GuidesConnect and integrate

Review lifecycle performance with Customer.io

Connect the correct Customer.io region with non-sensitive read access and prepare a weekly lifecycle brief.

The Lifecycle performance review template turns campaign, newsletter, segment, and delivery evidence into a weekly decision brief. It follows the emails marketing skill: measure the lifecycle system, keep audience privacy explicit, propose the next experiment or draft, and leave sends to a person.

Enable and connect Customer.io

An operator must first enable MANAGED_MCP_CUSTOMERIO_ENABLED. A Customer.io account admin must also turn on Customer.io MCP under Settings → AI. Then open Work on Repeat's Connections page and choose the card matching the account's data region:

  • Customer.io (US) uses https://mcp.customer.io/mcp.
  • Customer.io (EU) uses https://mcp-eu.customer.io/mcp.

The two explicit cards prevent an EU account from being silently routed to the US endpoint. Customer.io accounts have one region for all workspaces.

Both connections are OAuth-only and request just read, Customer.io's required default scope. Work on Repeat does not request read:sensitive, write, write:live, or configure. The person authorizing selects the workspaces and cannot grant more authority than their Customer.io role already has.

Current beta boundary

Customer.io is connection-only until exact authenticated schemas are captured for its current cio_* tool surface. The checked-in policy exposes no runnable tools—not even cio_read_api, cio_schema, or cio_auth_status. This matters because the hosted server can cover the Journeys UI API and CDP Data Pipelines API, including writes and deletes when broader scopes are granted.

After schema review, the first manifest should remain read-only. Draft and live changes must be classified separately, and sending, subscription changes, suppression changes, deletion, and workspace configuration should stay blocked or require explicit approval.

Privacy, sessions, and recovery

The read scope excludes profile attributes marked sensitive. Keep Customer.io's Allow MCP to access sensitive data and Allow MCP to edit live data toggles off for this routine. Customer.io checks the account-level MCP toggle on every call, and each user manages and revokes their own connected sessions under personal settings.

If authorization expires or is revoked, Work on Repeat moves the connection to reauthorization_required; reconnect the same regional card to update the saved connection in place. Customer.io's published MCP guidance does not describe a separate per-call credit budget, so Work on Repeat does not present one. Account availability, workspaces, roles, privacy toggles, and OAuth scopes remain the operative limits.

Choose Lifecycle performance review, set the reporting window, attach the regional Customer.io connection, and prove one manual run after reviewed tools ship. See Customer.io's official MCP guide and account region guide for current tools, scopes, permissions, sessions, and data residency.

On this page

Edit this page on GitHub