Ducto

Product

One URL. Every platform. Every write governed.

Point Claude, ChatGPT, Cursor, or any MCP client at mcp.getducto.com and it can operate your ads, tags, and analytics — through a policy engine it cannot talk its way past.

Coverage

226 tools across 16 mounts

Generated from the running gateway's tool registry — this table only lists what's shipping. Read-only and write counts are per the readOnlyHint annotation on every tool.

PlatformMountToolsRead-onlyWrite
Google Ads/google-ads271017
Google Tag Manager/gtm351817
Google Analytics 4 (Admin)/ga41477
Google Search Console/search-console1174
Google Merchant Center/merchant-center550
Google Business Profile/business-profile770
YouTube (Data + Analytics)/youtube550
Core Web Vitals (CrUX / PageSpeed)/web-vitals440
Meta (Facebook / Instagram) Ads/meta-ads231112
Microsoft Advertising/microsoft-ads201010
LinkedIn Ads/linkedin-ads1266
TikTok Ads/tiktok-ads1156
Looker Studio (assets + report links)/looker-studio440
HubSpot CRM/hubspot1477
Google Sheets/sheets734
Cross-platform workflows/workflows1055

The combined endpoint serves everything behind one URL, filtered per token. Per-platform mounts exist for clients with small tool budgets — Cursor's 40-tool cap included.

The write lifecycle

Preview, apply, approve, audit

The policy engine implements one contract for all 84 write tools — the connector never decides policy, and no tool input can override the row.

Preview

apply: false

The mutation runs validate-only against the live platform. Ducto persists a draft preview keyed by the mutation's fingerprint and audits it. Nothing changes yet.

Apply

apply: true

The gateway checks read-only, then requires a live preview whose fingerprint matches this exact mutation. Caps come from the policy row. Then — and only then — the write executes.

Approve

pending_approval

If you've flagged this tool class as high-stakes, the write parks with its preview attached and waits in your approval inbox. Approve it and it executes; nothing re-negotiates with the model.

Audit

prev_hash → hash

Preview, apply, approve, deny — every event is appended to a per-org hash chain. The table has no update or delete for any role; a trigger enforces it.

Bring your own agent

Any MCP client, one connector URL

Streamable HTTP with OAuth 2.1 sign-in, or bearer tokens for headless setups. Scoped tokens narrow what each agent sees — per platform, per tool, or per client account.

  • Claude and Claude Code — paste the URL, sign in, done
  • ChatGPT and Cursor — same URL, same policies
  • n8n, LangChain, custom agents — bearer token auth
mcp — connector url

https://mcp.getducto.com/

https://mcp.getducto.com/google-ads

https://mcp.getducto.com/gtm

https://mcp.getducto.com/meta-ads

…one mount per platform, 14 total

Connect read-only in minutes. Enable writes when you've set your caps.

Read-only is the default, not a trial mode. The product is what it takes to safely go past it.