Secure Apollo access for AI agents
Go-to-market data and outreach across contacts, accounts, deals, sequences, calls, tasks, and buyer intent via Apollo's MCP server.
Through Apollo, agents can search prospects and companies, read and update the contacts, accounts, deals, and tasks your team tracks, run outreach sequences, and read call recordings and conversation insights. Every call runs through your policies and is logged for audit.
Server URL: https://mcp.apollo.io/mcp
Credential modes
Apollo supports per-org dynamic registration only, so there is no app to create on Apollo's side and no client ID or secret to enter. See Credential modes for how it compares with Use SecureAuth's app and Bring your own app.
Before you begin
- An Apollo account with access to the records your agents need. Apollo's own role and permission model still applies.
- Administrator access to your Agent Authority workspace, to add the resource.
Setup
- In the Agent Authority console, go to Resources and click Add Resource.
- Select Apollo from the catalog.
- On Choose how to install Apollo, click Per-org dynamic registration. Selecting it adds the resource right away with its tools pre-configured.
Dynamic client registration
When you add the resource, the gateway registers its own OAuth client with Apollo, the credential that lets it sign users in. An agent can only reach what the person who signed in could already reach.
Two Apollo specifics are worth knowing:
- Apollo returns its own granted scope list during registration, and that list replaces whatever the gateway asked for. The table under Requested scopes is the request, not necessarily the grant.
- Apollo's authorization-server metadata endpoint can be slow to answer on a cold path. If adding the resource fails with
couldn't reach https://mcp.apollo.io/mcp, retry. That message covers a transient fetch failure as well as a genuinely unreachable host.
Verify the connection
The gateway syncs the Apollo tools automatically. To check the connection end to end, ask your agent to run a request:
Search my Apollo contacts for people at AcmeIf your contacts come back, the connection is working.
How users connect
Access is per user. Each additional user connects their own Apollo account the first time their agent calls an Apollo tool: the gateway returns a sign-in link, the user authorizes once, and the tools work from then on. Go to Connections to manage linked accounts.
Credit-consuming tools
Several Apollo tools spend account credits on a successful match, and Apollo's own tool descriptions instruct the agent to confirm with the user before calling them. Credits spent cannot be refunded. The enrichment tools are the ones to watch:
| Tool | Cost |
|---|---|
apollo_organizations_enrich | 1 credit per match |
apollo_organizations_bulk_enrich | 1 credit per matched record |
apollo_people_match | 1 credit per match |
apollo_people_bulk_match | 1 credit per matched record |
apollo_email_account_purchase_create is not credit-based: it purchases a sending
mailbox and incurs a charge on the Apollo account.
Available tools
Every Apollo tool listed below carries one of the built-in tags read-only, write, or destructive. A tool that Apollo adds later has none until the catalog updates. See limits.
Apollo exposes a large surface. The gateway syncs the authoritative list, with each tool's full input schema, on the first connection. What your agents see is Apollo's own current set, which may differ from the summary below.
| Area | Tools |
|---|---|
| People and company data | apollo_mixed_people_api_search, apollo_mixed_companies_search, apollo_people_match, apollo_people_bulk_match, apollo_organizations_enrich, apollo_organizations_bulk_enrich, apollo_organizations_lookup, apollo_organizations_job_postings |
| Contacts | apollo_contacts_search, apollo_contacts_create, apollo_contacts_bulk_create, apollo_contacts_update |
| Accounts | apollo_accounts_create, apollo_accounts_bulk_create, apollo_accounts_update |
| Deals | apollo_deals_search, apollo_deals_show, apollo_deals_create |
| Sequences and campaigns | apollo_sequences_create, apollo_sequences_update, apollo_emailer_campaigns_search, apollo_emailer_campaigns_show, apollo_emailer_campaigns_approve, apollo_emailer_campaigns_add_contact_ids, apollo_emailer_campaigns_remove_or_stop_contact_ids, apollo_emailer_campaigns_activity_feed, apollo_emailer_schedules_index |
| Email messages | apollo_emailer_messages_search, apollo_emailer_messages_get_content, apollo_emailer_messages_create, apollo_emailer_messages_send_now, apollo_emailer_messages_email_send_status, apollo_email_accounts_index |
| Calls and conversations | apollo_phone_calls_search, apollo_phone_calls_create, apollo_phone_calls_update, apollo_conversations_search, apollo_conversations_get_transcript, apollo_conversations_get_insights, apollo_conversations_get_recording_links |
| Tasks | apollo_tasks_search, apollo_tasks_show, apollo_tasks_create, apollo_tasks_bulk_create, apollo_tasks_update, apollo_tasks_complete, apollo_tasks_skip |
| Lists and labels | apollo_labels_index, apollo_labels_create, apollo_labels_update, apollo_labels_add_entity_ids_to_label_names, apollo_labels_remove_entity_ids_from_label_names |
| Context center | apollo_context_center_show, apollo_context_center_show_product, apollo_context_center_create_product, apollo_context_center_update_product, apollo_context_center_create_profile, apollo_context_center_update_profile |
| Website visitors | apollo_website_visitors_domain_aggregates, apollo_website_visitor_domain_tracker_index, apollo_website_visitor_domain_tracker_update, apollo_website_visitor_domain_tracker_install_script, apollo_website_visitor_domain_tracker_send_install_email |
| Purchasing | apollo_domain_purchase_index, apollo_email_account_purchase_index, apollo_email_account_purchase_create |
| Administration | apollo_users_api_profile, apollo_users_search, apollo_fields_index, apollo_usage_stats_credit_usage_stats, apollo_analytics_sync_report, apollo_webhook_result_show, apollo_survey_submit, apollo_feedback_log, apollo_prompts_suggest |
Requested scopes
The gateway requests Apollo's full advertised scope set automatically when it registers the client, so there is nothing for you to configure. Apollo decides what to grant, and the scopes it returns during registration replace the requested list.
Apollo publishes 70 scopes. They group as follows:
| Scope group | Why |
|---|---|
read_user_profile, users_list | Identify the signed-in user and resolve assignees |
contacts_search, contact_read, contact_write, contact_update | Read and maintain contacts |
account_write, account_update, account_bulk_create | Read and maintain accounts |
people_match, organizations_enrich, and their bulk variants | Enrichment, these are the credit-consuming calls |
opportunity_read, opportunities_list, opportunity_write | Deals |
emailer_*, email_accounts_list | Campaigns, sequences, and individual emails |
conversation_intelligence_*, phone_call_* | Calls, recordings, transcripts, and insights |
tasks_list, tasks_create, agent_task | Tasks |
lists_*, tags_list, custom_field*, custom_objects_* | Lists, labels, and custom schema |
website_visitor*, website_visitors_read | Buyer-intent and visitor identification |
domain_purchase_*, email_account_purchase_* | Purchasing sending domains and mailboxes |
api_usage_stats_read, credit_usage_stats_read, report_sync | Usage reporting |
If your org does not want the full set, trim apolloScopes() in the catalog entry, since the gateway only ever requests what that list contains.
Policy examples
Every org is created with a seeded Allow all rule at the bottom of the list, so any call your own rules don't match stays allowed. Express restrictions as deny rules above it. New rules are added at the top, so a fresh deny outranks it automatically. See Rule order.
- Read-only access: deny
apollo_*_create,apollo_*_update,apollo_*_bulk_create,apollo_tasks_complete,apollo_tasks_skip,apollo_emailer_messages_send_now,apollo_emailer_campaigns_approve,apollo_emailer_campaigns_add_contact_ids,apollo_emailer_campaigns_remove_or_stop_contact_ids,apollo_labels_add_entity_ids_to_label_names,apollo_labels_remove_entity_ids_from_label_names,apollo_context_center_create_product,apollo_context_center_update_product,apollo_context_center_create_profile,apollo_context_center_update_profile, andapollo_website_visitor_domain_tracker_send_install_email. - Stop agents spending credits: deny
apollo_people_match,apollo_people_bulk_match,apollo_organizations_enrich, andapollo_organizations_bulk_enrich. - Stop agents spending money: deny
apollo_email_account_purchase_create. - No outbound sending: deny
apollo_emailer_messages_send_nowandapollo_emailer_campaigns_approve. - Keep call contents out of agent context: deny
apollo_conversations_get_transcriptandapollo_conversations_get_recording_links. - Block destructive tools: add a deny rule with the built-in
destructivetag (Tools pill) for this resource (MCP pill).
Next steps
- Create a policy – start from the credit-protection pattern in Policy examples above.
- Policies – how first-match-wins rule order and the seeded Allow all rule interact.