Claude Code MCP: how to connect Claude to your business tools
What MCP is in Claude Code, how to add a server with claude mcp add, which scope to pick, and how to keep connected tools safe in a real business.
Short answer
MCP (Model Context Protocol) is the open standard Claude Code uses to connect to outside tools like your CRM, calendar, task board or database. You add a server with one command, claude mcp add, and Claude can then read and act inside that tool. Connect one tool at a time, start with read access, and only add a server you trust.
Key takeaways
- An MCP server is a connector. It gives Claude Code a set of tools for one outside system, such as a task board, an inbox or a database.
- You add one with claude mcp add. Remote servers use --transport http and a URL, local ones run a command on your machine.
- Scope decides who gets the server: local is just you in one project, project is shared through .mcp.json, user is you in every project.
- Every server you add is access you hand out. Start read-only, keep risky actions behind your approval, and never install a server you would not trust with the data.
- MCP gives Claude access, not judgment. Pair each connected tool with memory or a skill that explains how you use it.
Claude Code on its own can read and write files and run commands on your machine. That is a lot. But most of a business does not live in files. It lives in a CRM, a calendar, an inbox, a task board, a database.
MCP is how Claude gets into those places. In my own setup, Claude Code reaches my Trello board, my inbox, my calendar and n8n through MCP servers. Without them it would be a smart assistant with no hands.
This guide covers what MCP is, how to add a server, which scope to pick, and how to do it without handing an AI the keys to everything.
What is MCP in Claude Code?
MCP, the Model Context Protocol, is an open standard that lets Claude Code connect to outside tools and data through small connectors called MCP servers. Each server exposes a set of tools for one system. Connect a calendar server and Claude can list your meetings. Connect a database server and it can run queries.
Anthropic introduced MCP in November 2024 as an open protocol, not a Claude-only feature. That choice is why it spread. Other AI apps and coding tools adopted it, and in December 2025 Anthropic donated MCP to the Agentic AI Foundation under the Linux Foundation. In that announcement, Anthropic said there were more than 10,000 active public MCP servers. For you that means one thing: for most popular business tools, a connector already exists.
The simplest way to think about it: a USB port for AI. The tool vendor builds the plug once, and any MCP client can use it.
How is MCP different from skills, subagents and CLAUDE.md?
MCP gives Claude access to a tool, while skills, subagents and CLAUDE.md shape what Claude knows and how it works. They are separate layers, and a useful setup combines them.
| Part | What it adds | Example |
|---|---|---|
| CLAUDE.md | Facts that are always true | What you sell, who your clients are |
| Skill | The procedure for one task | How you write a proposal |
| Subagent | A separate worker with its own context | Research that should not clutter your main session |
| MCP server | Access to an outside system | Reading and updating your CRM |
Access without knowledge gives you fast, generic work. Claude can open your CRM, but it does not know which deals matter or how you follow up. That part lives in memory and skills. I covered both in my guides to Claude Code skills and Claude Code subagents.
How do you add an MCP server to Claude Code?
You add an MCP server with the claude mcp add command in your terminal, then check it inside Claude Code with /mcp. The exact command depends on where the server runs.
There are two common kinds:
- Remote servers run on the vendor's side. You connect over HTTP with a URL, and you usually log in through your browser.
- Local servers run as a program on your own machine. Claude Code starts them with a command, often through
npxoruvx, and talks to them directly.
Here is the order I would follow for your first one:
- Pick one tool. The one where you spend the most time copying things in and out of Claude. Often a task board or a CRM.
- Find the official server. Check the vendor's docs first. A server from the company that makes the tool beats a random one from a search.
- Add it. For a remote server:
For a local server, everything afterclaude mcp add --transport http notion https://mcp.notion.com/mcp--is the command that starts it:claude mcp add my-tool --env API_KEY=your_key -- npx -y some-mcp-server - Connect and log in. Start Claude Code and type
/mcp. You see every server, whether it is connected, and a login option for servers that use OAuth. - Test with a read. Ask something harmless first: "list my open tasks" or "show the last five deals". Check the answer against the real tool.
- Only then try a write. Create one test item, see what happened, and decide what Claude may do on its own.
Two more commands you will use: claude mcp list shows everything you have installed, and claude mcp remove <name> deletes a server you no longer need.
Which scope should you pick: local, project or user?
The scope decides who gets the server and where its config is stored. You set it with --scope when you add the server.
| Scope | Who gets it | Stored in | Use it for |
|---|---|---|---|
local (default) |
Only you, only in this project | Your personal Claude Code config | Trying a server, or anything with private credentials |
project |
Everyone who works in the repo | .mcp.json in the project root |
Tools the whole team should use the same way |
user |
Only you, in every project | Your personal Claude Code config | Tools you want everywhere, like your own task board |
For business work I lean on user for personal tools and project for shared ones. A .mcp.json file looks like this:
{
"mcpServers": {
"crm": {
"type": "http",
"url": "https://example.com/mcp"
}
}
}
Never put API keys in that file if you commit it. Claude Code can read environment variables in .mcp.json with ${VAR} syntax, so the file can be shared while the secret stays on each machine. Claude Code also asks for approval before it uses a project server for the first time, which is a good moment to check what you are turning on.
Which MCP servers are worth connecting first?
The servers worth connecting first are the tools where you already copy and paste between Claude and the app. That copying is the cost MCP removes.
For most small businesses that shortlist looks like this:
- Task board: Trello, Asana, Linear, Notion. Claude can read what is open, update cards and give you a plan for the day.
- Calendar and email: meeting prep with context, inbox triage, drafts in your voice.
- CRM: who said what, which deals are stuck, who needs a follow-up.
- Automation platform: n8n or similar, so Claude can work with workflows and not only describe them.
- Database or analytics: questions in plain language instead of exports.
You do not need all of them. One connected tool that Claude uses every day beats ten it touches once a month. If you want to see how a few connected tools turn into a working system, I walked through my own setup in this walkthrough of my daily setup. My free resources include Claude Code templates and n8n automations you can start from.
How do you keep MCP servers safe?
You keep MCP servers safe by treating every server as access you hand out: trust the source, give it the narrowest access that works, and keep risky actions behind your own approval. An MCP server can read and change real data. That is the point, and it is also the risk.
The things I would check before connecting anything:
- Who built it? Prefer official servers from the tool's vendor. Anthropic's own docs warn that third-party servers are used at your own risk and are not verified by them.
- What can it do? Read your data, or also create, change and delete it? Start with read access where the tool allows it.
- What does it fetch? A server that pulls in web pages, emails or documents brings in text you did not write. That text can contain instructions meant to mislead the model. This is called prompt injection, and it is the main reason not to let Claude act on outside content without a check.
- Which actions need you? Claude Code asks permission before using a tool unless you allow it. Keep it that way for anything that sends, pays, publishes or deletes. You can also deny specific tools in your permission settings.
This is not theory. Gartner predicted in June 2025 that over 40% of agentic AI projects will be canceled by the end of 2027, pointing to rising costs, unclear business value and weak risk controls. In my experience the risk part is mostly boring: access that is too wide and no human on the risky steps. I went through those patterns one by one in my article on agents that break after launch.
What goes wrong with MCP in Claude Code?
Most MCP problems come from connecting too much at once, not from the protocol itself. A few I would watch for:
- Too many servers. Every server adds tool descriptions Claude has to consider. Ten servers you rarely use make it slower to pick the right tool and fill your context. Remove what you do not use.
- Huge tool output. A query that returns thousands of rows floods the session. Claude Code warns when an MCP tool returns more than 10,000 tokens and caps output at 25,000 tokens by default, according to Anthropic's documentation. Ask for filtered, summarized results instead.
- Silent login expiry. A server that worked last week now fails because the token expired. If Claude says a tool is unavailable, check
/mcpfirst. - Access without instructions. Claude can update your CRM, but nobody told it your pipeline stages. The output looks confident and is wrong. Write it down in a skill or in CLAUDE.md.
Is MCP worth setting up?
Yes, once Claude already knows your business and you are tired of being the copy-paste layer between it and your tools. Setting up a single server takes minutes. Making it useful takes a bit longer, because Claude needs to know how you use that tool.
My advice: connect one tool, read-only, and use it for a week. Watch what Claude gets right and where it guesses. Write the guesses down as instructions. Then give it the next permission, or the next tool.
That is how an assistant in a terminal becomes something that works inside your business. One connector at a time, with you deciding what it may touch.
Frequently asked questions
What is MCP in Claude Code?
MCP stands for Model Context Protocol, an open standard Anthropic introduced in November 2024 for connecting AI models to outside tools and data. In Claude Code, an MCP server adds a set of tools Claude can call, for example to read your calendar, update a task or query a database.
How do I add an MCP server to Claude Code?
Run claude mcp add in your terminal. For a remote server: claude mcp add --transport http <name> <url>. For a local server: claude mcp add <name> -- <command>. Then open Claude Code and type /mcp to check the connection and log in if the server asks for it.
Where is the Claude Code MCP config stored?
Project-scoped servers live in a .mcp.json file in the root of your project, which you can commit and share. Local and user-scoped servers are stored in your personal Claude Code configuration (~/.claude.json), so they are not shared with anyone.
Are MCP servers safe to use?
They are as safe as the server and the access you give it. A server can read and change data in the connected tool, and content it fetches can contain instructions meant to mislead Claude. Use servers from sources you trust, prefer read-only access to start, and keep actions like sending or deleting behind your approval.
What is the difference between MCP and a Claude Code skill?
MCP gives Claude access to a tool. A skill tells Claude how to do a task. You usually need both: the MCP server lets Claude open your CRM, the skill explains how you qualify a lead once it is in there.
- /2 oct 2026
Claude Code skills: what they are and how to write one
What a Claude Code skill is, where SKILL.md lives, how to write a description Claude actually picks up, and which business tasks deserve a skill first.
- /23 jun 2026
Claude Code subagents: when to use them and how to build one
When a Claude Code subagent beats a skill or slash command, how to write one as a Markdown file, and the rules that stop agents flooding your context.
- /16 jan 2026
How I Run My Business With Claude Code: The 5 Jobs It Handles
I use Claude Code as an AI employee with memory: tasks, calendar, email, n8n workflows and sales. What it does, what changed, what it costs, how to start.
