# YouSpot > YouSpot is a personal CRM for AI-native professionals. It builds a second brain from the people, companies, notes and files you already deal with, syncing Gmail, Google Calendar, HubSpot, X and LinkedIn into one graph you can ask in plain English. One plan, $10 a month, no seats to count. --- # YouSpot: The AI-native Solo CRM built just for you. > YouSpot is a personal CRM for AI-native professionals. It builds a second brain from the people, companies, notes and files you already deal with, syncing Gmail, Google Calendar, HubSpot, X and LinkedIn into one graph you can ask in plain English. One plan, $10 a month, no seats to count. ## What YouSpot does ### Chat with your Second Brain Ask questions across a million objects (contacts, companies, notes and files) and get answers grounded in your own data, not the internet's. ### Connect what you already use HubSpot, Gmail, Google Calendar, X/Twitter and LinkedIn, plus 3 connected mailboxes. Your tools finally talking to each other. ### Agents that keep working Long-running agents inspired by OpenClaw and Hermes, plus a premium GTM app library: ImageGen, ProspectFinder, DomainValue and more. ## When to use YouSpot - Look up a person or company in the signed-in member's own network, not the public web. - Answer "who do I know at X?" across imported LinkedIn connections, contacts and companies. - Log an interaction and set a follow-up after a call or an email. - Read what needs attention today: unanswered threads, stale follow-ups, upcoming meetings. - Draft and send email from a connected Gmail mailbox, or read a calendar for context. - Sync a contact or company both ways with a connected HubSpot portal. - Search the member's Brain graph (notes, files, objects) and cite the objects behind the answer. ## Pricing One plan. $10 a month. Cancel anytime. Details: https://youspot.com/pricing ## For developers and agents - [llms.txt](https://youspot.com/llms.txt): this site, for language models - [llms-full.txt](https://youspot.com/llms-full.txt): the long-form version - [sitemap.xml](https://youspot.com/sitemap.xml): every public page with a last-modified date - [index.md](https://youspot.com/index.md): the home page as markdown - [agents.md](https://youspot.com/agents.md): what an agent can do here, in one page - [MCP server](https://youspot.com/mcp/v1): streamable HTTP; initialize and tools/list need no credential - [MCP server card](https://youspot.com/.well-known/mcp/server-card.json): the endpoint, transport and every tool - [auth.md](https://youspot.com/auth.md): how an agent gets a credential - [agent identity](https://youspot.com/agent/identity): what identity you can hold here, and who you are holding - [OpenAPI 3.1](https://youspot.com/openapi.json): every HTTP endpoint that exists - [Agent Plugins manifest](https://youspot.com/plugin.json): both MCP servers and the skills, in one bundle - [API catalog](https://youspot.com/.well-known/api-catalog): RFC 9727 - [agent index](https://youspot.com/v1): every endpoint, and what each one costs in credentials - [docs MCP server](https://youspot.com/mcp/docs): the public pages over MCP, no credential at all - [sandbox MCP server](https://youspot.com/mcp/sandbox): the read tools over a demo account, no credential and no signup - [ask](https://youspot.com/ask): a question in plain words, answered from these pages - [A2A agent card](https://youspot.com/.well-known/agent-card.json): JSON-RPC at /a2a - [OAuth 2.1 authorization server metadata](https://youspot.com/.well-known/oauth-authorization-server): RFC 8414 - [protected resource metadata](https://youspot.com/.well-known/oauth-protected-resource): RFC 9728 - [Agent Skills index](https://youspot.com/.well-known/agent-skills/index.json): skills an agent can load - [ARD catalog](https://youspot.com/.well-known/ard.json): agent resource discovery - [security.txt](https://youspot.com/.well-known/security.txt): how to report a vulnerability - [Web Bot Auth key directory](https://youspot.com/.well-known/http-message-signatures-directory): the key YouSpot agents sign their own requests with Docs: https://youspot.com/docs ## Questions ### What is YouSpot? A personal CRM for one person rather than a sales team. It imports the people and companies you already know, keeps them current from your mail, calendar and LinkedIn, and answers questions about them in plain English. ### How much does YouSpot cost? YouSpot Pro is $10 a month and includes 1,000 credits/month. One plan, cancel anytime. ### Can an AI agent use YouSpot? Yes. YouSpot runs a Model Context Protocol server at https://youspot.com/mcp with OAuth 2.1 (PKCE S256, dynamic client registration, refresh-token rotation), so Claude, ChatGPT, Cursor and Claude Code can connect to a member account and call its tools. ### What can the tools do? Search and read people, companies, notes and files in the member's graph; record interactions and follow-ups; read and send Gmail; read Google Calendar; read LinkedIn network data; and sync with HubSpot. Read tools are free to call; writes ask first. ### What data does YouSpot hold? Only what a member connects: contacts, companies, notes, files, and the mail and calendar metadata from the mailboxes they link. Every tool call is scoped to the signed-in member. ### Which integrations are supported? HubSpot, Gmail, Google Calendar, X/Twitter and LinkedIn, with up to 3 connected mailboxes on Pro. ### How do I report a security issue? Email andrei@mail.youspot.com. The vulnerability disclosure policy is published at https://youspot.com/docs/security and https://youspot.com/.well-known/security.txt. ## Elsewhere - [Apps](https://youspot.com/tools) - [Second Brain](https://youspot.com/secondbrain) - [What is this?](https://youspot.com/about) - [Support](https://youspot.com/support), or email support@youspot.com - [Privacy](https://youspot.com/privacy), [Terms](https://youspot.com/terms) --- # YouSpot pricing > YouSpot Pro is $10 a month. One plan, no seats to count, cancel anytime. ## What it costs - **YouSpot Pro**: $10 per month - Use up to 1,000 credits/month ## What is included - Chat with your Second Brain - Access to OpenAI, Anthropic and Gemini models - Store up to 1M objects (contacts, companies, notes, files) - 3 connected mailboxes - Support for HubSpot, GMail, GCal, X/Twitter and LinkedIn - Long-running agents inspired by OpenClaw/Hermes - Access to premium GTM app library including ImageGen, ProspectFinder, DomainValue and others ## Every plan, side by side | | YouSpot Solo | YouSpot Pro | | --- | --- | --- | | Price | $1/month | $10/month | | Billing | Monthly, cancel anytime | Monthly, cancel anytime | | Credits | 100 credits/month | 1,000 credits/month | | Objects stored | 100,000 | 1,000,000 | | Connected mailboxes | 1 | 3 | | Models | OpenAI, Anthropic, Gemini | OpenAI, Anthropic, Gemini | | Integrations | HubSpot, Gmail, Google Calendar, X, LinkedIn | HubSpot, Gmail, Google Calendar, X, LinkedIn | | Long-running agents | Yes | Yes | | GTM app library | Yes | Yes | | MCP server and HTTP API | Yes | Yes | | Seats | One person. There are no per-seat charges. | One person. There are no per-seat charges. | ## What a credit is A credit is one unit of metered work: a chat turn, a tool call that reaches a model, an enrichment. Reading your own data, browsing the app, and every discovery endpoint on this site cost nothing. Credits reset monthly and do not roll over. Running out stops metered work; it does not delete anything or lock you out of your data. ## For agents and developers - The MCP server, the HTTP API and the OAuth server are included in both plans at no extra cost. There is no separate API tier and no per-call charge beyond credits. - No credential is needed to read the [documentation MCP server](https://youspot.com/mcp/docs), the [sandbox](https://youspot.com/mcp/sandbox), the public directory, or any discovery document. Those are free to anyone, with no account. - Rate limits and the headers that declare them are documented at [/docs/versioning](https://youspot.com/docs/versioning). - There is no free tier of the product itself, no trial period, and no annual discount. ## Cancelling Cancel any time from billing settings. There is no contract and no cancellation fee. Your data stays readable and exportable after cancelling. ## Both plans - [YouSpot Pro](https://youspot.com/pricing/pro): $10 a month, 1,000 credits/month - [YouSpot Solo](https://youspot.com/pricing/solo): $1 a month, 100 credits/month ## More - [Docs for developers and agents](https://youspot.com/docs) - [Support](https://youspot.com/support), or email support@youspot.com --- # YouSpot pricing > YouSpot Pro is $10 a month. One plan, no seats to count, cancel anytime. ## What it costs - **YouSpot Pro**: $10 per month - Use up to 1,000 credits/month ## What is included - Chat with your Second Brain - Access to OpenAI, Anthropic and Gemini models - Store up to 1M objects (contacts, companies, notes, files) - 3 connected mailboxes - Support for HubSpot, GMail, GCal, X/Twitter and LinkedIn - Long-running agents inspired by OpenClaw/Hermes - Access to premium GTM app library including ImageGen, ProspectFinder, DomainValue and others ## Every plan, side by side | | YouSpot Solo | YouSpot Pro | | --- | --- | --- | | Price | $1/month | $10/month | | Billing | Monthly, cancel anytime | Monthly, cancel anytime | | Credits | 100 credits/month | 1,000 credits/month | | Objects stored | 100,000 | 1,000,000 | | Connected mailboxes | 1 | 3 | | Models | OpenAI, Anthropic, Gemini | OpenAI, Anthropic, Gemini | | Integrations | HubSpot, Gmail, Google Calendar, X, LinkedIn | HubSpot, Gmail, Google Calendar, X, LinkedIn | | Long-running agents | Yes | Yes | | GTM app library | Yes | Yes | | MCP server and HTTP API | Yes | Yes | | Seats | One person. There are no per-seat charges. | One person. There are no per-seat charges. | ## What a credit is A credit is one unit of metered work: a chat turn, a tool call that reaches a model, an enrichment. Reading your own data, browsing the app, and every discovery endpoint on this site cost nothing. Credits reset monthly and do not roll over. Running out stops metered work; it does not delete anything or lock you out of your data. ## For agents and developers - The MCP server, the HTTP API and the OAuth server are included in both plans at no extra cost. There is no separate API tier and no per-call charge beyond credits. - No credential is needed to read the [documentation MCP server](https://youspot.com/mcp/docs), the [sandbox](https://youspot.com/mcp/sandbox), the public directory, or any discovery document. Those are free to anyone, with no account. - Rate limits and the headers that declare them are documented at [/docs/versioning](https://youspot.com/docs/versioning). - There is no free tier of the product itself, no trial period, and no annual discount. ## Cancelling Cancel any time from billing settings. There is no contract and no cancellation fee. Your data stays readable and exportable after cancelling. ## Both plans - [YouSpot Pro](https://youspot.com/pricing/pro): $10 a month, 1,000 credits/month - [YouSpot Solo](https://youspot.com/pricing/solo): $1 a month, 100 credits/month ## More - [Docs for developers and agents](https://youspot.com/docs) - [Support](https://youspot.com/support), or email support@youspot.com --- # YouSpot Solo pricing > YouSpot Solo is $1 a month. One plan, no seats to count, cancel anytime. ## What it costs - **YouSpot Solo**: $1 per month - Use up to 100 credits/month ## What is included - Chat with your Second Brain - Access to OpenAI, Anthropic and Gemini models - Store up to 100k objects (contacts, companies, notes, files) - 1 connected mailbox - Support for HubSpot, GMail, GCal, X/Twitter and LinkedIn - Long-running agents inspired by OpenClaw/Hermes - Access to premium GTM app library including ImageGen, ProspectFinder, DomainValue and others ## Every plan, side by side | | YouSpot Solo | YouSpot Pro | | --- | --- | --- | | Price | $1/month | $10/month | | Billing | Monthly, cancel anytime | Monthly, cancel anytime | | Credits | 100 credits/month | 1,000 credits/month | | Objects stored | 100,000 | 1,000,000 | | Connected mailboxes | 1 | 3 | | Models | OpenAI, Anthropic, Gemini | OpenAI, Anthropic, Gemini | | Integrations | HubSpot, Gmail, Google Calendar, X, LinkedIn | HubSpot, Gmail, Google Calendar, X, LinkedIn | | Long-running agents | Yes | Yes | | GTM app library | Yes | Yes | | MCP server and HTTP API | Yes | Yes | | Seats | One person. There are no per-seat charges. | One person. There are no per-seat charges. | ## What a credit is A credit is one unit of metered work: a chat turn, a tool call that reaches a model, an enrichment. Reading your own data, browsing the app, and every discovery endpoint on this site cost nothing. Credits reset monthly and do not roll over. Running out stops metered work; it does not delete anything or lock you out of your data. ## For agents and developers - The MCP server, the HTTP API and the OAuth server are included in both plans at no extra cost. There is no separate API tier and no per-call charge beyond credits. - No credential is needed to read the [documentation MCP server](https://youspot.com/mcp/docs), the [sandbox](https://youspot.com/mcp/sandbox), the public directory, or any discovery document. Those are free to anyone, with no account. - Rate limits and the headers that declare them are documented at [/docs/versioning](https://youspot.com/docs/versioning). - There is no free tier of the product itself, no trial period, and no annual discount. ## Cancelling Cancel any time from billing settings. There is no contract and no cancellation fee. Your data stays readable and exportable after cancelling. ## Both plans - [YouSpot Pro](https://youspot.com/pricing/pro): $10 a month, 1,000 credits/month - [YouSpot Solo](https://youspot.com/pricing/solo): $1 a month, 100 credits/month ## More - [Docs for developers and agents](https://youspot.com/docs) - [Support](https://youspot.com/support), or email support@youspot.com --- # The Second Brain: you forget, it does not > Everything you know, every person, conversation, deal, domain and half-finished thought, filed into one graph, connected the way it actually happened, and answerable in plain English. ## It fills itself Zero data entry. That is the whole point. Connect Gmail, LinkedIn, HubSpot or the Chrome extension once, and the people you email, the posts you write and the files you save land in the graph on their own: typed, tagged and time-stamped. ## You just ask Plain English in, your own life out. "Who do I know at Gusto?" "Which invitations did I never answer?" "What did I pay for that domain?" It answers from your graph, not the internet's. ## It acts while you sleep Agents that wake when life happens. New email arrives, an agent reads it, files what matters, and leaves a paper trail in your feed. Your Second Brain does not just remember, it does the follow-up. ## Getting one The Second Brain comes with every YouSpot plan. See [pricing](https://youspot.com/pricing). An agent can read and write the same graph over MCP. See the [docs](https://youspot.com/docs). --- # YouSpot apps > Sharp, focused apps for the daily work of revenue: grade your stack, make your assets, price your names. Each one does one job well. ## The apps ### [HubGrader](https://youspot.com/hubgrader) Grade any HubSpot portal and see how your setup stacks up against best practices. ### [CompanyResearch](https://youspot.com/companyresearch) AI research reports on any company: people, products, funding and news. ### [ImageGen](https://youspot.com/imagegen) Generate and edit on-brand images with AI, right in your browser. ### [DomainValue](https://youspot.com/domainvalue) AI-powered domain valuations to price and compare any name in seconds. ### [DomainSuggest](https://youspot.com/domainsuggest) AI-powered domain name suggestions for your next idea. ### [MetaPrompt](https://youspot.com/metaprompt) Paste any AI prompt and get a sharper, more effective version back. ### [LinkedIn Explorer](https://youspot.com/linkedin/explorer) Import your LinkedIn network and ask questions across your connections. ## More - [Pricing](https://youspot.com/pricing): every app is included in the plan - [Docs for developers and agents](https://youspot.com/docs) --- # YouSpot docs for developers and agents > The MCP server, OAuth 2.1, the HTTP endpoints, and the discovery files that describe them. ## Pages - [YouSpot for developers and agents](https://youspot.com/docs/overview.md): What YouSpot exposes to code: an MCP server, OAuth 2.1, public profile endpoints, and the discovery files that describe them. - [YouSpot API authentication](https://youspot.com/docs/authentication.md): YouSpot is an OAuth 2.1 authorization server for agents: dynamic client registration, PKCE S256, refresh-token rotation. Members can also mint a long-lived API token by hand. - [YouSpot MCP server](https://youspot.com/docs/mcp.md): Connect Claude, ChatGPT, Cursor or Claude Code to https://youspot.com/mcp/v1 and let an agent read and write your own CRM. - [YouSpot HTTP API](https://youspot.com/docs/api.md): The endpoints YouSpot answers over plain HTTP: public profile data with no auth, and the MCP tool surface with a bearer token. - [YouSpot API versioning, deprecation and rate limits](https://youspot.com/docs/versioning.md): How the YouSpot API is versioned, what notice you get before anything is removed, the RateLimit headers every limited endpoint answers with, and how Idempotency-Key makes a retry safe. - [YouSpot security and vulnerability disclosure](https://youspot.com/docs/security.md): How to report a security issue to YouSpot, Inc., what is in scope, and what we commit to in return. ## Machine endpoints - [llms.txt](https://youspot.com/llms.txt): this site, for language models - [llms-full.txt](https://youspot.com/llms-full.txt): the long-form version - [sitemap.xml](https://youspot.com/sitemap.xml): every public page with a last-modified date - [index.md](https://youspot.com/index.md): the home page as markdown - [agents.md](https://youspot.com/agents.md): what an agent can do here, in one page - [MCP server](https://youspot.com/mcp/v1): streamable HTTP; initialize and tools/list need no credential - [MCP server card](https://youspot.com/.well-known/mcp/server-card.json): the endpoint, transport and every tool - [auth.md](https://youspot.com/auth.md): how an agent gets a credential - [agent identity](https://youspot.com/agent/identity): what identity you can hold here, and who you are holding - [OpenAPI 3.1](https://youspot.com/openapi.json): every HTTP endpoint that exists - [Agent Plugins manifest](https://youspot.com/plugin.json): both MCP servers and the skills, in one bundle - [API catalog](https://youspot.com/.well-known/api-catalog): RFC 9727 - [agent index](https://youspot.com/v1): every endpoint, and what each one costs in credentials - [docs MCP server](https://youspot.com/mcp/docs): the public pages over MCP, no credential at all - [sandbox MCP server](https://youspot.com/mcp/sandbox): the read tools over a demo account, no credential and no signup - [ask](https://youspot.com/ask): a question in plain words, answered from these pages - [A2A agent card](https://youspot.com/.well-known/agent-card.json): JSON-RPC at /a2a - [OAuth 2.1 authorization server metadata](https://youspot.com/.well-known/oauth-authorization-server): RFC 8414 - [protected resource metadata](https://youspot.com/.well-known/oauth-protected-resource): RFC 9728 - [Agent Skills index](https://youspot.com/.well-known/agent-skills/index.json): skills an agent can load - [ARD catalog](https://youspot.com/.well-known/ard.json): agent resource discovery - [security.txt](https://youspot.com/.well-known/security.txt): how to report a vulnerability - [Web Bot Auth key directory](https://youspot.com/.well-known/http-message-signatures-directory): the key YouSpot agents sign their own requests with --- # YouSpot for developers and agents > What YouSpot exposes to code: an MCP server, OAuth 2.1, public profile endpoints, and the discovery files that describe them. YouSpot is a personal CRM for AI-native professionals. It builds a second brain from the people, companies, notes and files you already deal with, syncing Gmail, Google Calendar, HubSpot, X and LinkedIn into one graph you can ask in plain English. One plan, $10 a month, no seats to count. ## What you can call - **MCP server** at `https://youspot.com/mcp`: streamable HTTP transport, OAuth 2.1 with PKCE S256 and dynamic client registration. This is the primary way an agent reads and writes a member's CRM. - **Public profile endpoints** at `https://youspot.com/api/human/` (also `.json` and `.md`) and `https://youspot.com/api/network/members`: no auth, public data only. - **Discovery files** listed below, so a crawler or an agent can find all of the above without being told. ## Discovery files | Path | What it is | | --- | --- | | `/llms.txt` | this site, for language models | | `/llms-full.txt` | the long-form version | | `/sitemap.xml` | every public page with a last-modified date | | `/index.md` | the home page as markdown | | `/agents.md` | what an agent can do here, in one page | | `/mcp/v1` | streamable HTTP; initialize and tools/list need no credential | | `/.well-known/mcp/server-card.json` | the endpoint, transport and every tool | | `/auth.md` | how an agent gets a credential | | `/agent/identity` | what identity you can hold here, and who you are holding | | `/openapi.json` | every HTTP endpoint that exists | | `/plugin.json` | both MCP servers and the skills, in one bundle | | `/.well-known/api-catalog` | RFC 9727 | | `/v1` | every endpoint, and what each one costs in credentials | | `/mcp/docs` | the public pages over MCP, no credential at all | | `/mcp/sandbox` | the read tools over a demo account, no credential and no signup | | `/ask` | a question in plain words, answered from these pages | | `/.well-known/agent-card.json` | JSON-RPC at /a2a | | `/.well-known/oauth-authorization-server` | RFC 8414 | | `/.well-known/oauth-protected-resource` | RFC 9728 | | `/.well-known/agent-skills/index.json` | skills an agent can load | | `/.well-known/ard.json` | agent resource discovery | | `/.well-known/security.txt` | how to report a vulnerability | | `/.well-known/http-message-signatures-directory` | the key YouSpot agents sign their own requests with | ## The CLI, the SDKs and the source The official client is published under the YouSpot name in both ecosystems. Everything except calling a tool works with no credential, so either one is useful before anybody signs in. ```bash npx youspot ask "how do I connect an MCP client" npx youspot tools pip install youspot ``` | Where | What | | --- | --- | | [npm: youspot](https://www.npmjs.com/package/youspot) | the CLI and the JavaScript SDK. `npx youspot ask "..."` needs no credential. | | [PyPI: youspot](https://pypi.org/project/youspot/) | the Python client. `pip install youspot`. | | [GitHub: OnStartups/youspot-agent-tools](https://github.com/OnStartups/youspot-agent-tools) | source, the agent skills, AGENTS.md, .cursorrules and the Agent Plugins manifest. | The repository carries `AGENTS.md` and `.cursorrules` for coding agents, an Agent Plugins manifest at `plugin.json`, and the three agent skills. It is the same source the packages are built from. ## Reading pages as markdown Every public page answers a markdown twin. Add `.md` to the path, or send `Accept: text/markdown` and get the same body back at the original URL. ```bash curl https://youspot.com/pricing.md curl -H "Accept: text/markdown" https://youspot.com/pricing ``` ## Where to go next - [Authentication](https://youspot.com/docs/authentication): the OAuth 2.1 flow, and the API token a member can mint by hand. - [MCP](https://youspot.com/docs/mcp): connecting Claude, ChatGPT, Cursor and Claude Code, and what the tools do. - [API](https://youspot.com/docs/api): the HTTP surface that needs no MCP client. - [Security](https://youspot.com/docs/security): how to report a vulnerability. --- # YouSpot API authentication > YouSpot is an OAuth 2.1 authorization server for agents: dynamic client registration, PKCE S256, refresh-token rotation. Members can also mint a long-lived API token by hand. YouSpot issues its own OAuth 2.1 access tokens to agents. A token is always bound to one member: every tool call reads and writes that person's data and nobody else's. ## Discovery - `https://youspot.com/.well-known/oauth-protected-resource` (RFC 9728) names the resource and its authorization server. - `https://youspot.com/.well-known/oauth-authorization-server` (RFC 8414) names the endpoints below. ### What identity you can hold `POST https://youspot.com/agent/identity` answers that directly. Send `{"type":"anonymous"}` and it lists the surfaces that need no credential at all. Send `{"type":"service_auth"}` with a bearer token and it names the member whose access you are holding, and whether the credential belongs to a person's AI client or to one of their cloud agents. No other identity type exists here: there is no client-credentials grant, because a token that belonged to no person would have nothing to read. ## Endpoints | Endpoint | Purpose | | --- | --- | | `POST /agent/identity` | What identity you can hold, and who you are holding. No credential needed to ask. | | `POST /oauth/register` | Dynamic client registration (RFC 7591). Open: registration alone grants nothing. | | `GET /oauth/authorize` | Consent. A signed-out person is sent through Clerk first, then shown what the client is asking for. | | `POST /oauth/token` | Authorization code exchange and refresh. Refresh tokens rotate on use. | | `POST /oauth/revoke` | RFC 7009. Revoking either token kills the pair. 200 whether or not the token was live. | ## The flow - Register a client, or reuse one you already registered. - Send the member to `/oauth/authorize` with `response_type=code`, `code_challenge_method=S256`, a `code_challenge`, your `redirect_uri`, and `scope=linkedin`. - They sign in and approve. You get a code on your redirect URI. - Exchange the code at `/oauth/token` with your `code_verifier`. - Call `/mcp` with `Authorization: Bearer `. ### Scope There is one scope, `linkedin`, and it covers the whole tool surface. Finer-grained scopes are not issued yet. ## API tokens A member who wants to script against their own account without running an OAuth flow can mint a named token on the MCP tab at `https://youspot.com/user/integrations/mcp`. Send it the same way, as `Authorization: Bearer `. ```bash curl -X POST https://youspot.com/mcp \ -H "Authorization: Bearer $YOUSPOT_TOKEN" \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' ``` ## Errors - A missing or expired bearer gets `401` with a `WWW-Authenticate: Bearer` header naming the protected-resource metadata URL, so a client can rediscover where to authorize. - A token belonging to a different member never sees your data; there is no cross-account read. --- # YouSpot MCP server > Connect Claude, ChatGPT, Cursor or Claude Code to https://youspot.com/mcp/v1 and let an agent read and write your own CRM. YouSpot runs a Model Context Protocol server at `https://youspot.com/mcp/v1`. Transport is streamable HTTP; auth is OAuth 2.1, so a client that speaks MCP can connect with no key pasted anywhere. ## Connect a client ### Claude Settings, Connectors, Add custom connector, then paste `https://youspot.com/mcp/v1`. Claude registers itself and opens the consent screen. ### ChatGPT Settings, Connectors, Create, then paste `https://youspot.com/mcp/v1` and choose OAuth. ChatGPT registers dynamically the same way. ### Claude Code ```bash claude mcp add --transport http youspot https://youspot.com/mcp/v1 ``` ### Cursor Add this to `~/.cursor/mcp.json`: ```json { "mcpServers": { "youspot": { "url": "https://youspot.com/mcp/v1" } } } ``` ## What the tools do | Family | What it covers | | --- | --- | | Brain graph | Search, read and write the objects in your graph: people, companies, notes, files. | | Attention | What needs you today: unanswered threads, stale follow-ups, upcoming meetings. | | LinkedIn | Query your imported connections and the companies behind them. | | Gmail | Read threads, draft and send mail from a connected mailbox. | | Google Calendar | Read events for context on who you are about to meet. | | HubSpot | Read and sync contacts and companies with a connected portal. | | Company research | Research a company and file the result as an object. | | Prospecting | Find people and companies that match a description. | | Files and imports | Import a file and read what was extracted from it. | | Domains | Value and suggest domain names. | | Slack, X/Twitter, Obsidian | Read from the other sources a member has connected. | ## What it is not This is not a public web search and not a shared directory. Every tool call is scoped to the signed-in member, so an agent asking "who do I know at Acme" gets that person's network and nobody else's. ## Calling it directly The server is plain JSON-RPC over HTTP POST. `initialize`, `ping` and `tools/list` answer without a credential, so you can handshake and read the tool list before anyone has signed in: ```bash curl -X POST https://youspot.com/mcp/v1 \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' ``` Every `tools/call` needs an OAuth access token or a member API token, because every tool reads one person's own CRM. See [Authentication](https://youspot.com/docs/authentication) or the machine walkthrough at [auth.md](https://youspot.com/auth.md). ```bash curl -X POST https://youspot.com/mcp/v1 \ -H "Authorization: Bearer $YOUSPOT_TOKEN" \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"get_connections_summary","arguments":{}}}' ``` ## Try it without an account A third server at `https://youspot.com/mcp/sandbox` runs the same read tools against a demo account whose contacts, companies and interactions are generated. No credential, no signup, no credits. Every tool that writes is refused there, and the answers are shaped exactly like the answers a real account gives. ```bash curl -X POST https://youspot.com/mcp/sandbox \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_graph_objects","arguments":{"query":"consulting"}}}' ``` ## Machine descriptions | Document | What it holds | | --- | --- | | [Server card](https://youspot.com/.well-known/mcp/server-card.json) | The endpoint, the transport, the protocol versions and every tool. Built from the live tool table, so it cannot claim one that does not exist. `GET /mcp/v1` returns the same document. | | [auth.md](https://youspot.com/auth.md) | Discover, register, consent, exchange, call, revoke. In that order, with runnable requests. | | [api-catalog](https://youspot.com/.well-known/api-catalog) | RFC 9727 linkset pointing at the card, the docs and the OAuth metadata. | `https://youspot.com/mcp` still answers for every client that already has it, so nothing that is connected today has to change. `/mcp/v1` is the URL every discovery document advertises. --- # YouSpot HTTP API > The endpoints YouSpot answers over plain HTTP: public profile data with no auth, and the MCP tool surface with a bearer token. Most programmatic work here goes through the MCP server, because that is where the tools live. These endpoints answer over plain HTTP for the cases where running an MCP client is not worth it. ## Public, no auth | Endpoint | Returns | | --- | --- | | `GET /api/human/` | A public member profile as JSON. | | `GET /api/human/.json` | The same profile, explicit extension. | | `GET /api/human/.md` | The same profile as markdown. | | `GET /api/network/members` | A page of the public member directory. | ```bash curl https://youspot.com/api/human/dharmesh.json ``` ## Authenticated The tool surface is reached by posting JSON-RPC to `/mcp` with a bearer token. `tools/list` enumerates it and `tools/call` runs one. ```bash curl -X POST https://youspot.com/mcp \ -H "Authorization: Bearer $YOUSPOT_TOKEN" \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"search_connections","arguments":{"query":"acme"}}}' ``` ## Errors A missing or expired bearer gets `401` with a `WWW-Authenticate: Bearer` header naming the protected-resource metadata URL. A tool that fails returns a JSON-RPC result with `isError` set rather than an HTTP error, so a client can read what went wrong. ## Rate limits Tool calls are metered against the member's monthly credits. A member out of credits gets a clear error naming the limit rather than a silent failure. --- # YouSpot API versioning, deprecation and rate limits > How the YouSpot API is versioned, what notice you get before anything is removed, the RateLimit headers every limited endpoint answers with, and how Idempotency-Key makes a retry safe. An agent should not have to guess whether the surface it integrated against will still be there next month. This page is the contract. ## Versioning The API is versioned in the URL path. `/mcp/v1` is the current product MCP server and `/v1` is the agent index. A version never changes meaning underneath you: a breaking change gets a new path, not a new shape at the old one. - Adding an endpoint, a response field, an optional parameter or a new MCP tool is not breaking, and happens without notice. - Removing or renaming a field, tightening a type, or removing an endpoint or tool is breaking, and only ever happens at a new version path. - The OpenAPI document at `/openapi.json` always describes what is live right now. ## Deprecation and sunset A path being retired answers with `Deprecation: true` (RFC 9745) and a `Link` header with `rel="successor-version"` naming what replaces it. Once a removal date is set, the same responses carry `Sunset` (RFC 8594) as an HTTP-date. The commitment: at least 180 days between the first `Sunset` header and the path being removed, and a deprecated path keeps working unchanged for that whole window. Watch for the header rather than polling this page. | Path | State | Use instead | | --- | --- | --- | | `/mcp` | Deprecated, no sunset date set | `/mcp/v1` | | `/mcp/v1` | Current | | | `/mcp/docs` | Current | | | `/mcp/sandbox` | Current | | ```bash curl -sD - -o /dev/null https://youspot.com/mcp # Deprecation: true # Link: ; rel="successor-version" ``` ## Rate limits Every limited endpoint answers with the RFC 9331 headers, so you can pace against the real budget instead of backing off blindly. The dashed triple is sent alongside for clients that parse it. | Header | Meaning | | --- | --- | | `RateLimit` | `"policy";r=;t=` | | `RateLimit-Policy` | `"policy";q=;w=` | | `RateLimit-Limit` | Requests allowed in the window | | `RateLimit-Remaining` | Requests left | | `RateLimit-Reset` | Seconds until the window resets | | `Retry-After` | On a 429: seconds to wait | The sandbox MCP server allows 60 calls a minute per address. A 429 is a JSON-RPC error with code -32003 and a `Retry-After` header. ## Idempotency A dropped connection leaves an agent unable to tell a lost response from a refused request. Send `Idempotency-Key` on a write and the retry is safe: the first answer is replayed rather than the write repeating. - The key is any unique string up to 255 characters. A UUID is the usual choice. - A key is scoped to the credential that sent it, so it replays only your own answer. It does not need to be unguessable. - A recorded answer is replayed for 24 hours, with `Idempotency-Replayed: true`. - The same key with a different request body is a `422`, because that is a client bug rather than a retry. - Honoured on `POST /oauth/register`, `POST /mcp/v1` and `POST /mcp/sandbox`, and declared on those operations in `/openapi.json`. ```bash curl -X POST https://youspot.com/oauth/register \ -H "Idempotency-Key: $(uuidgen)" \ -H "Content-Type: application/json" \ -d '{"redirect_uris":["https://example.com/callback"],"client_name":"My agent"}' ``` ## Work that outlives one request A tool that cannot finish inside one call enqueues instead and answers with `task_id`. Poll `GET /api/jobs/` until `terminal` is true; while it is still going the response carries `Retry-After` with the interval to use. `result` is filled once `state` is `succeeded`. ```bash curl https://youspot.com/api/jobs/8412 \ -H "Authorization: Bearer $YOUSPOT_TOKEN" # {"job_id":8412,"kind":"file_import","state":"running","terminal":false,...} ``` --- # YouSpot security and vulnerability disclosure > How to report a security issue to YouSpot, Inc., what is in scope, and what we commit to in return. YouSpot, Inc. welcomes reports from security researchers. Email **andrei@mail.youspot.com**. Reports may be submitted anonymously. ## In scope - `https://youspot.com`, the web application. - `https://be.youspot.com`, the API. Anything not listed is out of scope, including the third-party services YouSpot integrates with (Clerk, Supabase, Stripe, Google APIs, Anthropic, OpenAI). Report those to the vendor. If you are unsure, ask before you start. ## Not authorized - Denial-of-service testing, network or application level. - Physical testing and social engineering, including phishing. ## What we ask - Tell us as soon as you find something. - Give us at least 90 days from acknowledgment before publishing. - Use an exploit only far enough to confirm the issue exists. Do not pivot, persist, or pull data. - If you reach personal data, stop, tell us, and keep it confidential. ## What to include - What the vulnerability is. - Where you found it: the URL or endpoint. - What an attacker could do with it. - Steps to reproduce. Scripts and screenshots are welcome. ## What we commit to We acknowledge a report within three business days, keep you posted through confirmation and remediation, and will not pursue legal action over research conducted in line with this policy. The full policy is published at `https://youspot.com/.well-known/security.txt`. --- # YouSpot MCP server > The product MCP server: one member's own contacts, companies, notes and files, over OAuth 2.1. ## Connecting - Endpoint: `https://youspot.com/mcp/v1` - Transport: streamable HTTP, JSON-RPC 2.0 - Protocol versions: `2025-06-18`, `2025-03-26` - Credential: A bearer token for `tools/call`. `initialize`, `ping` and `tools/list` answer anonymously, so a client can handshake before anyone signs in. ```bash curl -X POST https://youspot.com/mcp/v1 \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' ``` ## Tools - `tools/list`: The live tool table, with a typed `inputSchema` and read-only and destructive hints on each. It is the authority; the server card carries names and summaries only. ## Notes - JSON-RPC batching is refused, per MCP 2025-06-18. - `/mcp` is the same server under its old path. It is deprecated and answers with `Deprecation: true`. - Send `Idempotency-Key` on a call you may retry: the first answer is replayed rather than the write repeating. - A tool that cannot finish in one call answers with `task_id`. Poll `/api/jobs/`. ## Related - [Server card](https://youspot.com/mcp/v1) over GET, and at [/.well-known/mcp/server-card.json](https://youspot.com/.well-known/mcp/server-card.json) - [MCP documentation](https://youspot.com/docs/mcp) - [Versioning, deprecation and rate limits](https://youspot.com/docs/versioning) - [OpenAPI](https://youspot.com/openapi.json) --- # YouSpot documentation MCP server > Search and read YouSpot's public pages and developer documentation. No credential, no signup. ## Connecting - Endpoint: `https://youspot.com/mcp/docs` - Transport: streamable HTTP, JSON-RPC 2.0 - Protocol versions: `2025-06-18`, `2025-03-26` - Credential: None. Everything it reads is a page anybody can already fetch. ```bash curl -X POST https://youspot.com/mcp/docs \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' ``` ## Tools - `search_docs`: Search the public pages and developer docs. Returns each matching page with the passage that matched and its URL. - `read_doc`: Read one public page in full, as markdown, by the path search_docs returned. - `list_docs`: Every public page with its title and one-line description, optionally narrowed to one section. ## Notes - Exposes `ui://youspot/docs-results` as an MCP Apps view, so a host that can render shows the results as a list instead of a wall of text. - Also serves every documentation page as an MCP resource over `resources/list`. ## Related - [Server card](https://youspot.com/mcp/docs) over GET, and at [/.well-known/mcp/server-card.json](https://youspot.com/.well-known/mcp/server-card.json) - [MCP documentation](https://youspot.com/docs/mcp) - [Versioning, deprecation and rate limits](https://youspot.com/docs/versioning) - [OpenAPI](https://youspot.com/openapi.json) --- # YouSpot sandbox MCP server > Every YouSpot read tool, with no credential, over a demo account whose contacts and interactions are generated. Try the tools before connecting a real one. ## Connecting - Endpoint: `https://youspot.com/mcp/sandbox` - Transport: streamable HTTP, JSON-RPC 2.0 - Protocol versions: `2025-06-18`, `2025-03-26` - Credential: None. No signup, and nothing here costs credits. ```bash curl -X POST https://youspot.com/mcp/sandbox \ -H "Content-Type: application/json" \ -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' ``` ## Tools - `tools/list`: The read half of the product tool table. Write tools are not listed and not callable here. ## Notes - The data belongs to a fictional consultant and resets to the same fixture. Nothing here is a customer record. - Rate limited to 60 calls a minute per address, declared in the `RateLimit` headers on every response. - Connect `/mcp/v1` for the write tools and for real data. ## Related - [Server card](https://youspot.com/mcp/sandbox) over GET, and at [/.well-known/mcp/server-card.json](https://youspot.com/.well-known/mcp/server-card.json) - [MCP documentation](https://youspot.com/docs/mcp) - [Versioning, deprecation and rate limits](https://youspot.com/docs/versioning) - [OpenAPI](https://youspot.com/openapi.json) --- # What, why, and who is this? > A letter from Dharmesh Shah about what YouSpot is, why it exists, and who it is for. By Dharmesh Shah, Co-founder and CTO, HubSpot. July 2026. ## What is this? YouSpot is a personal CRM. Not a CRM for your company, HubSpot does that, and does it well. This one is for you: the people you know, the conversations you have had, the follow-ups you meant to send. You talk to it the way you would talk to a person who happened to remember everything. "Who do I know at Gusto?" "Which invitations did I never answer?" It just answers. ## Why does it exist? Because I have thousands of connections and remember approximately none of the details. The tools I tried all wanted me to maintain them: fields to fill, stages to advance, a discipline I was never going to keep up. The interesting shift is that an AI does not need the tidy database first. It can work from the mess: your exports, your inbox, your actual history. That is the bet here. It is not AI bolted onto a CRM. It is a CRM that only makes sense because the AI came first. ## Who is it for? Solo professionals. Founders, investors, consultants, salespeople, connectors, anyone whose network is a real asset but who has no team, no ops person, and no interest in becoming a database administrator on the side. If you have ever failed to remember where you met someone right as you were shaking their hand again, it is for you. ## More - [Pricing](https://youspot.com/pricing) - [Second Brain](https://youspot.com/secondbrain) - [Docs for developers and agents](https://youspot.com/docs) --- # Support > Questions, bugs, or something that just looks off: email support@youspot.com and a human answers. ## Getting help Email **support@youspot.com**. Every email opens a tracked ticket, so nothing gets lost. Include a screenshot and the page URL if you can, it helps us fix things faster. ## Feature ideas Send them to **ideas@youspot.com** and they join the public [ideas board](https://youspot.com/ideas). ## Security Report a vulnerability to **andrei@mail.youspot.com**. See the [security policy](https://youspot.com/docs/security). ## More - [Docs](https://youspot.com/docs) - [Pricing](https://youspot.com/pricing) - [Privacy](https://youspot.com/privacy), [Terms](https://youspot.com/terms)