Skip to main content
Connecting an AI assistant means the assistant’s provider processes what Claimr sends back. Claimr MCP is designed so that what the assistant sees is limited to campaign configuration, and so that you stay in control of what it can change.

Participant data stays in Claimr

Claimr MCP doesn’t send participants’ personal data to your AI assistant. The assistant can’t read:
  • Participant names, emails, social handles, or wallet addresses.
  • Form and quiz answers.
  • Raffle candidates and winners.
  • Tournament standings.
  • The participants in a segment.
To see this data, open the campaign in the Claimr admin panel.

You choose what each connection can reach

When you authorize a connection, you pick its organizations, campaigns, and permissions. A connection can never do more than your own role allows. See Authorize a connection. Give each connection the least access it needs:
  • Pick specific campaigns instead of all campaigns.
  • Grant Read only, if you just want the assistant to review or explain.
  • Leave out Organization unless the assistant needs to create new campaigns.
  • Leave out Segments unless you plan to work on audiences.

Sign-in and tokens

  • You sign in on a Claimr page, not inside the assistant. Your password is never shared with the assistant.
  • The connection uses OAuth 2.1 with PKCE. The assistant receives a token tied to your account and to the access you chose.
  • Tokens refresh automatically while in use. Each refresh replaces the old token, so a stolen refresh token stops working as soon as the real assistant refreshes.
  • A connection unused for 90 days expires.

Organization oversight

Organization admins see every connection that reaches the organization, including who made it and when it was last used, and can narrow or revoke it. See Manage connections.

Confirm before changes

Most AI assistants show each tool call and ask for approval before changing data. Review changes before you approve them, especially:
  • Deleting groups, quests, tasks, forms, or images.
  • Running a raffle draw.
  • Starting or ending a tournament.
These actions affect participants and some can’t be undone.

Report a problem

If you see a connection you don’t recognize, revoke it right away from your profile or the organization’s API page, then contact support@claimr.io.