# Zulink

## MCP Server

> Category: AI agents

---

## Pages


### Getting started

- [What is Zulink?](https://docs.zulink.co/getting-started/what-is-zulink)
- [Quickstart](https://docs.zulink.co/getting-started/quickstart)
- [Custom domains](https://docs.zulink.co/getting-started/custom-domains)

### Links

- [Creating links](https://docs.zulink.co/links/creating-links)
- [Targeting](https://docs.zulink.co/links/targeting)
- [A/B testing](https://docs.zulink.co/links/a-b-testing)
- [Link security](https://docs.zulink.co/links/link-security)
- [Social previews](https://docs.zulink.co/links/social-previews)

### Design and analytics

- [OpenGraph Designer](https://docs.zulink.co/design-and-analytics/opengraph-designer)
- [Analytics](https://docs.zulink.co/design-and-analytics/analytics)

### Team and plans

- [Members and invitations](https://docs.zulink.co/team-and-plans/members-and-invitations)
- [Roles and permissions](https://docs.zulink.co/team-and-plans/roles-and-permissions)

### AI agents

- [MCP Server](https://docs.zulink.co/ai-agents/mcp-server)

---

# MCP Server

Zulink speaks the [Model Context Protocol](https://modelcontextprotocol.io), so you can let an AI agent create and maintain your short links, read your analytics and build preview designs for you. Connect your client once, then describe what you need in plain language. The agent works in the same projects you already use in the dashboard, so everything it does shows up there right away.

## Connecting

The server is hosted at `https://zulink.co/mcp`. There is nothing to install and no key to paste anywhere.

### Claude Code

```bash
claude mcp add --transport http zulink https://zulink.co/mcp
```

### Codex

Add the server to `~/.codex/config.toml`:

```toml name="config.toml"
[mcp_servers.zulink]
url = "https://zulink.co/mcp"
auth = "oauth"
```

Then sign in once:

```bash
codex mcp login zulink
```

### Claude Desktop, Cursor and other clients

Most other clients read a JSON config:

```json name="mcp.json"
{
	"mcpServers": {
		"zulink": {
			"type": "http",
			"url": "https://zulink.co/mcp"
		}
	}
}
```

The first request opens your browser so you can sign in to Zulink and approve access. Your client remembers the login and renews it on its own from then on.

## What you are approving

The consent screen lists exactly what the client is asking for:

- View your projects.
- View project domains.
- View short links, and create, update and delete them.
- View link analytics.
- View OpenGraph designs, and create, update and delete them.
- Stay connected until you revoke access.

You can approve a subset. A client that was only granted reading will be told a write is not permitted rather than quietly doing something else.

On top of that, an agent never gets more rights than you have. Your role in each project applies unchanged: if you may not delete links there, neither may the agent, and a project you are not a member of does not exist as far as the connection is concerned. See [Roles and permissions](https://docs.zulink.co/team-and-plans/roles-and-permissions).

## Start with a project

Everything happens inside one project, so that is the first thing to settle. Ask your agent to list your projects and pick the one you want to work in. The listing tells it which plan the project is on and what this particular connection is actually allowed to do there, so it knows up front whether, say, targeting is available at all.

## What to ask for

From there on you can just say what you want:

- "Create a short link on go.example.com that points at our pricing page and tag it *spring*."
- "Which of our links got the most clicks in the last 30 days, and from which countries?"
- "Send Android visitors of the download link to Play and everyone else to the website."
- "Add UTM parameters for the newsletter to all links tagged *newsletter*."
- "Build a preview design with our logo, the title on the left and a dark background, and use it on the pricing link."
- "Show me what that design looks like."

## What the agent can do

| Area | What it covers |
| --- | --- |
| Projects and domains | List your projects with their plan and limits, list domains and their verification status |
| Links | Search and page through links, read a single link, create, update and delete links, check whether a path is free, read the Open Graph data of a destination |
| Analytics | Read the click analytics of a project for a time range your plan allows |
| Designs | List and read designs, create them, change canvas and elements, reorder or delete elements, upload images, render a design as a PNG preview |

Individual links and designs can also be handed to the agent as a reference, so you can point at one thing instead of describing it.

## Good to know

**Passwords are never exposed.** A link's password is not part of what the agent can read. It only sees whether one is set, and it can set a new one if you ask.

**Changes are guarded against overwriting.** To change something, an agent has to have read its current state first. If the link or design changed in the meantime, because a colleague edited it in the dashboard, the write fails and the agent has to re-read and try again. Nobody's work is silently replaced.

**Deleting takes an explicit confirmation.** Removing a link, a design or a canvas element is a separate, deliberate step, not something that happens as a side effect of a vague instruction.

**Your plan still applies.** An agent cannot switch on a feature your plan does not include; it will be told so, the same way the interface would tell you.

**Every change is real.** There is no separate sandbox, so treat it like working in the dashboard yourself. Deleted links stop resolving immediately.

**There are rate limits.** A connection may make up to 120 requests a minute, of which up to 30 may be changes, and up to 10 may be expensive operations such as uploading an image or rendering a preview. An agent that runs into a limit simply waits a moment before continuing.

## Ending a connection

Disconnect the server in your client, either by removing it or by logging out of it, and the access it holds stops working immediately, not at the end of some grace period.

The connection is also tied to the sign-in you approved it with. Ending that session under **Account settings → Active sessions**, or signing out on that device, cuts the agent's access along with it. Reconnecting always means going through the browser consent screen again.
