> ## Documentation Index
> Fetch the complete documentation index at: https://docs.revdesk.com/llms.txt
> Use this file to discover all available pages before exploring further.

# RevDesk MCP Server

> Connect AI agents to RevDesk over the Model Context Protocol.

RevDesk's remote [Model Context Protocol](https://modelcontextprotocol.io) server gives AI agents a
small, auditable tool surface for calling, SMS, phone numbers, caller IDs, and usage. It uses
Streamable HTTP and the same organization-scoped OAuth grants, API keys, and least-privilege scopes
as the REST API.

**Server URL:** `https://mcp.revdesk.com/mcp`

**Discovery:** `https://mcp.revdesk.com/.well-known/mcp`

**Official registry:**
[`io.github.cell-labs-inc/revdesk-product`](https://registry.modelcontextprotocol.io/v0/servers/io.github.cell-labs-inc%2Frevdesk-product/versions/1.1.0)

Agents may initialize the server and inspect tool names and schemas without a credential. Reading
organization data or invoking any tool requires a valid OAuth access token or API key;
unauthenticated tool calls fail before reaching the RevDesk API.

## Connect

OAuth-capable MCP clients discover RevDesk's authorization server automatically. Connect RevDesk,
select the organization, review the named scopes, and approve the grant. If a client does not
support OAuth, create an API key in **Settings → API Keys**, grant only the scopes the agent needs,
then configure an `Authorization: Bearer rv_…` header:

```json theme={null}
{
  "mcpServers": {
    "revdesk": {
      "type": "http",
      "url": "https://mcp.revdesk.com/mcp",
      "headers": {
        "Authorization": "Bearer ${REVDESK_API_KEY}"
      }
    }
  }
}
```

<Warning>
  Keep API keys in your MCP client's secret or environment-variable store. Never paste a key into a prompt,
  source file, or configuration file that will be committed.
</Warning>

## Tools

| Tool | Action | Typical scopes |
| - | - | - |
| `send_sms` | Send an SMS from an owned RevDesk number | `sms:write` |
| `place_call` | Place an outbound phone call | `calls:write` |
| `list_calls`, `get_call` | Read call history and details | `calls:read` |
| `hangup_call` | End an in-progress call | `calls:write` |
| `list_phone_numbers` | List numbers available to the organization | `phone_numbers:read` |
| `search_available_numbers` | Search carrier inventory | `phone_numbers:read` |
| `buy_phone_number` | Purchase a number; account billing applies | `phone_numbers:write` |
| `list_caller_ids` | List verified caller IDs and display names | `voice:read` |
| `get_usage` | Read current-month usage | `usage:read` |

The MCP layer calls the same v1 endpoints as the [official TypeScript SDK](/api-reference/sdks).
Scope checks, rate limits, idempotency, and tenant isolation are therefore enforced consistently.

Every tool publishes MCP safety annotations for read-only, destructive, idempotent, and open-world
behavior. `get_usage` also advertises a `ui://` resource using the MCP Apps media type so compatible
hosts can present a compact RevDesk usage surface beside the tool result.

## Security and approvals

Tools that send messages, place calls, buy numbers, or hang up calls change external state or incur
cost. Get the user's approval before placing calls, sending messages, spending money, or changing
configuration. For read-only discovery, use a separate OAuth grant or key containing only the necessary
`:read` scopes.

The protected-resource metadata at
`https://mcp.revdesk.com/.well-known/oauth-protected-resource` lists every supported scope and the
accepted bearer method and OAuth authorization server.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.