
Last updated:
OutboundSync MCP 0.4.0 and Agent Skills update
TL;DR. On September 28 we shipped OutboundSync MCP 0.4.0 and a new Agent Skills release (2026.09.28.1). The MCP now tells your agent which tools change data, returns errors it can act on, and matches API v1 limits exactly. The skills now report results in one consistent layout, and their API and MCP references match what is live. The MCP is hosted, so you’re already on 0.4.0. To get the new skills, reinstall the pack.
We launched the hosted MCP server two weeks ago and grew the skills pack to 15 in August. This release is about trust. When a coding agent works on your CRM sync, it has to know which calls are safe, what a failure means, and when it has actually seen all the data. We audited the MCP and every skill against the live API v1 and fixed what didn’t match.
What changed in OutboundSync MCP 0.4.0?
OutboundSync MCP 0.4.0 makes three things explicit for your agent: whether a tool changes data, why a call failed, and whether a request is valid before it reaches the API. All 35 MCP tools now match the API v1 reference for limits, scopes, and errors.
Your agent knows which tools change data
MCP tools carry safety hints, and clients such as Cursor and Claude Code use them to decide when to ask before running a tool. The MCP spec treats a write tool as destructive unless it says otherwise. Our write tools didn’t say otherwise, so harmless actions like retrying a sync or sending a test ping were labeled as destructive.
In 0.4.0 every tool is labeled explicitly:
- Read tools are read-only.
- Writes that don’t lose anything are writes, but not destructive. That covers retries, replays, test pings, webhook creation, and blocklist pause and resync.
- Three tools are destructive:
update_webhook,delete_webhook, androtate_webhook_secret. They can reroute lead data, remove an endpoint, or break a signing secret. - Tools that call your URL (
test_webhookand both replay tools) are marked as reaching outside OutboundSync, because they make OutboundSync POST to your endpoint.
The full table is in how MCP tools behave. Whatever the hint says, your agent should still confirm with you before any write.
Errors your agent can act on
Before 0.4.0, many failures came back as a generic upstream_error. Now every error includes the API’s HTTP status, and the common cases have their own codes: bad_request, not_found, timeout, forbidden, and rate_limited, which includes retryAfterSeconds. A 403 explains its actual cause, such as a connection-scoped key calling an account route, webhooks being turned off, or a missing write scope.
That lets an agent make the right call. It retries a 5xx or a rate limit. It fixes the request after a bad_request. It stops and tells you when the key needs a different scope. If the MCP gets back something that isn’t JSON, such as a proxy’s HTML page, it now reports an error instead of passing the page along as data.
Bad requests stop before they reach the API
The MCP now checks inputs itself:
- Date ranges must be in order and span 31 days or less, the same rule as REST. A request for a longer window is rejected, and the agent is told to split it.
- Page sizes follow API v1.
list_eventsandlist_webhook_deliveriescap at 100 (default 25). They used to accept 500. - Paging follows
hasMoreandnextCursor. A short page doesn’t mean the list is finished, and an error or timeout means the answer is unknown, never “none found.”
Input descriptions for ids and filters are clearer too, so agents pick the right argument on the first try.
What changed in OutboundSync Agent Skills?
The Agent Skills pack now uses one status layout across every skill that checks something, and its API and MCP references are corrected against the live API and MCP 0.4.0. It’s still 15 skills, MIT-licensed on GitHub.
One status layout across the pack
Preflight introduced a gauge-style readout. That format is now the standard for the whole pack. The heading is the verdict. Below it are a 20-cell gauge, one card per area, and a numbered Next list. Here’s the top of a sync monitoring report (illustrative data). The endpoint that carried sync.failed auto-disabled, so failure alerts stopped while CRM sync errors piled up:
## Sync Monitoring needs attention
Overall ████████░░░░░░░░░░░░ 2/5 · needs attention
Access ████████████████████ ✓ readyEndpoints ░░░░░░░░░░░░░░░░░░░░ ✗ none healthy cover sync.failedDeliveries ████████████████████ ✓ 25/25 okEvents ██████████████░░░░░░ ✗ 18/25 deliveredCRM syncs ███████████████████░ ✗ 1,216/1,277 ok · 7 daysCards for each area and a Next list follow the gauge.
One rule matters more than the formatting. A failed lookup is never an empty result. If a call errors or times out, the skill prints UNVERIFIED with the reason and the status code. It never prints a quiet zero that reads like “all clear.”
Skills with bigger updates
- Sync monitoring is now a health dashboard. It gauges access, endpoints, deliveries, events, and seven days of CRM syncs. It lists every webhook write tool in a Mutations table and shows a Proposed change card before any write.
- API adds cards for access, plan, prior outreach, blocklists, and metrics. Its endpoint reference is now the pack’s single REST-to-MCP map for all 35 tools, including access rules, enums, pagination, rate-limit headers, and the MCP error format.
- CRM analysis has a formal output contract: a verdict, a field-coverage gauge, a field check, and ranked results. All nine examples are re-rendered.
- Email authentication, sending-domain quality, and connection requests now always show a gauge. Connection requests also gets its missing /100 score meter.
Accuracy fixes
We compared every skill’s API guidance with the live API and MCP 0.4.0:
/sourcesisn’t paginated, and the skills no longer page through it./eventsneeds webhooks enabled on the account (canUseWebhooks), for reads too.- Destinations with no bound Sources are flagged, because they forward nothing.
- The old “OpenAPI lags the API” caveat is gone. The OpenAPI spec now matches the MCP tool for tool.
- A non-JSON
200is treated as a route that hasn’t shipped, not as a success.
We also fixed a few rendering bugs, such as a score meter that showed 15 of 20 cells for 78/100 (it should be 16). And we fixed links that broke when you installed a single skill with npx skills add.
Under the hood
The pack’s checks moved from a bash script to a tested Node validator. It reports every problem in one run and enforces the output conventions described above. CI now pins its actions, runs with least-privilege permissions, and checks external links weekly. New contributors can start from CONTRIBUTING.md and a skill template. See the release notes for the full list.
How to update
MCP: nothing to install. The server at https://mcp.outboundsync.com/mcp is already on 0.4.0, and your API key and client config are unchanged. Start a new agent session so your client picks up the new annotations. New to MCP? Start with MCP setup.
Skills: reinstall the pack, then open a new agent session:
npx skills add outboundsync/skills -gTo update one skill, add --skill <name>, for example --skill sync-monitoring. Full steps are in Install skills.
Then try one of these:
- Are my OutboundSync Sync Monitoring webhooks delivering?
- What can my OutboundSync API key access?
- Are my campaigns ready to launch?
Frequently asked questions
What changed in OutboundSync MCP 0.4.0?
Every tool now tells your MCP client whether it reads, writes, or destroys data. Errors carry the API’s HTTP status and a specific code (bad_request, not_found, timeout, rate_limited, and others), so an agent can tell a retryable failure from a permanent one. Date ranges and page sizes are checked before the API is called.
Do I need to update anything to get MCP 0.4.0?
No. OutboundSync MCP is hosted at https://mcp.outboundsync.com/mcp, so every connected client is already on 0.4.0. Your Bearer API key and client config stay the same. Open a new agent session so your client reloads the tool list and annotations.
What is the new Agent Skills status layout?
Every skill that checks something now answers the same way: a verdict heading, a 20-cell gauge, one card per area, and a numbered Next list. A lookup that fails shows as UNVERIFIED with the reason. It never shows as an empty or passing result.
How do I update my installed Agent Skills?
Reinstall the pack with npx skills add outboundsync/skills -g, or reinstall one skill with --skill <name>. Then open a new agent session. The pack is still 15 skills, MIT-licensed on GitHub, and the latest release is 2026.09.28.1.
Get started
- How MCP tools behave · MCP setup
- Install skills · Browse the catalog
- Sync monitoring · API · CRM analysis · Preflight
- AI and Agents hub
Want to see it running against your own CRM? Get a demo.

Founder & President, OutboundSync
15+ years in B2B sales and operations. Former HubSpot Solutions Partner and Smartlead expert. Built the agency that became OutboundSync.
Similar posts
OutboundSync webhooks are live
OutboundSync now POSTs sync.failed and sync.recovered to your HTTPS endpoint — Slack, PagerDuty, n8n, Zapier, Clay — so you know when CRM sync breaks.
Harris Kenny
OutboundSync now supports WebMCP
AI agents can now use the OutboundSync website directly — find integrations, get pricing, and compare tools — via WebMCP and a public JSON API.
Harris Kenny
OutboundSync MCP Server out now
Hosted OutboundSync MCP for Cursor, Claude Code, and more. Same Bearer key as the REST API, with no local MCP process to run.
Harris Kenny


