Summary
Playable MCP lets an AI tool (such as Claude or ChatGPT) work in Playable on behalf of a signed-in Playable user, using that user's existing permissions.
Access requires three things: Playable MCP enabled for the workspace, MCP tool permissions on the user's role, and the user signing in and approving the connection.
Sign-in uses OAuth. Users never handle API keys or share their password with the AI tool.
The AI tool can read campaign content, campaign statistics (totals only) and the media library. It can't read participant or registration data.
It can only change draft campaigns that have never been live. It can't publish, schedule or delete campaigns.
Every action is logged with the user and workspace it was performed for.
Access can be removed at any time. Permission changes take effect on the next request.
How it works
Playable MCP is a server run by Playable at https://mcp.playable.com. It uses the Model Context Protocol (MCP), an open standard for connecting AI tools to other software.
When a user asks their AI tool something that involves Playable, the AI tool sends a request to Playable MCP, for example "list the pages of campaign 123". Playable checks the request, runs it with the user's permissions, and sends the result back to the AI tool.
Playable MCP runs on the same Playable infrastructure and uses the same data as the Playable platform. It doesn't copy your data anywhere else.
Some AI tools, including Claude and ChatGPT, send these requests from their own cloud services rather than from the user's computer.
Signing in and approving
Connections use standard OAuth 2.1, the same kind of sign-in used by "Sign in with Google" and similar services:
The user adds Playable in their AI tool and clicks Connect.
A browser window opens with Playable, and the user signs in with their normal Playable login.
Playable shows an approval screen. It names the AI tool, shows which Playable user the tool will act as, and lists what the tool will be able to do based on the user's permissions.
When the user clicks Authorize, Playable gives the AI tool an access token. The AI tool never sees the user's password.
Technical details:
Authorization code flow with PKCE, following the MCP authorization specification.
AI tools register automatically (dynamic client registration). Registration is only accepted for sign-in redirects to supported AI platforms (claude.ai, chatgpt.com and Gemini Enterprise) and to apps on the user's own computer (such as Claude Code).
Access tokens are valid for 1 hour. The AI tool renews them automatically with a refresh token that is valid for 1 month. If a connection isn't used for a month, the user has to sign in again.
All traffic is encrypted with HTTPS.
What decides what the AI tool can do
Every request is checked against three layers of access. All three must allow it.
Layer | Who controls it | What it does |
1. Workspace | Playable, on request | Playable MCP is enabled per workspace. When it's disabled, every request is refused. |
2. MCP tool permissions | Your workspace admins | Each role (or user) is given access to specific MCP actions, such as "Get campaign statistics" or "Update campaign layout". Actions a user doesn't have are hidden from the AI tool. |
3. Playable permissions | Your workspace admins | The user's normal Playable permissions and campaign restrictions still apply. A user who can't edit a campaign in Playable can't edit it through an AI tool. |
These checks happen on every single request, not just when the user connects. If you remove a permission, the next request is refused.
Workspace isolation
The AI tool only ever works inside the workspace of the user who approved the connection. Campaigns and other data from other workspaces aren't visible. A request for them is answered as if they don't exist.
What data the AI tool can access
Can read | Can't read |
Campaign names, types, status and settings | Participants, registrations and leads |
Page content, text and design of campaigns | Personal data submitted by participants |
Registration form setup (field names and options, not what people filled in) | Participant data exports |
Campaign statistics, as totals: sessions, registrations, conversion rate, devices, traffic sources, countries and time spent | Winners and prizes won |
Files in the media library | Your users, roles and account settings |
Saved color schemes and fonts | Billing information |
Playable's campaign templates and recommendations |
|
Where the data goes
When a user asks their AI tool about Playable, the data Playable returns becomes part of their conversation with that AI tool. From there, it's handled by the AI provider (for example Anthropic or OpenAI) under your company's agreement with them.
We recommend checking your AI provider's settings for data retention and model training, and using a business plan with the data protection terms your company needs.
What the AI tool can change
Draft campaigns only. Campaigns that are live, paused, expired or have ever been live are read-only. The AI tool can create a draft copy to work on instead.
No publishing. The AI tool can't publish, schedule, pause or take a campaign offline. This is always done by a person in Playable.
No deleting campaigns. The AI tool can remove pages, content blocks and form fields from draft campaigns, but not whole campaigns. Admins can turn off the delete actions per role.
No account changes. The AI tool can't change users, roles, permissions, integrations, emails or prizes.
Media uploads follow the same file-type and size rules as the Playable media library. Files can only be fetched from public HTTPS web addresses.
Logging and traceability
Playable logs every MCP action: which action was used, for which user and workspace, and whether it succeeded. Sensitive values are masked in these logs. If you need these logs, for example during an investigation, contact Playable support.
Campaign changes are recorded in the campaign's revision history in the same way as changes made in the editor, attributed to the user the AI tool acted for.
Campaigns built or edited with Playable MCP are marked. Under Campaign settings → Campaign information, they show "Created or edited with Playable MCP".
Admins can see who's connected. In Account Overview → Users, the MCP column shows which users have an active connection and which have connected before.
Revoking access
What you want | How |
A user disconnects an AI tool | In Playable: user avatar → OAuth sessions → Revoke. All tokens for that tool are revoked straight away. |
Stop a user or role from using Playable MCP | Remove the MCP tool permissions from the role or user. This applies to the next request. |
Remove a user who has left your company | Deactivate the user in Playable. Their connections stop working. |
Switch off Playable MCP for the whole workspace | Contact Playable. Once it's disabled, all requests are refused. |
Admins can currently see which users have a connection, but can't revoke another user's connection directly. Use permissions or deactivation instead.
Common questions from security reviews
Does Playable MCP give the AI tool access to anything a user can't already see? No. It uses the user's own permissions, and admins can narrow them further for MCP.
Can we allow MCP for some users only? Yes. Only users whose role (or user permissions) include MCP tool permissions can use it.
Can the AI tool act without the user asking? The AI tool calls Playable when it's working on a task for the user, and always as that user, with their permissions. Some AI tools can also run tasks on a schedule. These act as the user too, and stop working as soon as the connection is revoked.
Is our data used to train AI models? Playable doesn't send your data to AI providers for training. What happens to the data inside your AI tool depends on your AI provider's terms and your settings with them.
Can we use single sign-on (SSO)? Yes. Users sign in to Playable the same way they normally do, including through SSO where your workspace uses it.
Do users need an API key? No. There are no keys to create, store or rotate.
Need more details?
If your security team needs more information for a review, contact Playable support or your account manager.
