SerpBeats MCP

Technical summary of the SerpBeats MCP server: supported AI agents, authorization with OAuth or a personal token, the 12 read-only tools and the data they serve, revoking access and limits.

A read-only MCP server that opens the data of the projects in your SerpBeats account to an AI agent. In every paid plan at no extra cost.

Server: https://serpbeats.com/mcp · Transport: Streamable HTTP (MCP), POST https://serpbeats.com/mcp · Authorization: OAuth 2.1 + PKCE or a personal token · Access: Read-only · Available in: Every paid plan; not in the free trial

Clients

Any client that speaks streamable HTTP MCP can connect. Setup is ready for the ones below. Claude (OAuth): Settings → Connectors → Add custom connector. URL: https://serpbeats.com/mcp. Authentication: Sign in now, OAuth client: Register automatically. · ChatGPT (OAuth): Settings → Apps → add a custom MCP server (turn on Developer mode first if needed). URL: https://serpbeats.com/mcp, authentication: OAuth. · Gemini app (OAuth): Settings → Connected Apps → Add a custom app. URL: https://serpbeats.com/mcp. Google currently offers this only in the US, on personal accounts and in English. · Claude Code (Token): claude mcp add · Codex (Token): ~/.codex/config.toml · Cursor (Token): ~/.cursor/mcp.json · Gemini CLI (Token): gemini mcp add · Other MCP clients (Token): URL and an Authorization header

OAuth 2.1: sign in with your account

Where: You add the connector in the client; SerpBeats' approval page opens, you sign in with your account and allow it. No token to create. · Flow: Authorization Code + PKCE (S256); public client, no client secret · Client registration: Dynamic Client Registration (RFC 7591): POST /oauth/register, the app registers itself · Endpoints: /oauth/authorize · /oauth/token · Discovery: /.well-known/oauth-authorization-server · /.well-known/oauth-protected-resource · Scope: mcp:use · Lifetimes: Access token 1 hour, refresh token 30 days · Allowed redirect hosts: claude.ai, claude.com, chatgpt.com, chat.openai.com, platform.openai.com, gemini.google.com, Google's oauth-redirect relays, localhost and 127.0.0.1

Personal token

Where: Signed in, on the /ai-connection page: Create token · Use: Authorization: Bearer sbk_… header · Lifetime: 30, 90 or 365 days, or none; chosen when you create it · Ability: agent:read (read only) · Storage: Shown once; only its hash is kept · Count: At most 5 On every call the account is checked for an active paid plan. No or invalid credentials get 401; the free trial and an ended plan get 403.

Services and the data they serve

12 tools are active, all read-only. Data comes from stored scans, with no live lookups, and every answer carries the date of its data (data_as_of). Every tool except list_projects takes project: an id, a domain or a name; it may be left out when the account has a single project. list_projects: The account's projects: id, name, domain, country, tracked keyword count, date of the last scan. · get_project_summary: Project summary: distribution over top 100 / 50 / 30 / 10 / 3 / 1 (cumulative), how many keywords improved, dropped or left the rankings, visibility, average position, estimated monthly clicks and their changes. · get_keyword_rankings: Tracked keywords that are listed in Google: position, previous position, change, monthly volume, difficulty, intent, ranking page, estimated clicks, AI Overview and SERP features. sort=dropped_out returns the ones that left the rankings. · get_keyword_history: One keyword: daily positions (7–90 days), best and worst position, the ranking page and the days it changed, 12 months of volume, the AI Overview (text, sources, whether it cites the site), the results page (top 20) and where the rivals stand. · get_site_audit: Site health from the latest crawl: score and its change, pages scanned, counts of errors / warnings / recommendations, four area scores, Core Web Vitals. · get_audit_issues: Every site issue: severity, area, how many pages it hits, the points fixing it adds. For one issue: what it means, how to fix it and the affected pages. · get_audit_pages: The crawled pages: status code, score, load time, size, click depth, word count, title, description, H1, issues and the evidence for each. url opens one page in full. · get_audit_links: What the crawl found between pages: broken links (by target, with every page that carries the link and its anchor text), redirected links, redirect chains, pages hidden from search engines. · get_competitors: Tracked rivals (visibility, average position, who is ahead on shared keywords) and suggestions for rivals that keep appearing beside the site and are not tracked yet. · get_ai_visibility: Visibility in AI answers: score (0–100), score per platform and its change, the weekly trend, and for every tracked question cited, not cited or no data. · get_local_seo: The business on Google Maps (rating, reviews, profile gaps) and, per local keyword, the average rank over the scanned points, the share of top-3 points, the share by distance, the leaders and the strongest rivals. · get_report_data: One call for a report: distribution, movements, site health, rivals and AI visibility.

Revoking access

OAuth app: On the /ai-connection page, Remove access next to the app. All of the app's keys are revoked at that moment. · Token: On the same page, Delete next to the token. The token stops working at once. · Plan ends: When the plan ends or the account is deactivated, every connection closes (403). · Log: Which tool was called and when is recorded; the data returned is not kept.

Limits

Request rate: 60 requests a minute and 1,500 an hour per connection; beyond that, 429. · Answer size: At most about 120 KB; long lists are paged with limit and offset. · Rows per call: get_keyword_rankings and get_ai_visibility up to 100, get_audit_pages and get_audit_links up to 50. · History: get_keyword_history covers 7 to 90 days. · Data freshness: From the daily scans; no live lookups. Parts gone stale are marked in the answer (age_days, stale_sections). · Reading: No tool starts a scan, spends credits, changes a setting or deletes anything. · Tokens: At most 5 per account; OAuth access key 1 hour, refresh 30 days. · Out of scope: Keywords that were never listed are only counted, never listed. Without local keywords (local SEO) or an AI Bundle (AI visibility) the tool returns no data.

Are you an AI agent? Read the SerpBeats product and plan summary.