Secure Apollo access for AI agents

Go-to-market data and outreach across contacts, accounts, deals, sequences, calls, tasks, and buyer intent via Apollo's MCP server.

Through Apollo, agents can search prospects and companies, read and update the contacts, accounts, deals, and tasks your team tracks, run outreach sequences, and read call recordings and conversation insights. Every call runs through your policies and is logged for audit.

Server URL: https://mcp.apollo.io/mcp

Credential modes

Apollo supports per-org dynamic registration only, so there is no app to create on Apollo's side and no client ID or secret to enter. See Credential modes for how it compares with Use SecureAuth's app and Bring your own app.

Before you begin

  • An Apollo account with access to the records your agents need. Apollo's own role and permission model still applies.
  • Administrator access to your Agent Authority workspace, to add the resource.

Setup

  1. In the Agent Authority console, go to Resources and click Add Resource.
  2. Select Apollo from the catalog.
  3. On Choose how to install Apollo, click Per-org dynamic registration. Selecting it adds the resource right away with its tools pre-configured.

Dynamic client registration

When you add the resource, the gateway registers its own OAuth client with Apollo, the credential that lets it sign users in. An agent can only reach what the person who signed in could already reach.

Two Apollo specifics are worth knowing:

  • Apollo returns its own granted scope list during registration, and that list replaces whatever the gateway asked for. The table under Requested scopes is the request, not necessarily the grant.
  • Apollo's authorization-server metadata endpoint can be slow to answer on a cold path. If adding the resource fails with couldn't reach https://mcp.apollo.io/mcp, retry. That message covers a transient fetch failure as well as a genuinely unreachable host.

Verify the connection

The gateway syncs the Apollo tools automatically. To check the connection end to end, ask your agent to run a request:

Search my Apollo contacts for people at Acme

If your contacts come back, the connection is working.

How users connect

Access is per user. Each additional user connects their own Apollo account the first time their agent calls an Apollo tool: the gateway returns a sign-in link, the user authorizes once, and the tools work from then on. Go to Connections to manage linked accounts.

Credit-consuming tools

Several Apollo tools spend account credits on a successful match, and Apollo's own tool descriptions instruct the agent to confirm with the user before calling them. Credits spent cannot be refunded. The enrichment tools are the ones to watch:

ToolCost
apollo_organizations_enrich1 credit per match
apollo_organizations_bulk_enrich1 credit per matched record
apollo_people_match1 credit per match
apollo_people_bulk_match1 credit per matched record

apollo_email_account_purchase_create is not credit-based: it purchases a sending mailbox and incurs a charge on the Apollo account.

Available tools

Every Apollo tool listed below carries one of the built-in tags read-only, write, or destructive. A tool that Apollo adds later has none until the catalog updates. See limits.

Apollo exposes a large surface. The gateway syncs the authoritative list, with each tool's full input schema, on the first connection. What your agents see is Apollo's own current set, which may differ from the summary below.

AreaTools
People and company dataapollo_mixed_people_api_search, apollo_mixed_companies_search, apollo_people_match, apollo_people_bulk_match, apollo_organizations_enrich, apollo_organizations_bulk_enrich, apollo_organizations_lookup, apollo_organizations_job_postings
Contactsapollo_contacts_search, apollo_contacts_create, apollo_contacts_bulk_create, apollo_contacts_update
Accountsapollo_accounts_create, apollo_accounts_bulk_create, apollo_accounts_update
Dealsapollo_deals_search, apollo_deals_show, apollo_deals_create
Sequences and campaignsapollo_sequences_create, apollo_sequences_update, apollo_emailer_campaigns_search, apollo_emailer_campaigns_show, apollo_emailer_campaigns_approve, apollo_emailer_campaigns_add_contact_ids, apollo_emailer_campaigns_remove_or_stop_contact_ids, apollo_emailer_campaigns_activity_feed, apollo_emailer_schedules_index
Email messagesapollo_emailer_messages_search, apollo_emailer_messages_get_content, apollo_emailer_messages_create, apollo_emailer_messages_send_now, apollo_emailer_messages_email_send_status, apollo_email_accounts_index
Calls and conversationsapollo_phone_calls_search, apollo_phone_calls_create, apollo_phone_calls_update, apollo_conversations_search, apollo_conversations_get_transcript, apollo_conversations_get_insights, apollo_conversations_get_recording_links
Tasksapollo_tasks_search, apollo_tasks_show, apollo_tasks_create, apollo_tasks_bulk_create, apollo_tasks_update, apollo_tasks_complete, apollo_tasks_skip
Lists and labelsapollo_labels_index, apollo_labels_create, apollo_labels_update, apollo_labels_add_entity_ids_to_label_names, apollo_labels_remove_entity_ids_from_label_names
Context centerapollo_context_center_show, apollo_context_center_show_product, apollo_context_center_create_product, apollo_context_center_update_product, apollo_context_center_create_profile, apollo_context_center_update_profile
Website visitorsapollo_website_visitors_domain_aggregates, apollo_website_visitor_domain_tracker_index, apollo_website_visitor_domain_tracker_update, apollo_website_visitor_domain_tracker_install_script, apollo_website_visitor_domain_tracker_send_install_email
Purchasingapollo_domain_purchase_index, apollo_email_account_purchase_index, apollo_email_account_purchase_create
Administrationapollo_users_api_profile, apollo_users_search, apollo_fields_index, apollo_usage_stats_credit_usage_stats, apollo_analytics_sync_report, apollo_webhook_result_show, apollo_survey_submit, apollo_feedback_log, apollo_prompts_suggest

Requested scopes

The gateway requests Apollo's full advertised scope set automatically when it registers the client, so there is nothing for you to configure. Apollo decides what to grant, and the scopes it returns during registration replace the requested list.

Apollo publishes 70 scopes. They group as follows:

Scope groupWhy
read_user_profile, users_listIdentify the signed-in user and resolve assignees
contacts_search, contact_read, contact_write, contact_updateRead and maintain contacts
account_write, account_update, account_bulk_createRead and maintain accounts
people_match, organizations_enrich, and their bulk variantsEnrichment, these are the credit-consuming calls
opportunity_read, opportunities_list, opportunity_writeDeals
emailer_*, email_accounts_listCampaigns, sequences, and individual emails
conversation_intelligence_*, phone_call_*Calls, recordings, transcripts, and insights
tasks_list, tasks_create, agent_taskTasks
lists_*, tags_list, custom_field*, custom_objects_*Lists, labels, and custom schema
website_visitor*, website_visitors_readBuyer-intent and visitor identification
domain_purchase_*, email_account_purchase_*Purchasing sending domains and mailboxes
api_usage_stats_read, credit_usage_stats_read, report_syncUsage reporting

If your org does not want the full set, trim apolloScopes() in the catalog entry, since the gateway only ever requests what that list contains.

Policy examples

Every org is created with a seeded Allow all rule at the bottom of the list, so any call your own rules don't match stays allowed. Express restrictions as deny rules above it. New rules are added at the top, so a fresh deny outranks it automatically. See Rule order.

  • Read-only access: deny apollo_*_create, apollo_*_update, apollo_*_bulk_create, apollo_tasks_complete, apollo_tasks_skip, apollo_emailer_messages_send_now, apollo_emailer_campaigns_approve, apollo_emailer_campaigns_add_contact_ids, apollo_emailer_campaigns_remove_or_stop_contact_ids, apollo_labels_add_entity_ids_to_label_names, apollo_labels_remove_entity_ids_from_label_names, apollo_context_center_create_product, apollo_context_center_update_product, apollo_context_center_create_profile, apollo_context_center_update_profile, and apollo_website_visitor_domain_tracker_send_install_email.
  • Stop agents spending credits: deny apollo_people_match, apollo_people_bulk_match, apollo_organizations_enrich, and apollo_organizations_bulk_enrich.
  • Stop agents spending money: deny apollo_email_account_purchase_create.
  • No outbound sending: deny apollo_emailer_messages_send_now and apollo_emailer_campaigns_approve.
  • Keep call contents out of agent context: deny apollo_conversations_get_transcript and apollo_conversations_get_recording_links.
  • Block destructive tools: add a deny rule with the built-in destructive tag (Tools pill) for this resource (MCP pill).

Next steps

  • Create a policy – start from the credit-protection pattern in Policy examples above.
  • Policies – how first-match-wins rule order and the seeded Allow all rule interact.

On this page