Endorsal for AI agents
Endorsal automates collecting and displaying customer testimonials and reviews, building social proof widgets for a business's site, used by marketing teams growing customer trust signals. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Endorsal.
Pull testimonials for a widget
List testimonials tagged for a campaign so they can be shown on a wall of love widget.
Check a contact's testimonial history
Get a contact's past testimonials before sending them a new review request.
Confirm before deleting a testimonial
Require approval before deleting a testimonial, since it removes published social proof.
26 Endorsal actions, graded by risk.
Every Endorsal action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
17Look things up. Allowed by default.
- endorsal.get_tagGet Tag
- endorsal.list_tagsList Tags
- endorsal.get_widgetGet Widget
- endorsal.get_contactGet Contact
- endorsal.list_widgetsList Widgets
- endorsal.list_all_tagsList All Tags
- endorsal.list_contactsList Contacts
- endorsal.get_testimonialGet Testimonial
- endorsal.list_propertiesList Properties
- endorsal.search_contactsSearch Contacts
- endorsal.get_wall_of_loveGet Wall of Love
- endorsal.list_testimonialsList Testimonials
- endorsal.search_testimonialsSearch Testimonials
- endorsal.list_tag_testimonialsList Tag Testimonials
- endorsal.get_auto_request_campaignGet AutoRequest Campaign
- endorsal.list_contact_testimonialsList Contact Testimonials
write
6Create and change things. Allow, or ask the user first.
- endorsal.create_tagCreate Tag
- endorsal.create_contactCreate Contact
- endorsal.update_contactUpdate Contact
- endorsal.create_testimonialCreate Testimonial
- endorsal.update_testimonialUpdate Testimonial
- endorsal.tag_testimonialTag Testimonial
destructive
3Delete, cancel or archive. Ask first, or deny outright.
- endorsal.delete_tagDelete Tag
- endorsal.archive_contactArchive Contact
- endorsal.delete_testimonialDelete Testimonial
Endorsal in three steps.
- 01Your users connect EndorsalThey add their Endorsal api key on Arc0 Connect, under your brand. It goes straight into the vault.
- 02You set the rulesReads run, writes like “create Tag” can wait for the user, and “delete Tag” can be denied outright.
- 03Any agent can actYour agent calls Endorsal through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('endorsal', { read: 'allow', write: 'ask', // create_tag destructive: 'deny', // delete_tag }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Endorsal connects.
Users add their Endorsal api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
The same Endorsal connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Endorsal from any agent.
Endorsal and Arc0, answered.
Can I use Endorsal with Claude, ChatGPT or Cursor?
Yes. Connect Endorsal to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Endorsal actions you allow.
How do users connect Endorsal?
Users add their Endorsal api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.
Which Endorsal actions can my agent take?
26 in total: 17 read, 6 write and 3 destructive, such as “create Tag”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Endorsal?
Yes. Actions like “delete Tag” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Endorsal too?
Yes. The same Endorsal connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Endorsal into your agent.
Your users connect Endorsal once, under your brand. Your agent gets 26 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan