. |
Invalid input | The error names the fields to fix. |
Rejected idempotency key | The response includes the server time and your clock difference; build a new key from serverTime. |
Where to start
Call the context tool for the product family first: get_product_context, get_course_context, get_webinar_context, get_booking_context, get_lead_magnet_context, get_locked_content_context, get_telegram_community_context, or get_context for Auto-DM. Each returns the supported operations, missing permissions and the server time.
SuperProfile MCP server pages
- Overview: what the SuperProfile MCP server is
- Connect SuperProfile to Claude
- Connect SuperProfile to ChatGPT
- Connect SuperProfile to Claude Code
- Connect SuperProfile to OpenAI Codex
- Connect SuperProfile to Cursor
- Connect SuperProfile to Gemini
- Connect SuperProfile to Perplexity
- Connect SuperProfile to Windsurf
- Connect SuperProfile to VS Code (GitHub Copilot)
- Connect SuperProfile to Notion
- Connect SuperProfile to Muse by Meta
- Sell digital products with an AI assistant
- Automate Instagram and Messenger DMs with an AI assistant
- Frequently asked questions
Last updated .