# io.usefulapi/insightly (remote · insightly.usefulapi.io)

Read and write Insightly contacts, organisations, leads, opportunities, tasks and notes.

- Trust score: 75/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- remote · `insightly.usefulapi.io`: 75/100 (this document), [markdown](https://verifymcp.io/servers/io-usefulapi-insightly/insightly.md), [page](https://verifymcp.io/servers/io-usefulapi-insightly/insightly)

## Channel facts

- Endpoint: `https://insightly.usefulapi.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Endpoint Security**: 89/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 65/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 3794 tokens (~180/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 13/100
  - Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 90/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 71% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 21 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the io.usefulapi/insightly MCP server?

io.usefulapi/insightly is a hosted endpoint at https://insightly.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-usefulapi-insightly 'https://insightly.usefulapi.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-usefulapi-insightly": {
      "url": "https://insightly.usefulapi.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-usefulapi-insightly": {
      "type": "http",
      "url": "https://insightly.usefulapi.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-usefulapi-insightly]
url = "https://insightly.usefulapi.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-usefulapi-insightly": {
      "type": "remote",
      "url": "https://insightly.usefulapi.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-usefulapi-insightly --url 'https://insightly.usefulapi.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-usefulapi-insightly:
    url: "https://insightly.usefulapi.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-usefulapi-insightly": {
      "Transport": "http",
      "Url": "https://insightly.usefulapi.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-usefulapi-insightly -t streamable-http -u 'https://insightly.usefulapi.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-usefulapi-insightly": {
      "type": "http",
      "url": "https://insightly.usefulapi.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-04 (score 75, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-02 (score 74, +56)

- [security improvement] HTTPS: unverified → pass
- [security improvement] Authorization: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security improvement] Transport: fail → pass
- [security] First check of Authorization: partial
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Endpoint reachability: not serving MCP → reachable
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] Stability: unverified → 0.07
- [functional] Server version: 1.0.0 → 1.5.1

### 2026-10-01 (score 18, −51)

- [security regression] Endpoint reachability: reachable → not serving MCP
- [security regression] Tool safety: pass → unverified
- [security regression] Authorization: pass → unverified
- [security regression] Transport: pass → fail
- [functional regression] Capabilities: fail → unverified
- [functional regression] Tool coverage: 100 → unverified

### 2026-09-30 (score 69, +51)

- [security improvement] Authorization: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security improvement] Transport: fail → pass
- [security] First check of Judged manipulation: pass
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Destructive annotations: pass
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 71
- [functional] First check of Schema quality: good

### 2026-09-29 (score 18)

First indexed and scored.

## MCP tools (21)

### `insightly_get_current_user` (~61 tokens)

Get the current user

Fetch the user the API key belongs to (USER_ID, name, email, admin flag). A cheap way to confirm the key and pod are right, and to get your own id for owner fields. Insightly: GET /Users/Me.

### `insightly_list_users` (~99 tokens)

List users

List the users in the Insightly instance — needed to resolve OWNER_USER_ID / RESPONSIBLE_USER_ID. Insightly: GET /Users.

Input parameters:

- `count_total` (boolean): true = also return the total number of matching records (response becomes {total_count, items}).
- `skip` (integer): Records to skip, for paging.
- `top` (integer): Max records to return, 1-500 (API default 100).

### `insightly_list_records` (~295 tokens)

List or search records

List records of one type — Contacts, Organisations, Leads, Opportunities, Projects, Tasks, Events or Notes — optionally filtered by one field value and/or last-updated time. With field_name + field_value (both required together) or updated_after_utc this uses GET /<Object>/Search; otherwise GET /<Object>. Field names are Insightly's UPPER_SNAKE names, e.g. EMAIL_ADDRESS, LAST_NAME, ORGANISATION_NAME, OPPORTUNITY_STATE, LEAD_RATING, or a custom field such as Industry__c.

Input parameters:

- `brief` (boolean): true = only top-level fields (no CUSTOMFIELDS, TAGS, LINKS, ...). Smaller and faster.
- `count_total` (boolean): true = also return the total number of matching records (response becomes {total_count, items}).
- `field_name` (string): Field to filter on, e.g. EMAIL_ADDRESS.
- `field_value` (string): Value the field must equal.
- `object` (string, required): Record type.
- `skip` (integer): Records to skip, for paging.
- `top` (integer): Max records to return, 1-500 (API default 100).
- `updated_after_utc` (string): Only records updated after this time, yyyy-mm-ddThh:mm:ssZ (e.g. 2026-04-09T16:58:14Z).

### `insightly_get_record` (~72 tokens)

Get one record

Fetch a single Contact, Organisation, Lead, Opportunity, Project, Task, Event or Note by id, with its custom fields, tags and links. Insightly: GET /<Object>/{id}.

Input parameters:

- `id` (integer, required): The record's numeric id.
- `object` (string, required): Record type.

### `insightly_list_record_activity` (~205 tokens)

List a record's notes, tasks or events

List the Notes, Tasks or Events attached to one Contact, Organisation, Lead, Opportunity or Project — the activity history of that record. Insightly: GET /<Object>/{id}/Notes | Tasks | Events.

Input parameters:

- `brief` (boolean): true = only top-level fields (no CUSTOMFIELDS, TAGS, LINKS, ...). Smaller and faster.
- `count_total` (boolean): true = also return the total number of matching records (response becomes {total_count, items}).
- `id` (integer, required): The parent record's numeric id.
- `kind` (string, required): Which activity to list.
- `object` (string, required): The parent record's type.
- `skip` (integer): Records to skip, for paging.
- `top` (integer): Max records to return, 1-500 (API default 100).
- `updated_after_utc` (string): Only items updated after this time, yyyy-mm-ddThh:mm:ssZ.

### `insightly_search_by_tag` (~149 tokens)

Find records by tag

List Contacts, Organisations, Leads, Opportunities or Projects carrying a tag. Insightly: GET /<Object>/SearchByTag?tagName=.

Input parameters:

- `brief` (boolean): true = only top-level fields (no CUSTOMFIELDS, TAGS, LINKS, ...). Smaller and faster.
- `count_total` (boolean): true = also return the total number of matching records (response becomes {total_count, items}).
- `object` (string, required): Record type.
- `skip` (integer): Records to skip, for paging.
- `tag` (string, required): The tag name.
- `top` (integer): Max records to return, 1-500 (API default 100).

### `insightly_list_pipelines` (~72 tokens)

List pipelines

List the sales and project pipelines (PIPELINE_ID, name, whether for opportunities or projects). Insightly: GET /Pipelines.

Input parameters:

- `skip` (integer): Records to skip, for paging.
- `top` (integer): Max records to return, 1-500 (API default 100).

### `insightly_list_pipeline_stages` (~86 tokens)

List pipeline stages

List every pipeline stage (STAGE_ID, PIPELINE_ID, name, order) — map an opportunity's or project's STAGE_ID to a stage name. Insightly: GET /PipelineStages.

Input parameters:

- `skip` (integer): Records to skip, for paging.
- `top` (integer): Max records to return, 1-500 (API default 100).

### `insightly_list_lead_statuses` (~89 tokens)

List lead statuses

List the lead statuses defined in the instance (LEAD_STATUS_ID, name, type). Insightly: GET /LeadStatuses.

Input parameters:

- `include_converted` (boolean): Also include statuses used for converted leads.
- `skip` (integer): Records to skip, for paging.
- `top` (integer): Max records to return, 1-500 (API default 100).

### `insightly_list_lead_sources` (~70 tokens)

List lead sources

List the lead sources defined in the instance (LEAD_SOURCE_ID, name). Insightly: GET /LeadSources.

Input parameters:

- `skip` (integer): Records to skip, for paging.
- `top` (integer): Max records to return, 1-500 (API default 100).

### `insightly_create_contact` (~227 tokens)

Create a contact

Create a contact (first_name is required). Insightly: POST /Contacts.

Input parameters:

- `address_mail_city` (string)
- `address_mail_country` (string)
- `address_mail_postcode` (string)
- `address_mail_state` (string)
- `address_mail_street` (string)
- `background` (string): Background / description text.
- `custom_fields` (array): Custom field values to set.
- `email_address` (string): Primary email.
- `email_opted_out` (boolean): Opted out of email.
- `first_name` (string, required): First name (required).
- `last_name` (string): Last name.
- `organisation_id` (integer): Id of the contact's organisation.
- `owner_user_id` (integer): Owning user's id.
- `phone` (string): Business phone.
- `phone_mobile` (string): Mobile phone.
- `salutation` (string): e.g. Mr, Ms, Dr.
- `social_linkedin` (string): LinkedIn URL.
- `title` (string): Job title.

### `insightly_update_contact` (~251 tokens)

Update a contact

Update a contact. Only the fields you pass are changed (v3.1 partial update). Insightly: PUT /Contacts with CONTACT_ID.

Input parameters:

- `address_mail_city` (string)
- `address_mail_country` (string)
- `address_mail_postcode` (string)
- `address_mail_state` (string)
- `address_mail_street` (string)
- `background` (string): Background / description text.
- `contact_id` (integer, required): The contact's numeric id.
- `custom_fields` (array): Custom field values to set.
- `email_address` (string): Primary email.
- `email_opted_out` (boolean): Opted out of email.
- `first_name` (string): First name.
- `last_name` (string): Last name.
- `organisation_id` (integer): Id of the contact's organisation.
- `owner_user_id` (integer): Owning user's id.
- `phone` (string): Business phone.
- `phone_mobile` (string): Mobile phone.
- `salutation` (string): e.g. Mr, Ms, Dr.
- `social_linkedin` (string): LinkedIn URL.
- `title` (string): Job title.

### `insightly_create_organisation` (~152 tokens)

Create an organisation

Create an organisation (company). Insightly: POST /Organisations.

Input parameters:

- `address_billing_city` (string)
- `address_billing_country` (string)
- `address_billing_postcode` (string)
- `address_billing_state` (string)
- `address_billing_street` (string)
- `background` (string): Background / description text.
- `custom_fields` (array): Custom field values to set.
- `organisation_name` (string, required): Organisation name (required).
- `owner_user_id` (integer): Owning user's id.
- `phone` (string)
- `social_linkedin` (string): LinkedIn URL.
- `website` (string)

### `insightly_update_organisation` (~174 tokens)

Update an organisation

Update an organisation. Only the fields you pass are changed. Insightly: PUT /Organisations with ORGANISATION_ID.

Input parameters:

- `address_billing_city` (string)
- `address_billing_country` (string)
- `address_billing_postcode` (string)
- `address_billing_state` (string)
- `address_billing_street` (string)
- `background` (string): Background / description text.
- `custom_fields` (array): Custom field values to set.
- `organisation_id` (integer, required): The organisation's numeric id.
- `organisation_name` (string): Organisation name.
- `owner_user_id` (integer): Owning user's id.
- `phone` (string)
- `social_linkedin` (string): LinkedIn URL.
- `website` (string)

### `insightly_create_lead` (~318 tokens)

Create a lead

Create a lead (last_name is required). Insightly's schema also marks lead_status_id and lead_source_id as required — get valid ids from insightly_list_lead_statuses / insightly_list_lead_sources. Insightly: POST /Leads.

Input parameters:

- `address_city` (string)
- `address_country` (string)
- `address_postcode` (string)
- `address_state` (string)
- `address_street` (string)
- `custom_fields` (array): Custom field values to set.
- `email` (string): Email address.
- `email_opted_out` (boolean)
- `employee_count` (integer)
- `first_name` (string)
- `industry` (string)
- `last_name` (string, required): Last name (required).
- `lead_description` (string): Description / notes on the lead.
- `lead_rating` (integer): Rating, e.g. 1-5.
- `lead_source_id` (integer): Source id — see insightly_list_lead_sources.
- `lead_status_id` (integer): Status id — see insightly_list_lead_statuses.
- `mobile` (string)
- `organisation_name` (string): Company name (free text — leads are not linked to organisations).
- `owner_user_id` (integer)
- `phone` (string)
- `responsible_user_id` (integer)
- `salutation` (string)
- `title` (string): Job title.
- `website` (string)

### `insightly_update_lead` (~301 tokens)

Update a lead

Update a lead. Only the fields you pass are changed. Insightly: PUT /Leads with LEAD_ID.

Input parameters:

- `address_city` (string)
- `address_country` (string)
- `address_postcode` (string)
- `address_state` (string)
- `address_street` (string)
- `custom_fields` (array): Custom field values to set.
- `email` (string): Email address.
- `email_opted_out` (boolean)
- `employee_count` (integer)
- `first_name` (string)
- `industry` (string)
- `last_name` (string): Last name.
- `lead_description` (string): Description / notes on the lead.
- `lead_id` (integer, required): The lead's numeric id.
- `lead_rating` (integer): Rating, e.g. 1-5.
- `lead_source_id` (integer): Source id — see insightly_list_lead_sources.
- `lead_status_id` (integer): Status id — see insightly_list_lead_statuses.
- `mobile` (string)
- `organisation_name` (string): Company name (free text — leads are not linked to organisations).
- `owner_user_id` (integer)
- `phone` (string)
- `responsible_user_id` (integer)
- `salutation` (string)
- `title` (string): Job title.
- `website` (string)

### `insightly_create_opportunity` (~230 tokens)

Create an opportunity

Create a sales opportunity (opportunity_name is required). Insightly: POST /Opportunities.

Input parameters:

- `bid_amount` (number): Bid value.
- `bid_currency` (string): ISO currency code, e.g. USD.
- `bid_duration` (integer): Number of bid periods (for non-fixed bid types).
- `bid_type` (string): BID_TYPE — how the bid is priced, using a value your Insightly instance accepts.
- `category_id` (integer): Opportunity category id.
- `custom_fields` (array): Custom field values to set.
- `forecast_close_date` (string): Forecast close date, as "yyyy-MM-dd HH:mm:ss" in UTC (e.g. 2026-04-10 21:15:00).
- `opportunity_details` (string): Description.
- `opportunity_name` (string, required): Opportunity name (required).
- `organisation_id` (integer): Id of the linked organisation.
- `owner_user_id` (integer)
- `probability` (integer): Win probability, 0-100.
- `responsible_user_id` (integer)

### `insightly_update_opportunity` (~257 tokens)

Update an opportunity

Update an opportunity's value, probability, dates, owner or details. Only the fields you pass are changed. Insightly: PUT /Opportunities with OPPORTUNITY_ID.

Input parameters:

- `bid_amount` (number): Bid value.
- `bid_currency` (string): ISO currency code, e.g. USD.
- `bid_duration` (integer): Number of bid periods (for non-fixed bid types).
- `bid_type` (string): BID_TYPE — how the bid is priced, using a value your Insightly instance accepts.
- `category_id` (integer): Opportunity category id.
- `custom_fields` (array): Custom field values to set.
- `forecast_close_date` (string): Forecast close date, as "yyyy-MM-dd HH:mm:ss" in UTC (e.g. 2026-04-10 21:15:00).
- `opportunity_details` (string): Description.
- `opportunity_id` (integer, required): The opportunity's numeric id.
- `opportunity_name` (string): Opportunity name.
- `organisation_id` (integer): Id of the linked organisation.
- `owner_user_id` (integer)
- `probability` (integer): Win probability, 0-100.
- `responsible_user_id` (integer)

### `insightly_create_task` (~301 tokens)

Create a task

Create a task (title is required). Insightly requires OWNER_USER_ID and COMPLETED on a task: if owner_user_id is omitted it is filled with the API key's own user (via GET /Users/Me), and completed defaults to false. Insightly: POST /Tasks.

Input parameters:

- `category_id` (integer): Task category id.
- `completed` (boolean): Whether the task is done.
- `custom_fields` (array): Custom field values to set.
- `details` (string): Task description.
- `due_date` (string): Due date, as "yyyy-MM-dd HH:mm:ss" in UTC (e.g. 2026-04-10 21:15:00).
- `opportunity_id` (integer): Link the task to this opportunity.
- `owner_user_id` (integer): Owner's user id.
- `percent_complete` (integer)
- `priority` (integer): Priority number.
- `project_id` (integer): Link the task to this project.
- `responsible_user_id` (integer): Assignee's user id.
- `start_date` (string): Start date, as "yyyy-MM-dd HH:mm:ss" in UTC (e.g. 2026-04-10 21:15:00).
- `status` (string): Task STATUS text, using a value your Insightly instance accepts (read an existing task to see them).
- `title` (string, required): Task title (required).

### `insightly_update_task` (~291 tokens)

Update a task

Update a task — mark it completed, change due date, status, assignee or details. Only the fields you pass are changed. Insightly: PUT /Tasks with TASK_ID.

Input parameters:

- `category_id` (integer): Task category id.
- `completed` (boolean): Whether the task is done.
- `custom_fields` (array): Custom field values to set.
- `details` (string): Task description.
- `due_date` (string): Due date, as "yyyy-MM-dd HH:mm:ss" in UTC (e.g. 2026-04-10 21:15:00).
- `opportunity_id` (integer): Link the task to this opportunity.
- `owner_user_id` (integer): Owner's user id.
- `percent_complete` (integer)
- `priority` (integer): Priority number.
- `project_id` (integer): Link the task to this project.
- `responsible_user_id` (integer): Assignee's user id.
- `start_date` (string): Start date, as "yyyy-MM-dd HH:mm:ss" in UTC (e.g. 2026-04-10 21:15:00).
- `status` (string): Task STATUS text, using a value your Insightly instance accepts (read an existing task to see them).
- `task_id` (integer, required): The task's numeric id.
- `title` (string): Task title.

### `insightly_add_note` (~94 tokens)

Add a note to a record

Add a note (title + body) to a Contact, Organisation, Lead, Opportunity or Project. Insightly: POST /<Object>/{id}/Notes.

Input parameters:

- `body` (string): Note body (may contain HTML).
- `id` (integer, required): The record's numeric id.
- `object` (string, required): The record type to attach the note to.
- `title` (string, required): Note title (required).

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-usefulapi-insightly/insightly#diagnostics

## Score history

- 2026-10-04: 75
- 2026-10-03: 74
- 2026-10-02: 74
- 2026-10-01: 18
- 2026-09-30: 69
- 2026-09-29: 18

## Common questions

### What is the io.usefulapi/insightly MCP server?

io.usefulapi/insightly is an MCP server listed in the public MCP registry as io.usefulapi/insightly. Read and write Insightly contacts, organisations, leads, opportunities, tasks and notes. This page covers its hosted endpoint (https://insightly.usefulapi.io/mcp).

### Is the io.usefulapi/insightly MCP server safe to use?

io.usefulapi/insightly scores 75 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.usefulapi/insightly MCP server expose?

io.usefulapi/insightly exposes 21 tools: insightly_get_current_user, insightly_list_users, insightly_list_records, insightly_get_record, insightly_list_record_activity, and 16 more. Their descriptions and schemas cost roughly 3,794 tokens of context every time the server is loaded.

### Does the io.usefulapi/insightly MCP server require authentication?

Yes. io.usefulapi/insightly asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the io.usefulapi/insightly MCP server still maintained?

io.usefulapi/insightly is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://insightly.usefulapi.io/mcp
- Repository: https://github.com/m190/usefulapi-mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-usefulapi-insightly/insightly.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-usefulapi-insightly/insightly.json
- HTML version of this page: https://verifymcp.io/servers/io-usefulapi-insightly/insightly
