MCP Server
Let an AI agent read conversations, reply and manage contacts through Wexio as MCP tools
The MCP server needs a Pro or Enterprise plan, on top of API access. On Standard the GraphQL API works but MCP does not: it answers 403 with {"error":"plan_feature_not_allowed","feature":"mcp"}.
Tech providers and their client organisations are unaffected - they are billed by usage rather than a retail plan.
Wexio runs an MCP server, so an AI agent can read conversations and reply in them as tool calls instead of GraphQL.
Any org can use it. Point an MCP client at the endpoint with an Org API key and the agent gets 43 tools, each gated by that key's scopes. The endpoint and its connection details are in the dashboard under Settings → Webhooks and API → MCP.
MCP now covers almost the whole surface: messaging, inbox reads, chat control, contacts, channels, WhatsApp templates and Telegram bot settings. Content (Help and News), team management beyond listing members, and key management stay GraphQL-only.
Connect
| Endpoint | POST https://<your-wexio-host>/mcp |
| Transport | Stateless streamable HTTP (MCP spec) |
| Auth | Authorization: Bearer wx_<keyId>_<secret> |
There is no X-Wexio-Org header here. A normal key always acts on its own org. A partner key can target a managed child with the orgId argument on each tool call.
Every call re-authenticates the key and re-checks the scope. Nothing is cached between calls, so revoking a key takes effect immediately, mid-session.
The Tools
43 tools, grouped by what they touch:
| Group | Tools | Scopes |
|---|---|---|
| Messaging | 5 | MESSAGES_READ, MESSAGES_SEND |
| Inbox reads | 4 | MESSAGES_READ |
| Chat control | 10 | CONVERSATIONS_MANAGE, MESSAGES_SEND, NOTES_WRITE, CONVERSATIONS_DELETE |
| Contacts | 5 | CONTACTS_READ, CONTACTS_MANAGE |
| Channels | 18 | CHANNELS_MANAGE |
| Team | 1 | TEAM_READ |
Errors and Limits
Tool failures come back as isError: true with readable text, never as a protocol error:
| Message | Meaning |
|---|---|
Unauthorized: invalid API key | Missing, malformed or revoked key. |
Forbidden: this API key lacks the <SCOPE> scope | Valid key, wrong scopes. |
Forbidden: organisation not accessible with this key | orgId is not a client you manage. |
Rate limited - retry after Ns | Over a rate limit. |
Not available on the current plan: ... | The org's plan does not include it. |
Internal error | Everything else - logged server-side, detail not returned. |
An agent seeing Internal error should surface it rather than retry in a loop. Page sizes are clamped to 100. See Rate limits.