Endorsal for AI agents

Endorsal automates collecting and displaying customer testimonials and reviews, building social proof widgets for a business's site, used by marketing teams growing customer trust signals. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

MarketingAPI keyMCP + RESTendorsal.io
AUDIT LOG · ENDORSALPOLICY: acme-support
09:41:07 · claude · u_8f2read
endorsal.list_tags
List Tags✓ allowed · 212ms
09:41:08 · claude · u_8f2read
endorsal.get_tag
Get Tag✓ allowed · 164ms
09:41:09 · claude · u_8f2write
endorsal.create_tag
Create Tag✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
endorsal.delete_tag
Delete Tag✕ blocked · policy: deny
EVERY ENDORSAL CALL, ON THE RECORD
01 · USE CASES

What agents do in Endorsal.

01

Pull testimonials for a widget

List testimonials tagged for a campaign so they can be shown on a wall of love widget.

02

Check a contact's testimonial history

Get a contact's past testimonials before sending them a new review request.

03

Confirm before deleting a testimonial

Require approval before deleting a testimonial, since it removes published social proof.

02 · ACTIONS

26 Endorsal actions, graded by risk.

Every Endorsal action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

17

Look things up. Allowed by default.

  • endorsal.get_tag
    Get Tag
  • endorsal.list_tags
    List Tags
  • endorsal.get_widget
    Get Widget
  • endorsal.get_contact
    Get Contact
  • endorsal.list_widgets
    List Widgets
  • endorsal.list_all_tags
    List All Tags
  • endorsal.list_contacts
    List Contacts
  • endorsal.get_testimonial
    Get Testimonial
  • endorsal.list_properties
    List Properties
  • endorsal.search_contacts
    Search Contacts
  • endorsal.get_wall_of_love
    Get Wall of Love
  • endorsal.list_testimonials
    List Testimonials
  • endorsal.search_testimonials
    Search Testimonials
  • endorsal.list_tag_testimonials
    List Tag Testimonials
  • endorsal.get_auto_request_campaign
    Get AutoRequest Campaign
  • endorsal.list_contact_testimonials
    List Contact Testimonials
+ 1 MORE

write

6

Create and change things. Allow, or ask the user first.

  • endorsal.create_tag
    Create Tag
  • endorsal.create_contact
    Create Contact
  • endorsal.update_contact
    Update Contact
  • endorsal.create_testimonial
    Create Testimonial
  • endorsal.update_testimonial
    Update Testimonial
  • endorsal.tag_testimonial
    Tag Testimonial

destructive

3

Delete, cancel or archive. Ask first, or deny outright.

  • endorsal.delete_tag
    Delete Tag
  • endorsal.archive_contact
    Archive Contact
  • endorsal.delete_testimonial
    Delete Testimonial
03 · HOW IT WORKS

Endorsal in three steps.

  1. 01Your users connect EndorsalThey add their Endorsal api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Tag” can wait for the user, and “delete Tag” can be denied outright.
  3. 03Any agent can actYour agent calls Endorsal through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('endorsal', {
  read: 'allow',
  write: 'ask',        // create_tag
  destructive: 'deny',  // delete_tag
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Endorsal connects.

Users add their Endorsal api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Endorsal connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Endorsal from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Endorsal and Arc0, answered.

Q01

Can I use Endorsal with Claude, ChatGPT or Cursor?

Yes. Connect Endorsal to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Endorsal actions you allow.

Q02

How do users connect Endorsal?

Users add their Endorsal api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Endorsal actions can my agent take?

26 in total: 17 read, 6 write and 3 destructive, such as “create Tag”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Endorsal?

Yes. Actions like “delete Tag” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Endorsal too?

Yes. The same Endorsal connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Endorsal into your agent.

Your users connect Endorsal once, under your brand. Your agent gets 26 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan