Integrations

Run your program from your assistant

A hosted MCP server, so Claude, ChatGPT and any MCP-capable assistant can work with your program in plain language. Seventeen read tools, twelve guarded write tools, and a confirmation card before any change. You never paste a key. Nothing that moves money is on the surface. Included in every plan, the trial too.

Published 3 September 2026. Every claim on this page was read off the documentation linked below on 3 September 2026. Written by Jimi Barkway, who built AffiliateRail. Jimi has run affiliate programs from both sides of the link. Corrections go to support@affiliaterail.com.

What an agent holding your token can and cannot doAn agent with an AffiliateRail token can read and write your program. There is no path from it to money, because AffiliateRail never holds any.An AI agentholding your API tokenAffiliateRailreads and writes the programACannot move money, because there is none here to movePayouts run only through your own rail’s credentials, which are never handed to a model.

01 Tools

What can an assistant do with it?

Ask who your top partners are this month, which commissions wait for approval over $50, who has gone quiet, why a payout failed. Seventeen read tools cover partners, customers, commissions, applications, revenue, reports, payouts, flows, referrals, risk, resources and messaging.

Allow writes and it can act, with your confirmation: approve or reject a commission, decide an application, close a risk flag, invite a partner, tidy the resources shelf, send a campaign. Amounts arrive formatted as money.

What is on the surface

  • Seventeen read tools

    top_partners, pending_commissions, idle_partners, payout_status, report and the rest.

  • Twelve guarded writes

    The review queues, invitations, risk flags, the resources shelf, campaigns and sequences.

  • Two resources

    program://current and catalog://events.

02 Connecting

How does it connect without a key?

You press Connect. AffiliateRail opens in your browser, you sign in the way you always do, and you press Allow. The assistant receives a short-lived token: one hour, refreshed on its own. The credential behind it is made on our side and listed under Settings, API keys, named after the assistant.

Revoke that one row and that assistant stops on its next request. Claude Code and other clients that can send a header can skip the browser with a key you made yourself.

claude mcp add --transport http affiliaterail \
  https://mcp.affiliaterail.com/mcp
Claude Code, one line. It opens the same Allow screen on first use.

03 Boundaries

What can it never touch?

Moving money: executing payout batches, editing payout connections, changing bank details. Minting credentials: API keys, webhook secrets, domain settings. Deleting partners, customers or programs. Billing and team roles. None of it is on the surface, whatever you allowed.

An assistant holding your token cannot move funds, because AffiliateRail never holds any. Every write it does make lands in your audit log, named as the assistant's connection.

Settings, API keys: the scope picker for a new key, with read, write, the narrower write scopes, mcp:read and mcp:write, and a test-mode box
Settings, API keys: the scope picker for a key you make yourself, and the list where every connected assistant appears.

Step by step

Connected in about a minute

The server URL is https://mcp.affiliaterail.com/mcp. It is part of every plan, the free trial included.

  1. Add the connector

    Claude: Settings, Connectors, Add custom connector, with the server URL. ChatGPT: Settings, Apps, Developer mode, Create app, OAuth.

  2. Press Connect, then Allow

    AffiliateRail opens in your browser behind your normal sign-in. Nothing is created until you press Allow.

  3. Keep writes on needs approval

    Leave the read tools on Always allow. Keep every write tool on Needs approval, so you confirm each change.

  4. Ask

    Who went quiet? Who should I pay this month? Is my program healthy? The recipes page shows which tools answer each.

Said plainly

What it does, and does not do

Both lists are read off the same docs pages as everything else here.

It does

  • Reads your live program

    Answers come from your ledger, not the model's memory. Numbers arrive formatted as money.

  • Acts in the review queues, with a card first

    Names resolved, amounts formatted, a field-level list of what would change. Nothing applies until you agree.

  • Connects with OAuth 2.1 and PKCE

    Dynamic client registration, one-hour access tokens, thirty-day refresh tokens, audience-bound.

  • Attributes every write

    The audit log names the assistant's connection, with before and after state.

  • Comes with a skill

    The AffiliateRail skill teaches Claude how to run a program well, connected or not.

It does not

  • Move money

    Payout batches, connections and bank details are not on the surface. There is no money here to move.

  • Mint credentials

    No API keys, webhook secrets or domain settings over MCP.

  • Delete partners, customers or programs

    The dashboard, with a signed-in human, is the only place.

  • See a pasted key

    The credential is made on our side. The assistant gets a short-lived token.

Questions

Common questions

Which assistants work?

Claude, ChatGPT, Claude Code, Cursor and anything that speaks MCP over streamable HTTP. The server URL is https://mcp.affiliaterail.com/mcp.

Is it safe to give an assistant access?

The most a connected assistant can do is approve a commission into your payable queue or send a campaign, and both need your explicit yes. It cannot move money, because AffiliateRail never holds any.

Is the MCP server on every plan?

Yes, the free trial included.

How do I disconnect one assistant?

Settings, API keys. Revoke the row named after the assistant. That one stops on its next request and no other is touched.

Sources

Where these facts come from

Every claim on this page was read off the product's own documentation on the date shown. The docs change with the product, and then this page is behind until we fix it. Email support@affiliaterail.com and we will correct it and move the date.

Start

Fourteen days to see it work, with nothing on the line

No card. Cancel in one click. Full refund within 30 days of your first payment.