# Perisclaw plugin & MCP server

Canonical URL: https://docs.perisclaw.com/mcp-server

You can use your Perisclaw WhatsApp from **ChatGPT, Codex, Claude, Cursor**,
and other compatible AI clients. Ask it to *“summarize my unread chats,”*
*“reply to Sarah,”* or *“find the address Priya sent last month,”* and it works
through your existing assistant.

In ChatGPT and Codex, **Perisclaw is an installable plugin**. The plugin
bundles two parts: Perisclaw’s live WhatsApp connector, powered by its **MCP
server**, and a skill that teaches the client safe WhatsApp workflows. Other AI
clients can connect directly to the same MCP server.

This is the mirror image of [connecting apps](/connecting-apps): there,
Perisclaw uses your other tools; here, your other tools use Perisclaw.

**Info: It is still your own WhatsApp**

  Everything happens on your own WhatsApp, through your private server. No
  second copy of your account is created, and the same sending safeguards that
  apply in chat apply here too.

## ChatGPT and Codex

Install the **Perisclaw plugin** from the Plugins directory, connect your
Perisclaw account, and choose **Read only** or **Read + write** access. The
public listing appears after OpenAI approves it.

During the developer preview, enable developer mode and add the production MCP
URL shown on the **MCP** page in your Perisclaw dashboard. This preview
connection uses the same consent screen and WhatsApp tools as the plugin.

## Other MCP clients

Clients such as Claude Desktop and Claude.ai support one-click connectors:

### 1. Add Perisclaw's connector

In your AI client, add a new connector or MCP server and paste the
Perisclaw MCP address from the **MCP** page in your
dashboard.

**Done when:**
The client shows Perisclaw as a new connection.

### 2. Sign in

The client opens a Perisclaw login in your browser. Because you are
already signed in to the dashboard, you just see a consent screen.

**Done when:**
The consent screen names the client requesting access.

### 3. Choose what it can do

Pick an access level, **Read only** or
** Read + write**, then approve.

**Done when:**
The client can now use your WhatsApp tools.

## Choose the right access level

| Access level     | What the client can do                                                                                      |
| ---------------- | ----------------------------------------------------------------------------------------------------------- |
| **Read only**    | Search and read your chats, contacts, and groups. Cannot send or change anything. The safe default.         |
| **Read + write** | Everything in Read only, **plus** sending messages, reacting, managing chats, groups, labels, and contacts. |

**Warning: Start with Read only**

  Widen access only when you specifically want the client to send messages or
  make changes. Permission changes apply to new connections, so reconnect an
  existing client to pick up a wider grant. Approving a wider grant
  automatically signs that client’s older sessions out.

## What you can do from your AI client

* **Catch up:** *“Summarize everything I missed in my work groups today.”*
* **Search:** *“Find the address Priya sent me last month.”*
* **Reply** (with Read + write): *“Reply to Sarah that Tuesday at 3 works.”*
* **Organize** (with Read + write): *“Label all the unanswered client chats
  ‘follow up.’”*

The plugin’s bundled skill resolves recipients before acting, treats message
content as data rather than instructions, and asks before sending or making
destructive changes. Standalone coding clients such as Claude Code or Cursor
can layer the same open Perisclaw workflow skill on top of a plain MCP
connection.

## Staying in control

* **Scoped to you:** a connection only ever reaches your own WhatsApp; it
  cannot touch anyone else’s.
* **Sends are still gated:** messages sent from an AI client go through the
  same per-chat permission and [mode](/chat-modes) checks as everything else.
* **See every grant:** the dashboard labels each connected client as Read
  only or Read & write, and flags clients that still have live sessions at
  both levels.
* **Revoke anytime:** remove a connection from the dashboard and the client
  immediately loses access.

For the bigger picture on what your assistant can and cannot touch, see
[Privacy & security](/privacy-and-security) and
[Permissions & access](/permissions-and-access).

### [Connect apps to Perisclaw](/connecting-apps)

The mirror image: let Perisclaw use your other tools from WhatsApp.

### [Review every grant](/permissions-and-access)

See and revoke what each connected client can do.