CLI and MCP Tools for GTM Engineers: Running Outbound From the Terminal (2026)
GTM engineers increasingly run list building, enrichment and campaign setup from a terminal: an agent CLI in front, the MCP servers of their tools behind it, and a few classic data utilities in between. We checked every tool in this guide against the vendor's own documentation in October 2026. Here is the stack by layer, a realistic workflow from target list to approved campaign, the guardrails that keep it from damaging your domain or your LinkedIn account, and who should not build this at all.
Kenneth Kather ยท Founder & CEO, KNK Outbound
Tools in this post
Key takeaways
- The 2026 terminal stack for GTM engineers has three parts: an agent CLI such as Claude Code, OpenAI Codex CLI or Gemini CLI, the official MCP servers or APIs of your GTM tools, and classic utilities like curl, jq, DuckDB and csvkit for list work.
- As of October 2026, Apollo, Attio, HubSpot, Instantly, lemlist, Smartlead, HeyReach, n8n, Apify, Firecrawl and Exa all document an official MCP server, and Clay offers MCP access to functions you enable. Clay, Firecrawl, Apify and HubSpot also ship a CLI. Community servers with the same names are not the same thing.
- A sensible workflow writes everything to a review file first: pull accounts, remove existing customers, research a reason to write, enrich contacts last to save credits, score and draft, and push only the rows a person has approved.
- Start read-only, test with ten rows, cap credits, keep keys out of prompts and shared config files, and never let an agent send emails or LinkedIn requests unreviewed. Without a technical owner, a proven offer and a market of more than a couple of hundred accounts, done-for-you is the better choice.
The short answer
The 2026 terminal stack for GTM engineers is an agent CLI (Claude Code, OpenAI Codex CLI or Gemini CLI), connected to the MCP servers or APIs of the tools you already pay for, plus a few classic data utilities such as curl, jq, DuckDB and csvkit. The agent does the research, enrichment and drafting. A human reviews everything that touches a prospect before it goes out. Most GTM tools now publish an official MCP server and a few also ship a real CLI, but which actions you allow matters far more than which interface you use.
What changed in the last year
A year ago, "outbound from the terminal" mostly meant Python scripts against vendor APIs. That still works. What changed is that agent CLIs now plug into vendor tools directly through the Model Context Protocol, the open standard we explained in plain language in MCP explained. Claude Code, Codex CLI and Gemini CLI all document how to add MCP servers, local or remote, and most sales tools now run one.
That turns the terminal into a control room. One session can pull accounts from Apollo, run a Clay function on them, check the CRM for existing relationships and write a review file, without a line of glue code. It is why the role we described in what a GTM engineer is is moving from building flows in no-code tools towards directing agents, a shift we looked at in the future of GTM engineering.
A small example from the vendor side: our own site runs a public, read-only MCP server at knkoutbound.com/mcp, described on our page for AI agents. In Claude Code, the command claude mcp add --transport http knk https://knkoutbound.com/mcp connects it, and the agent can then call get_pricing or check_fit by itself. Every vendor below works the same way, just with many more tools and with access to your real data. That last part is why the guardrails further down matter.
The stack by layer
We checked every entry against the vendor's own documentation in October 2026. "MCP" here means an official server from the vendor, not one of the many community projects with similar names on GitHub and MCP directories.
| Layer | Tool | Interface | Good for |
|---|---|---|---|
| Agent runtime | Claude Code | CLI, connects to MCP servers | Running the whole job from one session: files, tools, shell |
| Agent runtime | OpenAI Codex CLI | CLI, connects to MCP servers | The same role for teams on OpenAI |
| Agent runtime | Gemini CLI | CLI, connects to MCP servers | The same role, open source |
| Data and enrichment | Apollo | MCP (hosted, OAuth), API | People and company search, enrichment, hiring signals, sequences |
| Data and enrichment | Clay | CLI, MCP for enabled functions, API | Running Clay functions and workflows on a list from an agent |
| Data and enrichment | Exa | MCP (hosted), API | Web search and multi-step research to build and check lists |
| CRM | HubSpot | MCP (remote, OAuth), developer CLI | Reading and updating CRM records within the scopes you grant |
| CRM | Attio | MCP (hosted, OAuth), API | Lookups, notes, tasks, moving records between stages |
| Sending | Instantly | MCP (hosted), API | Campaigns, leads, analytics, sending accounts |
| Sending | Smartlead | MCP, API | Campaign insights, deliverability checks, lead data |
| Sending | lemlist | MCP (hosted, OAuth or key), API | Campaigns, leads, lead sourcing, email finding |
| Sending (LinkedIn) | HeyReach | MCP (per workspace), API | LinkedIn campaign data and lead handling |
| Scraping and research | Firecrawl | CLI, MCP | Scraping, crawling, mapping and searching websites |
| Scraping and research | Apify | CLI, MCP | Running ready-made scrapers (Actors) and reading their datasets |
| Glue | n8n | MCP (instance-level), API | Turning a proven terminal job into a scheduled workflow |
| Glue | curl, jq, DuckDB, csvkit | CLI | Calling APIs, reshaping JSON, SQL on CSV files, quick column cuts and stats |
- Tool
- Claude Code
- Interface
- CLI, connects to MCP servers
- Good for
- Running the whole job from one session: files, tools, shell
- Tool
- OpenAI Codex CLI
- Interface
- CLI, connects to MCP servers
- Good for
- The same role for teams on OpenAI
- Tool
- Gemini CLI
- Interface
- CLI, connects to MCP servers
- Good for
- The same role, open source
- Tool
- Apollo
- Interface
- MCP (hosted, OAuth), API
- Good for
- People and company search, enrichment, hiring signals, sequences
- Tool
- Clay
- Interface
- CLI, MCP for enabled functions, API
- Good for
- Running Clay functions and workflows on a list from an agent
- Tool
- Exa
- Interface
- MCP (hosted), API
- Good for
- Web search and multi-step research to build and check lists
- Tool
- HubSpot
- Interface
- MCP (remote, OAuth), developer CLI
- Good for
- Reading and updating CRM records within the scopes you grant
- Tool
- Attio
- Interface
- MCP (hosted, OAuth), API
- Good for
- Lookups, notes, tasks, moving records between stages
- Tool
- Instantly
- Interface
- MCP (hosted), API
- Good for
- Campaigns, leads, analytics, sending accounts
- Tool
- Smartlead
- Interface
- MCP, API
- Good for
- Campaign insights, deliverability checks, lead data
- Tool
- lemlist
- Interface
- MCP (hosted, OAuth or key), API
- Good for
- Campaigns, leads, lead sourcing, email finding
- Tool
- HeyReach
- Interface
- MCP (per workspace), API
- Good for
- LinkedIn campaign data and lead handling
- Tool
- Firecrawl
- Interface
- CLI, MCP
- Good for
- Scraping, crawling, mapping and searching websites
- Tool
- Apify
- Interface
- CLI, MCP
- Good for
- Running ready-made scrapers (Actors) and reading their datasets
- Tool
- n8n
- Interface
- MCP (instance-level), API
- Good for
- Turning a proven terminal job into a scheduled workflow
- Tool
- curl, jq, DuckDB, csvkit
- Interface
- CLI
- Good for
- Calling APIs, reshaping JSON, SQL on CSV files, quick column cuts and stats
Two notes on the table. For HubSpot, "CLI" means the developer CLI (hs), which builds apps on HubSpot and comes with a local MCP server for that purpose. Your CRM data runs through the separate remote MCP server. For Clay, MCP access is switched on per function: according to Clay's developer docs, publishing a function does not automatically expose it to an MCP client.
What each layer is really for
Agent runtime. Use the one your team already pays for. Claude Code stores MCP servers per project, per user, or in a shared project file that is checked into version control. Codex CLI keeps them in its config.toml and, according to OpenAI's docs, shares that configuration with the ChatGPT desktop app. Gemini CLI supports local servers as well as SSE and streamable HTTP. For GTM work, the differences between the three are smaller than the forum debates suggest.
Data and enrichment. Apollo's hosted MCP server covers people and company search, single and bulk enrichment, job postings as hiring signals, and sequences. Enrichment consumes credits, and Apollo's docs point out that people search returns no emails or phone numbers until you enrich. Clay now has a JSON-first CLI that agents use to run Clay functions and workflows. Exa runs a hosted MCP server with web search, page fetching and a multi-step research tool that can build a list and check each entry against criteria. If you are still choosing a data tool, our Clay alternatives guide covers the field.
CRM. HubSpot's remote MCP server lists read and write access for contacts, companies, deals and engagements, governed by the scopes of an app you create. One FAQ on the same page still calls the access read-only, so check the scopes you actually granted rather than trusting either sentence. Attio's hosted server signs in with OAuth and acts as your user, which means the agent can do whatever you can do in that workspace.
Sending. Instantly documents 31 MCP tools across campaigns, leads, email, analytics and accounts. lemlist supports OAuth or an API key and lets you limit which tools the agent sees with a bucket parameter, for example only prospecting tools. Smartlead documents an MCP server for campaign insights and deliverability checks. When we checked, its help article listed Claude Desktop as the only supported client, so confirm before you plan around it. HeyReach gives each workspace its own MCP connection URL.
Scraping and research. Firecrawl has both a CLI, with scrape, crawl, map and search commands, and an MCP server. Apify has a CLI for building and running its scrapers, called Actors, and a hosted MCP server that runs Actors and reads their results.
Glue. n8n exposes an instance-level MCP server, so an agent can search, run and even edit the workflows you enable for it. That is where a terminal job belongs once it has proven itself, as covered in n8n for sales automation. For everything in between, the classics still win: curl to call an API, jq to reshape JSON, DuckDB to run SQL directly on a CSV file, csvkit to cut columns and get quick statistics.
A realistic workflow, start to finish
Here is a job one person with a terminal can run sensibly: around 400 target accounts, one segment, one offer.
- Pull the target list. The agent queries Apollo for companies that match your written ICP and writes them to accounts.csv. You check the count and spot-check twenty rows before going further.
- Remove what you already have. The agent checks each domain against HubSpot or Attio and drops customers, open deals and anyone who opted out. If you export the CRM first, DuckDB does this join locally in seconds.
- Find a reason to write. Exa or Firecrawl reads each company's website, job posts or news and writes one line of evidence per account, with the source URL. No source, no line. Accounts without a reason drop out.
- Enrich contacts last. Only for accounts that survived step 3, the agent finds the right person and a verified email through Apollo or a Clay function. Enriching last saves credits on accounts you would have dropped anyway.
- Score and draft. The agent scores each row against the ICP and writes a first email per contact into drafts.csv, with columns for score, evidence, draft and approved.
- Human review. A person reads every draft, edits or deletes it, and sets approved to yes. The first batch from a new segment usually loses a fair share of rows here. That is the point of the step.
- Push approved rows only. The agent adds approved rows to an Instantly, Smartlead or lemlist campaign, and a person starts it. LinkedIn steps go to HeyReach the same way, reviewed.
- Log and learn. Every pushed row, the prompt version and the approver go into a log file. Replies flow back into the CRM, and the next batch starts from what worked.
On researched lists with a real reason to write, reply rates of 3 to 8% are realistic. Generic lists land below that, however clever the pipeline is. The terminal makes steps 1 to 5 much faster. It does not make step 6 optional.
Guardrails before you connect anything
- Read-only first. Start with read scopes in the CRM and add write access for one object once the job has run cleanly. Remember that an Attio OAuth connection acts as your user, and that an Apollo master key is a workspace-level credential, not a personal one. Use what the vendors offer to narrow access, such as lemlist's tool buckets and Clay's per-function MCP switch.
- Dry runs. Every write goes to a file first. Push ten rows, check them in the tool, then push the rest.
- Rate limits and API costs. Apollo enrichment consumes credits, lemlist warns before actions that use credits, and Apify limits its MCP server to 30 requests per second per user. An agent stuck in a retry loop burns through credits quickly, so set budgets inside the vendor tools, not only in the prompt.
- No unreviewed sending, and never on LinkedIn. LinkedIn's User Agreement prohibits bots or other unauthorized automated methods to add contacts or send messages, and software that scrapes profiles. An agent sending connection requests on its own is what that clause describes, and the account at risk is yours. Agents prepare, people approve.
- Keep secrets out of prompts. Use OAuth where it is offered and environment variables otherwise. Some vendors put the key into the connection URL: Instantly as a fallback, Smartlead and HeyReach by design. Treat those URLs like passwords and keep them out of project-level MCP files that get committed to a shared repository.
- Log everything. Which rows, which prompt, who approved, when it went out. When something goes wrong, the log is how you find out what.
Two legal points belong here. Since August 2, 2026 the transparency rules of the EU AI Act apply. One-to-one sales emails drafted by AI and substantively reviewed by a human sit comfortably, while chatbots and voice agents need a disclosure, as our EU AI Act guide explains. And in Germany, advertising email without prior consent counts as an unreasonable nuisance under the UWG, even in B2B. Presumed consent is the rule for phone calls to businesses, not for email. Austria is stricter. An agent changes none of that. It only makes it faster to break the rules at scale. Our guide on whether cold outreach is allowed covers each channel. This is not legal advice.
Who should not do this
- Nobody technical on the team. Someone has to read an API error, understand what a key can do and notice when the agent did something odd. Without that person, this stack is a liability, not a shortcut.
- A small market. With fewer than a couple of hundred possible buyers, research them by hand and write to each one personally. The pipeline costs more time than it saves.
- No proven offer. If nobody has bought yet, automation scales a message nobody has validated. Talk to twenty buyers first.
- You want meetings, not a project. Building and maintaining this takes weeks, then ongoing attention: APIs change, tools rename features, deliverability needs watching.
The honest alternative is done-for-you: hand the whole motion to a team that already runs it, or hire a GTM engineer once outbound has proven itself for your offer.
Where we fit
KNK Outbound does outbound for B2B companies in Europe and the US, done for you. We build the target lists, buy and validate the data, set up and warm domains and mailboxes, write the messages, send on cold email and LinkedIn, handle every reply, call interested prospects personally and book qualified meetings into your calendar. Tools, data, domains and mailboxes are included in the price, which starts at 3,300 euros a month, with details on the pricing page. If you have a GTM engineer and the market to justify building this yourself, this guide is a fair starting point, and we will tell you the same on a call.
Frequently asked questions
What are the best CLI tools for GTM engineers who want to run outbound and enrichment from the terminal?
Start with an agent CLI: Claude Code, OpenAI Codex CLI or Gemini CLI, all of which connect to MCP servers. Connect the official MCP servers of your tools, for example Apollo for search and enrichment, HubSpot or Attio for the CRM, and Instantly, Smartlead or lemlist for sending. Add Firecrawl or Apify for scraping, Exa for research, and curl, jq, DuckDB and csvkit for list work. Keep a human review step before anything reaches a prospect.
Do Apollo, Clay, HubSpot and Instantly have official MCP servers in 2026?
Yes, according to each vendor's documentation in October 2026. Apollo and HubSpot run hosted servers with OAuth sign-in, Instantly runs a hosted server authenticated with your API key, and Clay offers MCP access to the functions you enable, plus a CLI. Many community servers use the same names, so connect to the endpoint listed in the vendor's own docs.
I'm a solo founder. Can I just let Claude Code find leads, enrich them and send cold emails on autopilot?
You can automate the research, enrichment and drafting, but not the sending without review. Agents make confident mistakes, such as the wrong person, the wrong company or an invented reason to write, and each one lands in a real inbox under your domain. Have the agent write drafts to a file, read them, and push only approved rows. In Germany, advertising email to businesses without prior consent is restricted under the UWG, so check the legal side first. This is not legal advice.
Is it allowed to let an AI agent send LinkedIn connection requests automatically?
LinkedIn's User Agreement prohibits bots or other unauthorized automated methods to add contacts or send messages, so an agent sending requests on its own breaks the terms and puts your account at risk. Let the agent prepare targets and messages and have a person approve every action. Under the EU AI Act, human-reviewed one-to-one messages sit comfortably, while chatbots and voice agents need a disclosure.
Should we build an agent-based outbound stack ourselves or hire an agency?
Build it yourself if you have a technical person who can own it, a proven offer and a market large enough to justify weeks of setup and ongoing maintenance. Otherwise a done-for-you agency is usually the faster route to meetings. KNK Outbound runs the whole motion from 3,300 euros a month, with tools, data, domains and mailboxes included.