Key Takeaways
- The Marketo MCP server covers 100+ live operations today.
- Delete operations are restricted from MCP and AI use.
- No autonomous triggers exist; a person must start every session.
- Smart List and Smart Campaign creation ships in September 2026.
- Setup needs only LaunchPoint credentials and a Munchkin Account ID.
- Rate limits and permissions still inherit from your Marketo instance.
Table of Contents

The Marketo MCP server can run more than 100 operations against your instance, but it still can’t delete a record, run itself on a schedule, or build a Smart List from scratch. Adobe has the last two targeted for a September 2026 release, and until then, assuming otherwise is how a routine automation request turns into an open support ticket.
If you run marketing operations on Adobe Marketo Engage, you’ve probably already connected an AI assistant to the Marketo MCP server to clone a form, check a lead record, or activate a smart campaign without touching the UI. Adobe’s own developer documentation lists coverage across eight object domains, forms, programs, smart campaigns, leads, emails, snippets, lists, and folders, more than 100 operations in total.
That breadth is real, but it has edges. Delete operations, autonomous or scheduled runs, and Smart List or Smart Campaign creation and updates all sit outside what the server will do today, some by permanent design, some only until Adobe ships its next release. This piece maps that boundary precisely, using Adobe’s developer documentation as the source, not guesswork, so you know it before you build on it.
What the Marketo MCP Server Can Do Today
The Marketo MCP server covers eight object domains and more than 100 operations, which means it already handles most of the routine work a Marketo admin fields by hand every week. Adobe documents the full list in its Marketo Engage MCP Server reference, and this piece is the Marketo-only half of the broader picture, if you also run Eloqua, see 4TM’s guide to using MCP with Eloqua and Marketo for how the standard applies across both platforms.
Forms, Programs, and Email Management
Adobe’s Marketo MCP server can manage forms end to end: create a new form, clone an existing one into a different folder, approve it, and configure individual fields. It can also handle programs, creating, cloning, and tagging them, then browsing the results by type or channel. On the email side, it browses existing emails, creates and updates them, and manages reusable snippets, the kind of asset work that used to mean opening Design Studio and clicking through folders one at a time, or working inside 4TM’s breakdown of the new Marketo Engage email editor to build the template first.
Smart Campaigns, Leads, and Lists
Smart campaigns get real coverage too: the Marketo MCP server can create a smart campaign, configure its filters, add flow steps, and activate or deactivate it. On the lead side, it can find a lead, create a new one, and manage list membership, useful for one-off record fixes without opening the Lead Database directly. Every one of these is a live write operation, not a read-only preview, though it’s worth remembering that shared lead fields still carry their own quirks, the kind covered in 4TM’s program member custom field case study, regardless of whether a person or an assistant is the one editing the record.
Bulk Operations and Instance Structure
Beyond individual assets, the Marketo MCP server can execute bulk lead exports and monitor the resulting job status, and it can browse your instance’s structure, folders, channels, tags, and activity types, so an assistant can orient itself before it changes anything. That combination of asset management and instance visibility is what makes an Adobe Marketo MCP server connection worth the setup effort in the first place, and it pairs naturally with tracking work like 4TM’s guide to Marketo PPC integration, where accurate campaign attribution depends on the same underlying instance structure.
What the Marketo MCP Server Can’t Do (Yet)
Three Marketo MCP limitations matter more than the rest: it won’t delete anything, it won’t run without a person present, and it can’t build Smart Lists or Smart Campaigns from nothing, at least not for a few more months.
No Delete Operations, By Design
The underlying Marketo API includes delete_folder, delete_form, delete_program, and delete_snippet calls, but Adobe restricts every one of them from MCP and AI use, a full list of what is and isn’t exposed is in Adobe’s MCP Server Operations reference. That’s one of the clearest Marketo MCP limitations to plan around: the available Marketo MCP write operations cover create and update calls across every domain, but deletion is never one of them, and any workflow that assumes otherwise needs a human in the loop before anything gets removed.
No Autonomous Triggers or Scheduled Monitoring
The Marketo MCP server doesn’t host, run, or train any AI or ML model itself, and it doesn’t learn from your data between calls, all of that intelligence lives in the connected AI client, not the server. It also runs only inside a conversation a person starts. There’s no autonomous trigger, no scheduled monitoring job, and no stored credentials or session state carried between requests, a deliberate Marketo MCP security boundary, not an oversight. If you want the equivalent of a nightly cleanup routine, you’re still writing that outside the MCP layer; for a deeper look at where autonomous decisioning does live inside Marketo, see 4TM’s guide to Marketo Agentic AI, which covers Agent Studio and lead orchestration.
Smart List and Smart Campaign Create/Update, Targeted for September 2026
This is the gap practitioners hit first: creating or updating Smart Lists, and creating or updating the Smart Campaign asset itself (distinct from activating one that already exists), isn’t among today’s Marketo MCP write operations. Adobe has both targeted for a September 2026 release, so treat this as a near-term roadmap item, not a standing wall. Until it ships, plan segment and campaign-asset builds the way you always have, and let the server handle everything downstream of that build.
Setting Up the Adobe Marketo MCP Server
Getting the Adobe Marketo MCP server connected takes two credentials and one network path, nothing more exotic than that. You’ll need a Client ID and Client Secret, generated from Admin & LaunchPoint, and a Munchkin Account ID, found under Admin & Munchkin, or alternatively an IMS token paired with your org ID. From there, your AI client needs network access to Adobe’s hosted endpoint at https://marketo-mcp.adobe.io/mcp. There’s no local server to install, deploy, or patch; Adobe runs the infrastructure, and your credentials do the rest of the work. If your team already manages custom connections between Marketo and other systems, the setup pattern will look familiar, see 4TM’s breakdown of custom API integrations for the underlying model.
Marketo MCP Security: What Actually Governs Every Call
Every call the Marketo MCP server makes inherits its limits from your instance, not from the MCP layer itself. Rate limits and API quotas are whatever your Marketo instance already enforces, and permissions come from the role assigned to whichever API user you connect. Marketo mcp security, in other words, is Marketo’s existing API governance, nothing about the MCP layer widens or bypasses it.
Assign a tightly scoped API user in LaunchPoint, and the assistant can only do what that user is allowed to do; assign a broad one, and the assistant inherits that same breadth. The control point was always your permission model, and every Marketo MCP security review should start there, not with the MCP layer itself, which just makes it easier to notice when that model is too loose.
Conclusion
Adobe’s Marketo MCP server already covers more than 100 operations across forms, programs, smart campaigns, leads, emails, and instance structure, real write access, not a demo. What it withholds is just as deliberate: no delete operations, no autonomous runs, and, until September 2026, no ground-up Smart List or Smart Campaign creation. That combination of broad access and clear Marketo MCP security boundaries is exactly why it is worth wiring up now rather than waiting for every gap to close, and the Marketo MCP server’s boundary itself is not a moving target you need to keep re-checking week to week.
Knowing where it sits before you connect an assistant to production is what turns this from a support ticket into a genuine time saver. If you want help scoping a rollout, from LaunchPoint permissions to the specific write operations worth automating first, contact us and 4Thought Marketing’s Marketo team will help you map it to your instance.
About 4Thought Marketing
We're a B2B marketing automation and AI consultancy with a thing for getting complex tech to actually work. Since 2008, we've helped hundreds of organizations across financial services, technology, manufacturing, and real estate get more from Eloqua, Marketo, and their CRM integrations. We serve our clients across marketing automation strategy, lead lifecycle, AI, compliance, preference management, and more. Explore our services or get in touch.
FAQs
What is the Marketo MCP server used for?
It connects AI assistants like Claude, Copilot, or Cursor directly to your Adobe Marketo Engage instance, letting them execute real API calls across forms, programs, smart campaigns, leads, emails, and snippets instead of you clicking through the UI every time. It covers more than 100 operations across eight object domains, from routine form cloning to bulk lead exports.
Can it delete Marketo records?
No. Delete operations for folders, forms, programs, and snippets exist in Marketo’s underlying API, but Adobe restricts all of them from MCP and AI use. This is one of the most important Marketo MCP limitations to plan around before giving an assistant broad access.
Does it run on its own, without a person starting it?
No. The Marketo MCP server operates only inside a conversation a person initiates, with no autonomous triggers, scheduled monitoring, or stored credentials between requests. It also contains no AI or ML models itself; the intelligence lives entirely in the connected client.
When will it support creating Smart Lists and Smart Campaigns?
Adobe has targeted a September 2026 release for Smart List and Smart Campaign create and update tools. Until then, those two asset types still need to be built the traditional way, with everything downstream handled through the server.
What credentials does the Adobe Marketo MCP server require?
You need a Client ID and Client Secret from Admin u0026amp; LaunchPoint plus a Munchkin Account ID from Admin u0026amp; Munchkin, or an IMS token with your org ID. Your AI client also needs network access to Adobe’s hosted endpoint; there’s no local server to install.
Does the Marketo MCP server bypass Marketo’s API rate limits or permissions?
No. Marketo mcp security runs entirely on your instance’s existing rate limits and the permissions of whichever API user you assign in LaunchPoint. The MCP layer doesn’t widen access or bypass governance, it just routes requests through it.





