For IT & workspace admins
Connecting Skai MCP servers
On some platforms, adding a custom connector is gated behind an org or workspace admin. This page explains what Skai's MCP servers do, why they're safe to allow, and exactly what to enable, per platform.
Skai MCP connectors
Skai has multiple MCPs, each with different risk profiles
Reporting Connector (read-only)
Query your Skai reporting data from your AI assistant. Reporting data at various granularity levels, as well as change log data. It has no ability to add, remove, or change anything in your Skai account.
Every connection authenticates as one individual person, through Skai's own OAuth sign-in or a personal access token that expires every 90 days. There is no shared, org-wide credential.
Campaign Actions Connector (preview & approval gated)
Adjust bids, budgets, and statuses - with preview and approval before anything is applied. This MCP needs the reporting MCP installed as a prerequisite.
Every connection authenticates as one individual person, through Skai's own OAuth sign-in or a personal access token that expires every 90 days. There is no shared, org-wide credential.
Warning: We strongly recommend previewing and approving all updates made via this MCP by a person. Working with your agent in Auto Mode is not recommended.
Insights Connector (recommendations, plus experiment setup)
Forecasting, Experiments, Celeste (coming soon), Search Term analysis, Keyword Harvesting and AMC reports This connector needs the Reporting Connector installed as a prerequisite.
Most of what it does is read and summarize: opportunities, benchmarks, anomalies, and keyword or negative-keyword recommendations. Its tools also cover setting up and updating experiments, generating creative variations, and managing notification rules. It cannot change bids, budgets, or campaign statuses - those live only in the Campaign Actions Connector.
Every connection authenticates as one individual person, through Skai's own OAuth sign-in or a personal access token that expires every 90 days. There is no shared, org-wide credential.
Per platform
Where the toggle lives for admins
Steps marked from our own guide match what this site already tells your users to expect. Steps marked subject to change are our best current understanding, not a confirmed click-path. Search your admin console for a connector, plugin, or app allowlist and use Skai's OAuth Client ID (NB1XppreF8kHUVpRtrQKksayoedpfatm) wherever it asks for one.
Team, Enterprise & Enterprise+ only
- An organization owner opens Organization settings → Connectors in Claude.
- Adds a custom connector named "Skai" using the connector URL from this site's Reporting Connector, Campaign Actions Connector, or Insights Connector guide, plus the OAuth Client ID below.
- Each person on the team then connects it individually from their own Connectors settings, authorizing with their own Skai login. There's no shared credential.
From our own guide.
Quick reference
- OAuth Client ID (Claude, ChatGPT, Gemini Enterprise, Amazon Quick)
NB1XppreF8kHUVpRtrQKksayoedpfatm- Full connection guides your users are already following
- Reporting Connector setup · Campaign Actions Connector setup · Insights Connector setup
FAQ
Questions admins ask us
What data can Skai's MCP actually access?
It depends on the MCP they connect, but access is always scoped to whatever that individual user's own Skai login already permits. Connecting through an AI assistant doesn't grant anyone new data access, it only exposes what they could already see or do by logging into Skai directly.
Can a user's AI assistant change bids, budgets, or statuses without a person approving it?
The Campaign Actions Connector can adjust bids, budgets, and statuses, but every change is meant to go through a preview-and-approve step first. Skai's own guidance is: "We strongly recommend previewing and approving all updates made via this MCP by a person. Working with your agent in Auto Mode is not recommended." The Reporting Connector has no write capability at all. The Insights Connector cannot touch bids, budgets, or statuses either; it surfaces recommendations, and separately can set up experiments, creative variations, and notification rules.
What's the OAuth Client ID, and where do I put it?
NB1XppreF8kHUVpRtrQKksayoedpfatm. It goes wherever your platform's connector setup asks for a Client ID. Claude, ChatGPT, and Gemini Enterprise all use this same value. Cursor, VS Code, and other header-based clients use a personal access token instead and don't need it.
Is there a security or compliance document (SOC 2, data residency, etc.) I can review?
Skai meets some of the most stringent security and compliance standards in the industry, and we're glad to complete additional security or compliance documentation as needed. The fastest way to get a straight answer for your organization is to contact us directly, your Skai account team can walk through any infosec or compliance questions with you.
Who do I contact at Skai if I have questions this page doesn't answer?
Your organization's existing Skai account or customer success contact is the fastest path. If you don't have one, skai.io has general contact information.
Why am I suddenly getting a link to this page from one of my users?
You're probably here because a user in your organization is trying to connect Skai's MCP servers to their AI assistant (Claude, ChatGPT, Gemini, or similar) so it can pull reporting or stage changes for them. On some platforms, adding a custom connector is gated behind an org or workspace admin, and that's you, so they were told to loop you in rather than guess at it themselves.
Does enabling this cost anything, or need a separate contract?
Today, Skai clients have unlimited access to the Skai Reporting Connector for no additional cost. Campaign Actions Connector access is unlimited at no additional cost for Skai clients with a platform license agreement, subject to an additional legal amendment. The Insights Connector is newer and still in beta, so confirm its terms with your account team rather than assuming they match either of the other two. Please check with your Skai account team to confirm any specific requirements are met.
Does every person need their own login, or is this one shared credential for the whole org?
Each person authenticates individually, either through Skai's own OAuth sign-in or their own personal access token (valid 90 days, renewed at login.kenshoo.com). There's no single shared org-wide credential, so what any one person's AI assistant can see or do is exactly what that person could already see or do by logging into Skai themselves.
What about tools like Cursor or VS Code, do I need to allowlist anything for those?
Usually not. Those read a small config file with the developer's own personal access token, on their own machine, so there's typically no org-wide switch to flip. The platforms that do need something from you are the ones with a central connector or app allowlist: Claude (Team/Enterprise), ChatGPT (Business/Enterprise/Edu), and Gemini Enterprise via Google Workspace.
Can I revoke access later if I need to?
Since every connection rides an individual's own Skai login or personal access token, revoking that person's Skai account access (or declining to help them renew an expired token) ends their MCP access the same way it would end any other integration. Removing Skai from your platform's connector allowlist, where one exists, also stops any new connections.