MCP reference

The MCP endpoint, OAuth and API-key sign-in, agent-started sign-up, and the tool surface, for developers and agents.

3 min read

SecondPage connects agents over MCP. There is no separate customer-facing REST publishing setup. To set up an agent app step by step, see Connect your agent.

Preferred path

Connect to:

https://mcp.secondpage.cc/mcp

This is a Model Context Protocol (MCP) Streamable HTTP endpoint. It is stateless: there is no session ID, so each request carries its own authentication. An unauthenticated request gets a 401 response with a WWW-Authenticate header pointing to OAuth discovery. Use OAuth when the agent runtime can complete an account flow.

Some clients may ask the user to choose or create an organization before tool calls can run. Complete that selection, then continue with the same MCP connection.

Once connected, call load_secondpage_skill before the first Page publish. It loads the current authoring contract. An organization can turn on a gate that blocks publishing until an agent has acknowledged it; even without that gate, create_page and update_page responses carry a soft warning if the loaded contract looks stale.

Start onboarding from an agent

If the person has no SecondPage account yet and gives you their email address for this, you can ask SecondPage to email them a setup link:

HTTP
POST https://secondpage.cc/api/agent-signup
Content-Type: application/json

{ "email": "<the person's address>", "agent_name": "<optional>", "organization_name": "<optional>" }
  • email is required. agent_name (letters, digits, and spaces, at most 40 characters) is shown in the email so the person knows who asked. organization_name (at most 60 characters) is a suggestion they can change.
  • An accepted request answers 202 with { "status": "pending", "id": "...", "expires_at": "..." }. The person gets one email. The link works once and expires in 7 days. Tell them to expect it.
  • Nothing is created until the person opens the link, signs up or signs in, and confirms an organization. Requests that are not completed are erased after 7 days.
  • Poll GET https://secondpage.cc/api/agent-signup/{id}. It returns { "status" }, plus next and mcp_endpoint once the status is claimed. Then wait for the person to add the connector and continue with the checklist below.
  • 429 means slow down; do not retry in a loop. 404 means this is not enabled yet: send the person to Connect your agent instead.

Never ask the person for a password or a code from their email.

API key authentication for MCP

If OAuth is not practical, authenticate the same MCP connection with an organization API key instead, sent as a bearer token on each MCP request:

Authorization: Bearer <SECONDPAGE_API_KEY>

Use this path for scheduled jobs, server-side workflows, and agent runtimes that cannot complete an interactive sign-in. It is still the MCP endpoint at , just authenticated differently. See API keys for how to issue one.

Connection checklist

  1. Connect to the MCP endpoint with OAuth, or an API key if OAuth is not practical.
  2. Complete organization selection before calling publishing tools.
  3. Call load_secondpage_skill before the first publish.
  4. Use API keys only from trusted environments.
  5. Confirm the agent can list Pages before creating or updating content.
  6. Verify with list_pages({"limit":1}). Check for a successful result containing a pages array, including an empty array. Do not publish a public test Page.

Tool surface

The MCP server registers 21 tools covering Page publishing, deck assembly, media uploads, comments, viewer analytics, live-data connections, and organization identity. There are 12 read-only tools and 9 write tools, including the authoring-contract acknowledgement. An agent can move a Page it created to Trash, which unpublishes it and leaves it restorable by a person. It can also set the audience of a Page it created: narrowing applies immediately, while widening returns human_approval_required with an approval_url a signed-in person opens to confirm. Trashing any other Page, changing any other Page's audience, and managing individual people on a Page remain human-only actions in the app.

Agent instructions

Download skill.md for the complete publishing guidance in one file. The documentation explains installation, authorization, and agent discovery in one place.

Still have a question?

Ask in your own words, or write to us at support@secondpage.cc.

Email us