MCP Server
The Model Context Protocol (MCP) is the standard interface for letting AI clients call external tools. PlaceOptimizer speaks MCP at app.placeoptimizer.com, so an assistant can probe the service and read your managed locations, metrics, reviews, and posts — the same tenant data the operator console shows.
There are two MCP surfaces, deliberately split:
| Surface | URL | Auth | Tools |
|---|---|---|---|
| Public discovery | https://app.placeoptimizer.com/mcp | None | 3 read-only tools: ping_console, get_audit_overview, get_public_endpoints |
| Authenticated console | https://app.placeoptimizer.com/api/v1/mcp | PlaceOptimizer session (member role) | 5 tenant-scoped tools: list_locations, get_location_metrics, list_location_reviews, list_location_posts, get_org_info |
What can you do?
With the PlaceOptimizer MCP server connected, an AI assistant can:
- Probe the service — confirm the endpoint is reachable and report its identity and version.
- Summarize what PlaceOptimizer is — and how to request a free audit.
- List public discovery surfaces — MCP server card, API catalog, security contact, and the marketing-site llms.txt.
- List your managed locations — every GBP location the authenticated organization manages, with health score and source.
- Fetch per-location metrics — post, media, review, and optimization metrics.
- Read reviews and posts — across your locations.
How it works
AI client ──► https://app.placeoptimizer.com/mcp (public, no auth)
AI client ──► https://app.placeoptimizer.com/api/v1/mcp (console session)
The public endpoint is the discovery surface: it needs no authentication and exposes tools any caller can use. The authenticated endpoint sits behind the console's session guard — the same Better-Auth session that protects the dashboard — and its tools read the active organization's data through the same provider the console uses.
Both endpoints speak MCP v2 (spec revision 2026-07-28) over Streamable HTTP: POST-only, JSON response mode, no server-side sessions to manage.
Authentication model
- The public endpoint is open — no session, no API key, no tenant data.
- The authenticated endpoint requires a PlaceOptimizer console session
with an active organization and at least the
memberrole. Requests without a valid session are rejected with 401 Unauthorized before any tool runs. - OAuth 2.1 for third-party clients is rolling out. The console has staged
the OAuth 2.1 authorization server (dynamic client registration per RFC
7591, PKCE, refresh tokens, and the RFC 8628 device flow) and the schema
tables that back it, but the server is not yet wired into the running
console — the discovery document at
/.well-known/oauth-authorization-serverdoes not resolve yet. Until it ships, the authenticated tools are exercised through the console session, and third-party clients use the public endpoint. See Authentication.
Which clients work
The public endpoint uses the standard remote-MCP connector flow, so any client that supports custom connectors or remote MCP servers can attach to it today:
| Client | Flow |
|---|---|
| Claude (web / desktop) | Custom connector with a remote MCP URL |
| ChatGPT | Custom connector (developer mode) |
| Cursor | Remote MCP server in mcp.json |
See Setup for exact steps per client, Available Tools for the full tool reference, and Troubleshooting for common issues.
Next steps
- Setup — connect Claude, ChatGPT, or Cursor to the server
- Available Tools — full reference for all 8 tools
- Authentication — how auth works today and the OAuth 2.1 rollout
- Troubleshooting — common issues and fixes