
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@instantreply.co/mcp
Advanced tools
InstantReply MCP server — connect your AI inbox to any LLM agent. No account yet? Run it and the agent walks you through setup.
The InstantReply MCP server — connect an AI agent to a real Instagram, WhatsApp, or Messenger inbox. Works with Claude Code, Claude Desktop, Cursor, Windsurf, Zed, and any other MCP-compatible client.
No account yet? You don't need one before you start. Run it and the agent walks you through setup.
{
"mcpServers": {
"instantreply": {
"command": "npx",
"args": ["-y", "@instantreply.co/mcp"]
}
}
}
Drop that into your MCP client's config (claude_desktop_config.json, Cursor's mcp.json, etc.) and reconnect. If you already have an API key, add it:
{
"mcpServers": {
"instantreply": {
"command": "npx",
"args": ["-y", "@instantreply.co/mcp"],
"env": { "INSTANTREPLY_API_KEY": "ir_live_..." }
}
}
}
With no INSTANTREPLY_API_KEY set, the server starts with exactly two tools: start_setup and check_setup. Ask your agent to connect InstantReply, and it will:
start_setup with the channel you want and, optionally, who you are (persona: creator, business, developer, or agency, so the sign-up page opens the right path) (instagram is the fast path — no Meta app review needed for an account you own; whatsapp needs Meta Business Verification, which takes 2-6 weeks for a new business).check_setup, which waits for your approval and then tells you to reconnect the MCP server.The key it gets you is saved to ~/.instantreply/config.json, so the next npx run skips setup entirely. Set INSTANTREPLY_API_KEY explicitly if you'd rather manage the key yourself (CI, Docker, a shared machine).
Get a key directly, any time, at instantreply.co/dashboard/settings/api-keys.
ask_barq, list_pending_approvals, decide_approval) so your agent can use everything the in-product agent can. Every state-changing tool is marked destructiveHint so a cautious agent can ask before using it.conversation://{id} and contact://{id} for direct reference by ID.recommend_plan — give it what you know about a business (channels, expected volume, team size, API needs) and it returns a plan recommendation with plain-language reasons, a cheaper alternative when one still fits, and a warning when WhatsApp's Meta Business Verification is the real bottleneck, not price.| Plan | Price | Channels | Notes |
|---|---|---|---|
| Free | $0 | Read-only API, read-only MCP | |
| Dev Hobby | $19/mo | Full API, MCP, 3 webhooks | |
| Dev Pro | $49/mo | Instagram + Messenger | 5 API keys, 10 webhooks |
| Dev Scale | $149/mo | Instagram + Messenger | 25 keys, priority MCP routing |
| Starter / Growth / Pro | $59–$349/mo | + WhatsApp, Telegram | Team seats, CRM sync, campaigns |
Every paid plan starts with a 10-day trial. No card required. Full pricing: instantreply.co/pricing.
Meta requires Business Verification — a human review of your registered legal entity — before you can send anything on the WhatsApp Business API. That takes 2-6 weeks and there's no way around it. Instagram DMs for an account you already own only need Standard Access, which requires no App Review at all. If you want something working today, start there; add WhatsApp once your business is verified.
| Variable | Default | Purpose |
|---|---|---|
INSTANTREPLY_API_KEY | none | Skips zero-key setup entirely |
INSTANTREPLY_API_URL | https://api.instantreply.co | Point at a different environment |
npm install
npm run build # tsc -> dist/
npm test # node --test
npm run dev # tsx watch
MIT
FAQs
AI agent toolkit for WhatsApp, Instagram, and Messenger automation with zero-key MCP pairing, Barq AI, inbox tools, campaigns, templates, and developer diagnostics.
The npm package @instantreply.co/mcp receives a total of 71 weekly downloads. As such, @instantreply.co/mcp popularity was classified as not popular.
We found that @instantreply.co/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.