Stunt Double MCP server
Deploy AI user personas to validate user journeys at scale. Find UX friction before real users do.
Stunt Double deploys AI agents with realistic user personas to validate user journeys at scale. Create actors, run automated workflows and checklists against any web app, and surface friction points before real users encounter them. Integrates with Claude, Linear, GitHub, and Slack.
Connect a client
- Claude Code
- Claude Code plugin
- Claude (web, Desktop, mobile)
- Cursor and Windsurf
- From the Stunt Double app
Authentication
Authentication is handled automatically via OAuth 2.1 with PKCE. The first time your AI client connects, a browser window will open for you to sign in and authorise access to your Stunt Double account. No API keys or tokens required.
For Cursor, the OAuth redirect URI is fixed to cursor://anysphere.cursor-mcp/oauth/callback (docs).
What a connection can reach
The server acts as you, never more. Every tool resolves the workspace it is
being asked about and checks your membership of it before doing anything, so a
connection reaches exactly the workspaces list_workspaces returns for you, and
an archived workspace reaches nothing. A workspace you are not a member of
answers the same way one that does not exist does: "not found".
That holds for ids too, not just the workspace_id you pass. A tool that takes
another object's id (a checklist for an automation step, an actor for an
interview participant) checks that object belongs to the same workspace before
storing or running it, and refuses with "not found in this workspace" otherwise.
Refusals never say which workspace an id does belong to.
Scopes narrow this further, never widen it. The consent screen names what the
connection asked for, and a token granted mcp:read is not shown the write or
run tools at all: they are absent from tools/list rather than present and
failing.
| Scope | What it allows |
|---|---|
mcp:read | Read your workspaces and their contents |
mcp:write | Create and edit content in your workspaces |
mcp:run | Start checklist runs, automation runs and interviews, which consume the workspace run allowance, and re-run Stunt Double Index scores for domains you own |
Example prompts
Four prompts that exercise the core of the server once it is connected:
- Verify a flow: "Create a checklist that signs up for a new account on https://demo-checkout-stunt-double.vercel.app, adds an item to the basket and reaches payment, then run it and tell me which checks failed."
- Run a user interview: "Set up an interview with three personas (a first-time shopper, a returning customer and a screen reader user) about our pricing page, launch it, and summarise the report."
- Check agent readiness: "How well can AI agents use stripe.com according to the Stunt Double Index, and which categories are dragging its score down?"
- Triage feedback: "Summarise the open feedback on my main project, group it into themes, and mark anything already fixed as resolved."
Privacy Policy
The server is hosted by Stunt Double and acts as the signed-in user. It reads and writes only the workspaces that user belongs to, within the OAuth scopes they grant (mcp:read, mcp:write, mcp:run). It does not read your conversation with the AI client beyond the arguments passed to each tool call, and it does not access the client's memory, chat history or files.
Data created through the server (projects, actors, checklists, runs, interviews, feedback) is stored in your Stunt Double workspace and handled under the Stunt Double Privacy Policy, which covers collection, use, storage, sub-processors, retention and your rights. Revoke a connection at any time by disconnecting it in your AI client.
Support
- Email: support@stuntdouble.io
- Help centre and docs: stuntdouble.io/support
- MCP reference: docs.stuntdouble.io/api/mcp
- Security reports: see SECURITY.md
Transport
This server uses Streamable HTTP transport. The endpoint is:
https://app.stuntdouble.io/api/mcpMCP Registry
The server is listed in the official MCP Registry as io.stuntdouble/mcp-server, so registry-backed clients and directories can find it by name:
curl "https://registry.modelcontextprotocol.io/v0.1/servers?search=io.stuntdouble/mcp-server"