What the Recharm connector can do, and what it can’t
Written for the IT or security team asked to approve the Recharm MCP connector for Claude. It covers where the server runs, how users sign in, every tool it exposes, the data involved, and the controls you have to restrict it.
- Server
- mcp.recharm.com
- Sign-in
- OAuth, per user
- Tools
- 7 read · 2 publish
- Last reviewed
- 2026-10-09
The short answer
Four questions every review asks
Where does it run?
On Recharm’s servers, at a single HTTPS endpoint. Nothing is installed on the user’s machine. The plugin that ships the connector is a public repository of markdown files and a three-line config pointing at the server.
What actions can it perform?
Seven tools are read-only: identify the user, list brands and labels, search clips, fetch preview frames. Two tools publish: they render a brief or report the user composed and put it at an unlisted Recharm URL. There is no delete, no edit, no settings access.
What data does it touch?
Advertising footage and its tags. This is content made to run publicly on Meta, TikTok and YouTube, and it is already visible to anyone in the Meta Ad Library. No customer, financial or credential data lives in a Recharm library.
What guardrails do we have?
Allowlist or block the connector for your Claude organisation, deny the two publish tools by name to make it strictly read-only, keep per-call human approval on, and revoke any user’s grant from Recharm. Access never exceeds what the user already has in the Recharm app.
Architecture
A hosted server behind OAuth
MCP (Model Context Protocol) is the open standard Claude, ChatGPT and Cursor use to call external tools. The Recharm connector is a remote MCP server. Your AI client sends tool calls over HTTPS, the server checks the user’s OAuth token, and answers only from brands that token is entitled to.
Sign-in uses the standard OAuth authorisation flow. The user is sent to Recharm in their browser, logs in with their existing account, and approves access. The AI client receives a token scoped to that user. No password is ever shared with the AI client, and no shared API key is created.
- 01
Your Claude client
Claude desktop, claude.ai, Claude Code or another MCP client approved by your organisation. Holds the OAuth token. Asks the user before each tool call.
- 02
HTTPS to https://mcp.recharm.com/mcp
The only network destination the connector uses. Standard TLS. Each request carries the user’s bearer token.
- 03
Recharm MCP server
Validates the token, resolves the user’s brand permissions, and serves the nine tools listed below. Same permission model as the Recharm web app.
- 04
Recharm account data
Clip libraries, labels and published briefs for the brands the user can access. Nothing outside the user’s Recharm account is reachable.
Tool inventory
All nine tools, with access marked
This is the complete list the server exposes as of plugin version 0.1.20. After installation your Claude client shows the same list with each tool’s input schema, so it can be verified independently.
| Tool | Access | What it does | Data involved |
|---|---|---|---|
| whoami | Read | Returns the id and email of the user who authorised the connection. | The connecting user’s own identity |
| list_brands | Read | Lists the brand libraries the signed-in user is already entitled to see in the Recharm app. | Brand names |
| get_brand_info | Read | Returns a brand’s display name, description, industry and website. | Public brand profile |
| list_labels | Read | Returns the label taxonomy a team has applied to its clips (scene type, creator, product and so on). | Tagging vocabulary |
| search_clips_visually | Read | Semantic search over a brand’s clip library. Returns ranked clips with metadata, preview and download links. | Ad footage metadata and media links |
| get_clip_poster_image | Read | Returns one still frame from a clip as a JPEG. | Ad footage frame |
| get_clip_sprite_image | Read | Returns a grid of frames sampled across a clip as a JPEG, so the AI can check what happens in it. | Ad footage frames |
| save_brief | Write | Renders a finished footage brief (scene names, descriptions and chosen clips) and publishes it to an unlisted Recharm share URL. | A brief the user composed, plus clip previews |
| save_html_file | Write | Publishes an HTML report produced during a session, such as a footage-gap or creator report, to an unlisted Recharm share URL. | A report the user composed |
“Write” here means publishing a page to an unlisted Recharm share URL. No tool modifies or deletes existing data. Denying the two write tools at the client makes the connector read-only.
The data
Advertising content, built to be seen
A Recharm library holds a brand’s ad footage: creator videos, product b-roll, finished ads, and the labels a team applies to find them. Its purpose is to be cut into ads that run publicly on Meta, TikTok and YouTube. Every finished ad is also indexed by the Meta Ad Library and TikTok Creative Center for anyone to view.
- Not in a library. Customer records, order data, payment details, credentials, source code, internal documents.
- Personal data returned. Only the connecting user’s own id and email, via whoami. Creators appearing in footage have licensed that footage for advertising use.
- What leaves your Claude client. Search phrases, brand names, clip ids, and the text of a brief being published. Not chat history, not attached files, not results from other tools.
- In transit and at rest. TLS between the client and Recharm. Library data is stored and governed exactly as it is for the Recharm web app, under the same privacy policy.
Out of reach
What the connector cannot do
- Delete, edit, re-tag or upload clips, raw videos or labels.
- Change account settings, billing, seats, user roles or brand permissions.
- Reach any brand the signed-in user cannot already open in the Recharm app.
- Run code, read files, or touch anything on the user’s computer. The server is remote and the plugin is plain text.
- Access email, calendars, documents, code repositories or any other system. The connector only talks to Recharm.
- Send messages, post to ad platforms or publish anywhere other than an unlisted Recharm share URL.
Guardrails
Controls available to your admins
Most of these live in the Claude client your organisation already manages, so they apply before a request ever reaches Recharm.
Allow or block the connector centrally
Claude Team and Enterprise admins decide which connectors members can add. Claude Code accepts a managed settings file that allowlists MCP servers by name, so the connector can be rolled out to a group or kept off entirely.
Block individual tools
Every tool has a stable name. A client-side deny rule on the two publish tools turns the connector into a strictly read-only integration without any change on Recharm’s side.
Every call can be approved by a human
By default Claude asks before each tool call. Publishing a brief is a distinct, named action that the user sees and confirms. Nothing is published silently.
Per-user OAuth grants you can revoke
Each person authorises with their own Recharm login. Removing a user from the Recharm account ends their access. No shared API keys exist to leak or rotate.
Scope follows existing Recharm permissions
The connector cannot widen anyone’s access. Brand-level permissions set in the Recharm app are the ceiling for what the AI can see.
One egress domain
All connector traffic goes to mcp.recharm.com over HTTPS. Clip previews and share pages are served from Recharm’s storage. Nothing else needs to be on an allowlist.
Example: read-only rollout in Claude Code
A managed settings file that enables the connector and denies both publish tools. Tool names follow the pattern mcp__Recharm__<tool>.
{
"enabledMcpjsonServers": ["Recharm"],
"permissions": {
"deny": [
"mcp__Recharm__save_brief",
"mcp__Recharm__save_html_file"
]
}
}Questions we get
From security reviews so far
- Is this an AI tool that can take actions on our systems?
- No. The AI runs inside your approved Claude client. The connector only gives it a way to search a Recharm clip library and publish a brief back to Recharm. It has no access to your network, devices, identity provider or other SaaS.
- What is the worst case if a user’s Claude session is compromised or manipulated?
- The attacker could read the ad footage that user can already see in Recharm, and publish a brief or report to an unlisted Recharm URL. They could not delete anything, change settings, reach other brands or exfiltrate data to a third-party destination. Revoking the user’s access in Recharm closes the window.
- How sensitive is the data?
- The library contains advertising footage: creator videos, product b-roll and finished ads made to be shown publicly on Meta, TikTok and YouTube, and indexed in the Meta Ad Library and TikTok Creative Center. It holds no customer data, financial data, credentials or source code. The only personal data the connector returns is the connecting user’s own email.
- Who can open a published brief?
- Anyone with the link. Links are unlisted and unguessable, and they contain what the user chose to put in them: scene descriptions and previews of ad clips. If your policy requires publishing to be off, deny the two publish tools at the client and the connector becomes read-only.
- Does the connector install software on the laptop?
- No. The Recharm plugin is a public, MIT-licensed repository of markdown skill files and a three-line config that points at the hosted server. There is no binary, no background process and no local credential store beyond the OAuth token your Claude client already manages.
- Does Recharm see our Claude conversations?
- Only what the AI sends as tool inputs: search phrases, brand names and the contents of a brief being published. Chat history, attached files and other tool results stay in your Claude client. How Anthropic handles that data is governed by your Claude plan.
- How do we audit what was done?
- Every tool call is visible in the user’s Claude session. Published briefs are listed in the Recharm app under the brand they belong to. For a log of connector activity for your account, contact us at the address below.
- Can we try it before approving it?
- Yes. Install the plugin against a trial Recharm account with placeholder footage. After the OAuth step your Claude client lists all nine tools with their descriptions and input schemas, so you can inspect exactly what is exposed.
Verify it yourself
Nothing here needs to be taken on trust
- 01Read the plugin source. The repository is public and MIT licensed. The connector config is the file .mcp.json, which contains only the server URL.
- 02Install against a trial account. After the OAuth step, the connector view in Claude lists every tool with its description and input schema. Compare it to the table above.
- 03Watch the network. The only destination is mcp.recharm.com. Deny the publish tools and confirm that no write path remains.
- 04Ask us for anything not covered here: hosting details, data retention, subprocessors or a completed security questionnaire.
Resources
Links for the review file
Still have a question for the review?
Send it to support@recharm.com. We answer security questionnaires and can walk your team through the connector on a call.