Skip to content

WisePPC MCP Server: Technical Overview

Last updated

WisePPC runs an MCP server that lets an AI app such as Claude work with a business’s Amazon Ads and Amazon Seller Central data in WisePPC. This page is for the people who approve that connection: IT admins and business owners. For what it does and how to connect, see WisePPC MCP server and the setup guide.

At a glance

  • Server: https://mcp.wiseppc.com/mcp, Streamable HTTP.
  • Sign-in: OAuth with the user’s WisePPC account. Claude registers itself; no API key or client secret is needed.
  • Scope of a connection: one WisePPC business profile, chosen by the user when they approve.
  • Starts read-only. A connection can request changes only if a business owner or admin grants it, and it can never approve a change.
  • Revocable at any time in WisePPC, effective on the next request.
  • Operator: Crystal Logistics Corporation, which provides WisePPC. Hosted on AWS in the United States (us-east-1).

Add WisePPC to Claude

  • Claude.ai and Claude Desktop: in Settings, open Connectors, add a custom connector and enter https://mcp.wiseppc.com/mcp.
  • Claude Code: run claude mcp add --transport http wiseppc https://mcp.wiseppc.com/mcp, then open /mcp, choose wiseppc and Authenticate.

Either way, a browser window opens on WisePPC to sign in and approve.

How the OAuth sign-in works

  1. Claude calls the server, gets 401 Unauthorized with a pointer to the server’s metadata, and reads it from /.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server.
  2. Claude registers itself as an OAuth client (dynamic client registration). WisePPC has no pre-registered clients and issues no client secrets.
  3. The user’s browser opens WisePPC. The user signs in with their WisePPC account, so Claude never sees the password.
  4. A consent page, “Connect your AI assistant”, shows the business to connect, the app’s name (as the app reports it), the address WisePPC will return to, and the access it gets: read-only.
  5. Any active member of the business can approve. The connection is bound to that one business; another business needs a new sign-in.
  6. Claude exchanges the one-time code for tokens and sends the access token with every request.

Technical details:

  • Authorization code flow with PKCE (S256, required). state and resource are required, and resource must be https://mcp.wiseppc.com. The response includes the iss parameter.
  • Redirect addresses must be HTTPS or loopback and must match exactly.
  • One scope, mcp. What a connection may do is set on the connection in WisePPC, not by the scope.
  • Endpoints: /oauth/authorize, /oauth/token, /oauth/register and /oauth/revoke on https://mcp.wiseppc.com.
  • Access tokens last up to one hour. Refresh tokens rotate on every use, and reusing an old one revokes the whole connection. A connection lasts at most 30 days; then the user signs in again.
  • Tokens are stored only as hashes.

What a connection can do

A new connection gets the Agent (read-only) role:

  • It can read the Amazon Ads and Amazon Seller Central data the business has connected to WisePPC, including read-only SQL queries.
  • It can’t see sensitive data, such as Amazon Multi-Channel Fulfillment orders, and it can’t request changes.

A business owner or admin can change this for each connection in WisePPC:

  • Sensitive data: turned on only where the owner or admin opts in.
  • Changes: a connection can request changes to Amazon (for example bids, budgets, keywords or listings) only for the operations the owner or admin grants. Each grant decides whether a person approves the change in WisePPC before it is sent, or whether it is sent without review.
  • Approval stays with people: an AI connection can never approve a queued change. Only a person signed in to WisePPC can.
  • Permission changes apply on the connection’s next request, with no need to reconnect.

Every tool carries MCP annotations. Read tools are marked read-only. The three tools that queue or revise a change or save a preference are marked as able to change data, and they refuse unless the connection has the grant.

Revoking access

  • In WisePPC, open AI Integration → Connections & Permissions and choose Revoke connection. Members can revoke their own connections; owners and admins can revoke, pause or re-enable any connection in the business.
  • An app can revoke its own tokens at /oauth/revoke.
  • Revocation is checked on every request, so it takes effect on the next one. Removing a user from the business also ends their connections.
  • Removing WisePPC from Claude doesn’t end the connection in WisePPC; revoke it there.

Data handling

  • What WisePPC receives: the tool calls the app makes. Your conversation with Claude is never sent to WisePPC.
  • What leaves WisePPC: the data a tool returns goes to the AI app and is handled by its provider under its own terms (for Claude, Anthropic).
  • Records we keep: for each tool call, the tool, the names of the inputs (not their values), identifiers, row and byte counts, timing and any error. Kept for up to one year.
  • Limits: 60 requests a minute per connection and 500 an hour per user.
  • Security: data is encrypted in transit (TLS) and at rest, including databases and backups.

Our Privacy Policy covers the rest, including service providers and your rights. To delete data, see Delete Your Data. Use of WisePPC is governed by our Terms of Service.

API keys

Other MCP apps and your own scripts can use a WisePPC API key instead of OAuth. A business member with the Management role creates keys in WisePPC, and each key has its own read and change permissions. See the setup guide.

Contact