# Is the LeadTap.me MCP server safe? Security and data

> What the LeadTap.me MCP server never does (act on another account, delete, buy, turn a webhook on), how Claude confirms before writes, how webhooks send lead data only after the owner turns them on, rate limits and what is logged.

Source: https://docs.leadtap.me/mcp/security/ · Last updated: 2026-10-09

The LeadTap.me MCP server acts only on the account behind the credential, never deletes, never buys and never turns a webhook on, asks Claude to confirm before every write, and logs which tool was called but never the arguments or the results.

## What the LeadTap.me MCP server never does

There are five things the LeadTap.me MCP server never does, by design.

- **It never acts on an account other than the credential's.** The account comes from the credential, never from the arguments of a tool.
- **It never deletes anything.** There are no delete tools.
- **It never buys anything.** Store tools give links; the purchase happens in the portal, in the customer's own session.
- **It never turns a webhook on.** A webhook that Claude creates or points at a new URL starts off; the account owner gets an email and only the owner turns it on, in the portal. The email says what the webhook is for (the CRM, meaning every lead in the account, or one lead page), names its host and its events, and carries a link to revoke the connected app's access if the owner did not ask for it.
- **It never sends your data to a third party on its own.** It answers only the client that asked, with that account's data. Lead data leaves LeadTap.me through a webhook only after the account owner turned that webhook on.

## Claude confirms before every write

Every write tool is marked so that Claude asks you before calling it. That covers saving a draft, publishing, pausing a page, changing a link, changing where an object sends people, spending a bought QR code, and adding or changing a webhook. Publishing a page makes it public; a webhook sends lead data to a third party once it is on.

| Annotation | Tools | What Claude does |
|---|---|---|
| `readOnlyHint: true` | The 17 read tools | Calls them without asking |
| `readOnlyHint: false`, `destructiveHint: false` | Tools that create, such as `create_form`, `create_qr_code` or `create_crm_webhook` | Asks first |
| `readOnlyHint: false`, `destructiveHint: true` | Tools that replace or publish | Asks first |

## Webhooks and your lead data

A LeadTap.me webhook sends lead data to a URL the customer chooses, and only after the account owner turns it on in the portal. The CRM webhook sends every lead in the account; a page webhook sends one lead page's submissions. Claude asks the customer for the URL and never guesses it. The URL must be https, on a public host, with no credentials in it. After creating a webhook, Claude sees only its host, never the full URL or the signing secret again, and it cannot delete a webhook. See [how LeadTap.me webhooks work](https://docs.leadtap.me/concepts/webhooks/).

## Lead data is treated as data

Answers, names and notes typed by your leads are returned as data. The server tells Claude, in its instructions and in each CRM tool's description, to treat them as data and never as instructions.

## Rate limits and logging

The server allows 60 calls per minute per credential and answers `429` with `Retry-After` above that. Every call is logged for support with the account, the credential, the tool, success or error code, and duration; never the arguments or the results. Expired OAuth codes and tokens are purged daily.

## How to cut access

Revoke the credential in the portal: **Account & Billing → Connected apps** for OAuth, **Account & Billing → Claude & API** for API tokens. Access stops immediately. See [authentication](https://docs.leadtap.me/mcp/authentication/).

## Related pages

- [Privacy policy](https://app.leadtap.me/privacy-policy)
- [Terms of service](https://app.leadtap.me/terms-of-service)
