The address
https://mcp.allback.ai/mcp
AllBack is a remote MCP server over Streamable HTTP. Add this address as a custom connector in your AI app. Step-by-step instructions for each app are on Works in: Claude, ChatGPT, and Gemini.
Sign-in
You can start without an account. There are two modes:
- Guest mode (no token). An AI app that connects without a token gets all tools at once.
create_requestreturns anedit_keyand aclaim_url. The AI app passesrequest_idandedit_keyto every other tool. A guest form sends no email and takes at most 3 test answers. To send it, the user opensclaim_urland confirms their email with a 6-digit code. - Signed in (OAuth). The AI app signs the user in with OAuth 2.1 and PKCE. The user enters their email and a 6-digit code. There are no passwords. The token acts as that user, and it can do what the user can do, and nothing more.
For client developers:
| Endpoint | Address |
|---|---|
| Authorization server metadata | https://mcp.allback.ai/.well-known/oauth-authorization-server |
| Protected resource metadata | https://mcp.allback.ai/.well-known/oauth-protected-resource/mcp |
| Dynamic client registration | Supported |
| Client ID metadata documents (CIMD) | Supported |
| Issuer in the redirect (RFC 9207) | Supported |
Tools
| Tool | What it does | Main inputs |
|---|---|---|
create_request | Makes a request, or with kind: "form" a form with one open link. Returns a preview link and a test link, and a form's open_link. | title, form, kind, due_at, message, reminders, verify_email |
update_request | Changes the form, the title, the due date, or the message. People keep their answers for fields that stay. | request_id, form, title, due_at |
get_request | Gets the full form and settings, for example before a change. | request_id |
list_requests | Lists the user's requests and forms. Requests have counts of done, started, and not started. Forms have their answers. | kind |
add_recipients | Adds people from a list or a CSV, prefills their links, and sends the invites. On a form, this makes it a request. | request_id, recipients, csv, send_invites |
get_status | Shows who is done, who opened but is not done (and what is missing), and who did not open. | request_id |
get_insights | For a request: the funnel, the question where people stop, and how long the form takes. For a form: answers each day and the finish rate. | request_id |
send_reminders | Reminds people who are not done. Nobody gets two reminders within 12 hours. | request_id, message, emails |
export_results | Gives all answers as CSV and a download link. File links work for 7 days. | request_id |
share_open_link | Gives one link that anyone can fill. Needs a claimed request. | request_id, enabled |
close_request | Stops new answers and reminders, for a request or a form. Deletes nothing. reopen opens it again. | request_id, reopen |
In guest mode, every tool except create_request and list_requests also takes edit_key.
Every tool has a title, a readOnlyHint, and an openWorldHint. Results include structuredContent. The server sends instructions on connect, so the AI app knows the normal order: create, preview, add people, then status, reminders, and export.
Reminders
Automatic reminders go only to people who are not done:
- With a due date, the default is
["-3d", "-1d", "0d"]: 3 days before, 1 day before, and on the due day. - Without a due date, the default is
["+3d", "+7d"]after the invite. - Set
reminders_off: trueto send none. Each email has a link to stop reminders.
Requests and forms
There are two kinds, with the same tools:
- A request goes to a list of people. Each person gets a personal, prefilled link, and AllBack reminds the people who are not done.
- A form (
create_requestwithkind: "form") has one open link for anyone: a post, a newsletter, a website button, or a printed QR code. There is no list, no reminders, and no due date. Answers are unlimited on every plan.
Pick a form when the user does not know who will answer. Call add_recipients on a form, and it becomes a request: it keeps its open link and its answers. For safety, forms do not open inside other websites.
The form JSON
The form input is JSON: blocks, pages, logic, themes, and an optional custom design. See the form schema for all field types and options.
A typical conversation
- The user says: "Collect bios and headshots from these 24 speakers by October 9."
- The AI app calls
create_requestand shows the preview link. - The user says "Looks good." The AI app calls
add_recipientswith the list or a CSV. - Later the user asks "Who is still missing?" The AI app calls
get_status, andsend_remindersif the user wants. - At the end,
export_resultsgives one clean sheet.
Limits
- Forms and answers are unlimited, within the fair use policy.
- Forms that ask for passwords, one-time codes, card numbers, or bank details are refused.
- Guest forms that nobody claims are deleted after 30 days.
Without MCP
No connector in your app? Use the Any AI link: paste one prompt, and your AI gives you a link that opens your form. For the terminal, use the CLI.