Docs

Braze's Remote MCP Server: What to Track

Braze's new remote MCP server lets Claude, ChatGPT and Cursor act on analytics via OAuth — track every tool call before an agent trigger fires.

Analytics

Braze has replaced its original, locally-installed MCP server — the one that needed a package, a config file, and an API key sitting on someone’s machine — with a remote-hosted version that connects over OAuth instead. There’s no local install and no long-lived key to leak: a client authenticates with the signed-in user’s own Braze dashboard credentials, inherits that user’s existing permissions and OAuth scopes, and Braze has verified compatibility with Claude, ChatGPT, Copilot, Gemini CLI, Codex, and Cursor. Beta support extends to the Campaigns and Segments API and Operator Connect, meaning an agent can now not just query behavioural data but act on it — building a segment or triggering a campaign step through natural language.

That last part is the one worth pausing on. Querying analytics through an AI agent is a read-only risk: a wrong answer is embarrassing but reversible. An MCP server with beta write access to Campaigns and Segments turns a wrong answer into a wrong action — a segment built on a misread filter, or a campaign step triggered against the wrong audience, sent to real users before anyone reviews it. Because access is scoped to the signed-in user’s own permissions, the blast radius of a mistake is exactly as large as that person’s Braze role allows, which for anyone with campaign-send permissions is not small.

Unlike the old local server, this one leaves less for a team to configure wrong — no stray API key in a config file, no forgotten local install running stale code. What it doesn’t remove is the need to know what any given agent session actually did, since a natural-language request through a chat client doesn’t leave the same audit trail a dashboard action does by default.

Data Points to Track

  • OAuth session-to-action mapping, linking each MCP tool call back to the authenticated user and the client (Claude, ChatGPT, Cursor, etc.) that issued it
  • Write-capable tool calls specifically, flagged separately from read-only analytics queries, given the beta Campaigns/Segments/Operator Connect access
  • Segment or campaign changes with no corresponding dashboard session, as a signal the change originated from an agent rather than a human clicking through the UI
  • Permission scope per connected user, since agent capability is inherited entirely from the human’s existing Braze role — anyone with send permissions gives an agent send permissions
  • Deprecated local-server usage, if any team member is still running the August 2025 local MCP server, which is deprecated and won’t receive further updates

Setup Steps

  1. Inventory who has connected the Braze MCP server and cross-reference against who holds campaign-send or segment-write permissions in Braze itself.
  2. Migrate off the deprecated local MCP server — remove the local package and config file, and revoke any standing API key it depended on.
  3. Require a review step for any agent-proposed segment or campaign action during the Campaigns/Segments/Operator Connect beta, rather than allowing direct execution.
  4. Log MCP tool calls (or confirm Braze’s own audit logging covers them) so a campaign change can be traced back to the agent session that made it.
  5. Restrict OAuth scopes for agent-connected accounts to the minimum needed, rather than connecting an admin-level account for convenience.

Actionable Insights

Moving to OAuth removes a real class of leaked-credential risk, but it also makes an agent’s reach exactly as wide as the human account behind it — which is easy to forget when the interface is a chat window instead of a dashboard. Treat every MCP-connected account as a live extension of that person’s permissions, review write actions during the beta rather than trusting them by default, and make sure a campaign that goes out because an agent decided to send it is traceable back to the request that caused it.

Expert help

Need help tracking this in your app?

Our team sets up analytics pipelines for mobile and web teams every day. Talk to us and get your first events flowing in under an hour.

Talk to an expert