Skip to content

MCP Access Model v3.9 ​

Last updated: September 30, 2026

AI4Love provides an MCP (Model Context Protocol) server that lets AI assistants — Claude, ChatGPT, or any MCP-compatible client — query your supporter data conversationally. The MCP server is read-only: it surfaces intelligence and never changes your data. This page explains exactly what the assistant can see, what it can do, and how access is controlled.


How It Works ​

Staff member                 AI Assistant              MCP Server            Airtable
    │                            │                         │                    │
    │── "Who are our at-risk" ──▶│                         │                    │
    │                            │── MCP tool call ───────▶│                    │
    │                            │                         │── validate token   │
    │                            │                         │   (audience, org,  │
    │                            │                         │    scope, expiry)  │
    │                            │                         │── query data ─────▶│
    │                            │                         │◀── records ────────│
    │                            │                         │── format for  ──┐  │
    │                            │                         │   tool's purpose│  │
    │                            │                         │◀────────────────┘  │
    │                            │◀── formatted answer ────│                    │
    │◀── formatted answer ──────│                         │                    │
  1. Staff asks a question in their AI assistant
  2. The assistant calls one of the 40 tools available to authenticated clients
  3. The MCP server validates the caller's OAuth token (signature, expiry, audience, organization and scope) or API key
  4. If valid, the server queries that organization's dedicated working base — never another organization's
  5. Most tools format a bounded, purpose-specific response (see Data Minimization below); two tools are handled differently
  6. Results return to the assistant for response formatting

An unauthenticated request to the MCP endpoint receives an HTTP 401 that points the client to the server's OAuth discovery document, and never reaches step 4. No supporter data is reachable without valid credentials. A public /health endpoint reports only that the service is up.


What the Assistant Can Do ​

Authenticated clients see 40 tools, grouped by purpose:

CategoryExamplesBehavior
Diagnostics (3)health_check, auth_status, whoamiRead-only. whoami returns the signed-in staff account's display name, organization and role; no email and no supporter data
Supporter & activity queries (10)get_supporter, get_supporter_by_id, list_supporters, get_donations, list_volunteers, list_engagements, get_participation, list_events, get_supporter_timeline, export_supportersRead-only
Intelligence & operations (15)get_insights, get_at_risk_supporters, get_at_risk_brief, get_conversion_opportunities, get_conversion_brief, get_recognition_queue, get_campaign_recommendations, get_relationship_alerts, get_resurrection_opportunities, get_resurrection_brief, list_campaigns, get_generated_campaign, list_team, daily_overview, get_summary_statsRead-only
Research & schema (3)query_kindmind, query_vault, get_schemaRead-only
Guidance (1)helpRead-only; describes the available tools in plain language
Visual scenes (8)supporter_pulse, morning_brief, at_risk_brief, recognition_brief, resurrection_brief, conversion_brief, foundation_stats, campaigns_briefRead-only; return structured display instructions so a compatible client can render a multi-panel artifact instead of plain text

AI4Love MCP exposes 40 authenticated tools, all read-only by behavior. Supporter/source-system records and AI4Love working records are not writable through MCP. No tool creates, modifies or deletes anything in Airtable, in the research index or in the client knowledge vault. The two write tools offered before September 30, 2026 (add_to_kindmind and mark_campaign_refined) have been removed, and there is no write permission a client can request.

What the Assistant Cannot Do ​

  • Create, modify, or delete any record, under any tool
  • Access another organization's data — every request resolves to exactly one org
  • Trigger outreach, send messages, or take any other action

This boundary covers AI4Love's MCP server. If a staff member also connects their assistant to Airtable directly with their own Airtable access, that separate connection is governed by their Airtable permissions, not by AI4Love.


Access Controls ​

Authentication ​

Each request carries either an OAuth token or a provisioned per-organization API key.

  • OAuth (Claude, ChatGPT and other assistants): OAuth 2.1 authorization code flow with PKCE (S256). On the consent page the staff member enters their personal access key, which decides the organization; the page states that access is read-only. Tokens are bound to this server's own address as their audience, so a token issued for one AI4Love server is refused by any other. The only permission granted is read (ai4love:read). Access tokens expire after 30 minutes. Refresh tokens extend the session up to 7 days at a time, never beyond 30 days from sign-in, and every refresh rechecks that the staff account is still approved, still holds the same access key and still belongs to the same organization.
  • Per-organization API key (server-side use): checked with timing-safe comparison on every request, always read-only.

There is no long-lived session for the standard (Streamable HTTP) transport — every request revalidates the credential independently. Clients connecting over the older SSE transport hold a short-lived, in-memory session that only pins the organization for that connection; it never authenticates. Every message on it must still carry a valid credential, so an expired token or removed key stops SSE requests the same way.

Organization Isolation ​

Each MCP request resolves to a specific organization, which maps to a dedicated working base and credential set. A user authenticated for Organization A cannot query Organization B's data — this is enforced at the credential routing layer, not by a filter applied after the fact.

Transport Behavior ​

Requests without valid credentials receive an HTTP 401 with a standard WWW-Authenticate challenge that points to the server's OAuth discovery document, so compliant assistants start the sign-in flow on their own. Expired, tampered or wrong-audience tokens receive a 401 with invalid_token.


Request Limits ​

Being direct about the current state here, because a trust page that overstates its own controls is worse than one that's candid: individual tools apply their own query and response bounds (e.g., export_supporters defaults to 100 records per call). A fixed per-key request quota, a daily retrieval cap, and automated anomaly detection across the MCP surface are not currently enforced in the application code. If your organization needs a hard per-key rate limit or daily cap as a contractual requirement, that is a deployment-level control we can configure and verify before publishing a specific number for your account — we won't publish a limit here that the code doesn't actually enforce. Per-key call volume quotas at the Vercel layer are available on request.


Data Minimization ​

Most MCP tools are purpose-built: each tool's response format hard-codes the specific fields it renders for a normal query (e.g., get_supporter returns name, status, channel restrictions, donation total, volunteer hours, region — not a raw record dump), so typical conversational usage returns a bounded, tool-specific projection rather than every field on the record.

Two tools are intentionally broader, and we'd rather flag that here than let this page imply otherwise:

  • get_schema returns field-level metadata for approved tables — that's its purpose.
  • export_supporters accepts a caller-specified list of fields and returns whatever exists on the record for each one requested. It is not currently constrained to a fixed allow-list at the code level.

Both require authentication and are scoped to the caller's own organization. New Airtable fields — including any that carry sensitive information — are reviewed for MCP exposure before being added to a base that has MCP access enabled, since the schema and export tools don't filter by field sensitivity on their own.


The LLM Data Path ​

When the MCP server returns data to the AI assistant, that data transits through the LLM provider's infrastructure. On the MCP path the model is the staff member's own assistant (Claude or ChatGPT): that is client-side assistant use under the staff member's workspace terms, which AI4Love does not control.

For reference, these are the providers' API-tier terms, which apply where AI4Love itself calls them:

ProviderTierTrainingRetention
Anthropic (Claude)API (commercial)No — excluded from training by API termsUp to 30 days for trust & safety, then deleted
OpenAI (ChatGPT)API (commercial)No — excluded from training by API policyUp to 30 days for abuse monitoring, then deleted

Both providers offer zero-retention configurations, available depending on contract tier.

API-tier processing by AI4Love is limited to the nightly agents and dashboard campaign generation, listed on the Sub-Processors page.

Your options:

  • Restrict MCP to a single LLM provider
  • Disable MCP entirely (AI-generated insights in Airtable continue to work independently of MCP)

Audit Trail ​

Every MCP request is logged with:

FieldExample
Tool nameget_at_risk_supporters
Organization IDorg_stf
Auth type or error codeoauth, api-key, AUTH_MISSING, AUTH_INVALID
Staff account ID (OAuth)an opaque account record ID
Clientthe assistant's registered client ID, and a host label such as claude or chatgpt
Granted scopeai4love:read
Token audiencethe MCP server's own address
Result statusok, error
Timestamp2026-07-21T14:32:01Z

Credentials, response bodies, and supporter data are not included in the audit stream. The [MCP] line does not emit record counts or tool-level duration. Vercel request metadata accompanies the stream; see Security Controls for the application and request-metadata fields.

MCP audit lines are retained one day in Vercel runtime logs and streamed to Axiom, retained 30 days on the Personal plan. The Log Drain was added September 14, 2026 and covers ai4love-backend and stilltide-mcp only. MCP audit lines were unaffected by the February 14–September 9, 2026 dashboard/API audit-line gap. The planned working-base Access Log ships before first client go-live; see Audit Logging.


Disabling MCP ​

MCP is optional. If your organization prefers not to expose supporter data through AI assistants:

  1. Remove the staff member's access key or the organization's provisioned API key. API keys stop at the next request; an assistant signed in with OAuth stops at its next token refresh, within 30 minutes, or
  2. Request that AI4Love disable MCP access for your entire organization

AI-generated insights continue to appear in the dashboard — they're written directly to Airtable by the nightly agents and don't depend on MCP.

AI4Love Trust Center v3.9