# Spotwise, Inc. > Spotwise is an agentic operating system for broadcast media. It detects advertising across radio, TV, podcasts and streaming audio in real time, turns each detected airing into a qualified sales lead with decision-maker enrichment, drafts the outreach, and stages it in the broadcaster's CRM. Products: Spotwise aOS, Spotty (conversational co-pilot), Spotwise Intelligence, Lead-list, Contact Finder, Monitors & Signals, and Skills. EU-based (Riga), backed by 500 Global, used by broadcasters in 14 countries. This file was GENERATED by API Evangelist from probes of Spotwise's own public surface on 2026-08-12. Spotwise does not serve an llms.txt (https://spotwise.ai/llms.txt returns 404). ## What an agent can actually call - [Spotwise Remote MCP](https://app.spotwise.ai/api/mcp): The product MCP server. Streamable HTTP. OAuth 2.0 bearer required — an anonymous tools/list returns 401 with a WWW-Authenticate challenge. Scopes: openid, profile, email, offline_access. Tool list and input schemas are auth-gated and are not published. - [Spotwise CMS MCP](https://spotwise.ai/api/mcp): MCP server over the marketing site's content. OAuth 2.0 bearer required. Scopes add mcp:content.read and mcp:content.write. - [Spotwise Content API (REST)](https://spotwise.ai/api): Payload CMS 3 REST. Published content reads answer anonymously — /api/posts, /api/news, /api/pages, /api/media, /api/categories, /api/forms, /api/search, /api/insights. Page/limit pagination; response envelope carries docs, totalDocs, totalPages, hasNextPage. /api/users is 403. - [Spotwise Content GraphQL](https://spotwise.ai/api/graphql): Live GraphQL over POST. Anonymous queries against published content work. Introspection is DISABLED and no SDL is published, so the schema cannot be discovered by a machine. ## Authorization - [Authorization server metadata](https://spotwise.ai/.well-known/oauth-authorization-server): RFC 8414. authorization_code + refresh_token, PKCE S256, dynamic client registration, introspection, revocation, EdDSA id tokens. - [Protected resource metadata](https://spotwise.ai/.well-known/oauth-protected-resource): RFC 9728. Names the MCP resource and its authorization server. - [App authorization server metadata](https://app.spotwise.ai/.well-known/oauth-authorization-server) - [App protected resource metadata](https://app.spotwise.ai/.well-known/oauth-protected-resource) There is no /.well-known/openid-configuration, no security.txt, no api-catalog and no A2A agent card on any host. ## What does NOT exist - No OpenAPI or Swagger document anywhere. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc on spotwise.ai, app.spotwise.ai and api.spotwise.ai — all miss. - No developer portal, API reference, getting-started guide or code samples. - No SDK in npm, PyPI, RubyGems, crates.io or Packagist. The GitHub org SpotwiseAI holds three forks and no first-party code. (github.com/spotwise is a different company.) - No published rate limits and no RateLimit-*/Retry-After headers on any response. - No idempotency contract, no RFC 9457 problem details, no changelog, no deprecation or sunset policy, no SLA. - No public pricing. Quote-only: "Spotwise shares pricing on request." ## Company surface - [Website](https://spotwise.ai) - [Products](https://spotwise.ai/solutions): aOS, Spotty, Intelligence, Lead-list, Contact Finder, Monitors, Skills - [FAQ](https://spotwise.ai/faq): the most substantive public document about how the platform behaves - [Data & privacy](https://spotwise.ai/security): SOC 2 Type II and ISO 27001 both stated as in progress, not certified; GDPR alignment self-attested; EU AI Act alignment stated - [Status](https://status.spotwise.ai/): Better Stack; monitors "Dashboard" and "Spotwise API" - [News](https://spotwise.ai/news) - [Blog](https://spotwise.ai/blog) - [Glossary](https://spotwise.ai/glossary): ~120 broadcast-advertising terms - [Sign in](https://app.spotwise.ai) - [Book a demo](https://spotwise.ai/demo) - Contact: hello@spotwise.ai · security@spotwise.ai ## Notes for agents Spotwise's own launch announcement states: "All Spotwise data and workflows are available through an open API and a Model Context Protocol server." The MCP servers are real and spec-correct. The "open API" has no published description — no specification, no reference, no schema — so an agent cannot plan against it without an account. Everything an agent could do here begins with an interactive OAuth authorization_code + PKCE flow against https://app.spotwise.ai/api/auth.