Skip to content

Is the LeadTap.me MCP server safe? Security and data

The LeadTap.me MCP server acts only on the account behind the credential, never deletes, never buys and never turns a webhook on, asks Claude to confirm before every write, and logs which tool was called but never the arguments or the results.

There are five things the LeadTap.me MCP server never does, by design.

  • It never acts on an account other than the credential’s. The account comes from the credential, never from the arguments of a tool.
  • It never deletes anything. There are no delete tools.
  • It never buys anything. Store tools give links; the purchase happens in the portal, in the customer’s own session.
  • It never turns a webhook on. A webhook that Claude creates or points at a new URL starts off; the account owner gets an email and only the owner turns it on, in the portal. The email says what the webhook is for (the CRM, meaning every lead in the account, or one lead page), names its host and its events, and carries a link to revoke the connected app’s access if the owner did not ask for it.
  • It never sends your data to a third party on its own. It answers only the client that asked, with that account’s data. Lead data leaves LeadTap.me through a webhook only after the account owner turned that webhook on.

Every write tool is marked so that Claude asks you before calling it. That covers saving a draft, publishing, pausing a page, changing a link, changing where an object sends people, spending a bought QR code, and adding or changing a webhook. Publishing a page makes it public; a webhook sends lead data to a third party once it is on.

Annotation Tools What Claude does
readOnlyHint: true The 17 read tools Calls them without asking
readOnlyHint: false, destructiveHint: false Tools that create, such as create_form, create_qr_code or create_crm_webhook Asks first
readOnlyHint: false, destructiveHint: true Tools that replace or publish Asks first

A LeadTap.me webhook sends lead data to a URL the customer chooses, and only after the account owner turns it on in the portal. The CRM webhook sends every lead in the account; a page webhook sends one lead page’s submissions. Claude asks the customer for the URL and never guesses it. The URL must be https, on a public host, with no credentials in it. After creating a webhook, Claude sees only its host, never the full URL or the signing secret again, and it cannot delete a webhook. See how LeadTap.me webhooks work.

Answers, names and notes typed by your leads are returned as data. The server tells Claude, in its instructions and in each CRM tool’s description, to treat them as data and never as instructions.

The server allows 60 calls per minute per credential and answers 429 with Retry-After above that. Every call is logged for support with the account, the credential, the tool, success or error code, and duration; never the arguments or the results. Expired OAuth codes and tokens are purged daily.

Revoke the credential in the portal: Account & Billing → Connected apps for OAuth, Account & Billing → Claude & API for API tokens. Access stops immediately. See authentication.