Customer.io for AI agents

Customer.io sends targeted messages across email, SMS, and push based on customer behavior, letting a team automate lifecycle marketing campaigns. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

MarketingAPI keyMCP + RESTcustomer.io
AUDIT LOG · CUSTOMER.IOPOLICY: acme-support
09:41:07 · claude · u_8f2read
customer_io.list_snippets
List Snippets✓ allowed · 212ms
09:41:08 · claude · u_8f2read
customer_io.track_page
Track Page View✓ allowed · 164ms
09:41:09 · claude · u_8f2write
customer_io.create_alias
Create Profile Alias✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
customer_io.unsubscribe_delivery
Unsubscribe from Delivery✕ blocked · policy: deny
EVERY CUSTOMER.IO CALL, ON THE RECORD
01 · USE CASES

What agents do in Customer.io.

01

Track a customer event

Track an event for a customer, like a completed purchase, to trigger a message.

02

Check a segment's membership

Check who belongs to a segment before deciding to send them a targeted campaign.

03

Confirm before suppressing a profile

Suppress a customer profile once approved, stopping all future messages to them.

02 · ACTIONS

24 Customer.io actions, graded by risk.

Every Customer.io action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

17

Look things up. Allowed by default.

  • customer_io.get_trigger
    Get Trigger
  • customer_io.get_messages
    Get Messages
  • customer_io.get_segments
    Get Segments
  • customer_io.get_triggers
    Get Broadcast Triggers
  • customer_io.get_webhooks
    Get Customer.io Workspace Webhooks
  • customer_io.list_snippets
    List Snippets
  • customer_io.get_integrations
    Get Integrations
  • customer_io.list_collections
    List Collections
  • customer_io.list_newsletters
    List Newsletters
  • customer_io.list_ip_addresses
    List IP Addresses
  • customer_io.get_segment_details
    Get Segment Details
  • customer_io.get_segment_membership
    Get Segment Membership
  • customer_io.list_transactional_messages
    List Transactional Messages
  • customer_io.track_page
    Track Page View
  • customer_io.track_event
    Track Event
  • customer_io.track_screen
    Track Screen View
+ 1 MORE

write

6

Create and change things. Allow, or ask the user first.

  • customer_io.send_batch
    Send Batch CDP Calls
  • customer_io.create_alias
    Create Profile Alias
  • customer_io.add_person_to_group
    Add Person to Group
  • customer_io.trigger_broadcast
    Trigger Broadcast
  • customer_io.report_push_events
    Report Push Notification Events
  • customer_io.customer_io_suppress_person
    Suppress Customer Profile

destructive

1

Delete, cancel or archive. Ask first, or deny outright.

  • customer_io.unsubscribe_delivery
    Unsubscribe from Delivery
03 · HOW IT WORKS

Customer.io in three steps.

  1. 01Your users connect Customer.ioThey add their Customer.io api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Profile Alias” can wait for the user, and “unsubscribe from Delivery” can be denied outright.
  3. 03Any agent can actYour agent calls Customer.io through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('customer_io', {
  read: 'allow',
  write: 'ask',        // create_alias
  destructive: 'deny',  // unsubscribe_delivery
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Customer.io connects.

Users add their Customer.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Customer.io connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Customer.io from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Customer.io and Arc0, answered.

Q01

Can I use Customer.io with Claude, ChatGPT or Cursor?

Yes. Connect Customer.io to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Customer.io actions you allow.

Q02

How do users connect Customer.io?

Users add their Customer.io api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Customer.io actions can my agent take?

24 in total: 17 read, 6 write and 1 destructive, such as “create Profile Alias”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Customer.io?

Yes. Actions like “unsubscribe from Delivery” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Customer.io too?

Yes. The same Customer.io connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Customer.io into your agent.

Your users connect Customer.io once, under your brand. Your agent gets 24 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan