AppFlow
← Blog

MCP Explained: How to Connect Claude to All Your Business Tools in 2026

Claude gives sharper answers when you paste in context. The problem is that you are the one doing the pasting: copying from Notion, switching tabs to check a spreadsheet, pulling a thread from Slack, then assembling it into a prompt. Now imagine Claude fetching what it needs from those tools directly, acting on its findings, and writing results back. That is what the Model Context Protocol makes possible.

MCP is an open standard Anthropic published on November 25, 2024. It defines a common wire format for connecting AI models to external data sources and tools. Instead of building a one-off integration for every service, you deploy a small MCP server that speaks a language Claude already understands. Within 13 months the protocol crossed 97 million monthly SDK downloads. In December 2025, Anthropic donated it to the Linux Foundation alongside OpenAI and Block. That governance move signals something important: MCP is infrastructure now, not a product feature.

If you manage a tool stack and want to know whether Claude can actually connect to it without a custom development project, you will find out here: under-the-hood mechanics, step-by-step Claude Desktop setup, which servers to trust (and why most community servers will let you down), and where things quietly break in production.

If you are new to Claude API implementations and want to understand the full tiered approach from system prompts to Managed Agents, start with building a custom Claude AI assistant for small business.

What MCP Actually Is

Before MCP, connecting Claude to your tools meant writing custom code: call the tool's API, format the data, inject it into a Claude prompt, parse the response, call another API. For each new integration, you repeated that cycle. It worked, but nothing transferred between projects and every integration was one-off maintenance.

MCP standardizes the plumbing. It defines a client-server architecture where Claude (the client) speaks JSON-RPC 2.0 to a small server that handles one specific tool. The spec defines three primitives a server can expose: Resources (data Claude can read), Prompts (reusable instruction templates), and Tools (actions Claude can execute). On Claude's side: Sampling, Roots, and Elicitation handle how Claude interacts back with the server.

What this means practically: the plumbing for Notion, Google Drive, GitHub, Slack, and hundreds of other services already exists. You run the server, point Claude at it via a config file, and Claude gains live read and write access to that tool without any custom API code on your part.

97M+ Monthly SDK downloads, Python and TypeScript combined
78% Enterprise AI teams with MCP agents in production, July 2026
17,468 MCP servers indexed across registries, Q1 2026

The adoption curve reflects genuine production use, not hype. As of July 2026, 41% of surveyed software organizations are in limited or broad production with MCP servers, per Stacklok's 2026 report, and 28% of Fortune 500 companies run MCP servers. The Linux Foundation governance structure means vendor-neutral oversight, which matters if you are making a multi-year architectural bet.

For a closer look at how these deployments translate into real productivity gains and what breaks in production, see Claude AI agents: real business impact vs. the hype.

What MCP Enables That the Standard Claude API Cannot

The standard Claude API is stateless. You send context with every request, and you manage all tool calls yourself. If you want Claude to know what is in your Notion workspace, you retrieve that content first and include it in every prompt. MCP changes three things fundamentally.

Persistent, bidirectional data access. Claude can read from and write to your tools within a single session. A Notion page Claude reads can also be the page Claude updates with a structured summary. A Slack channel Claude monitors can also receive Claude's output. The connection runs both ways.

On-demand context retrieval. Instead of you deciding upfront what context to include, Claude fetches what it needs during the conversation. Ask "what is the status of the design agency project?" and Claude queries Notion, reads the relevant page, and answers from live data, not whatever you happened to paste in earlier.

Cross-tool orchestration in a single prompt. With Notion, GitHub, Slack, and Gmail MCP servers active, a single instruction can check Gmail for emails from your design agency this week, pull the related Notion project, create a GitHub issue for each action item, and post a summary to your #design Slack channel. End-to-end, without switching tabs or copying anything manually.

One concrete example: a rental company connected Gmail MCP to their rental management system and a Slack MCP server. Claude watches the inbox, parses order emails, pushes data to the management system, and posts a Slack notification. Per-order handling dropped from 15-30 minutes to under 2 minutes. Zero custom API code written.

Want Claude connected to your tool stack via MCP? I can set it up for your business.

Book a free call →

Setting Up Claude Desktop with MCP: Step by Step

Claude Desktop is the primary local MCP client, available on macOS and Windows. Here is what setup actually involves.

  1. Install Claude Desktop and upgrade your plan. MCP connectors require Pro ($17/month billed annually), Max ($100+/month), Team, or Enterprise. The Free plan does not include MCP access. Download Claude Desktop from claude.ai/download.
  2. Edit the config file. On macOS, it lives at ~/Library/Application Support/Claude/claude_desktop_config.json. On Windows, at %APPDATA%\Claude\claude_desktop_config.json. This JSON file declares which MCP servers Claude should connect to on startup. Each entry specifies a command to run and the environment variables (API keys, tokens) it needs.
  3. Add your first server. A minimal Notion config looks like this:
    {
      "mcpServers": {
        "notion": {
          "command": "npx",
          "args": ["-y", "@notionhq/notion-mcp-server"],
          "env": {
            "OPENAPI_MCP_HEADERS": "{\"Authorization\": \"Bearer YOUR_TOKEN\", \"Notion-Version\": \"2022-06-28\"}"
          }
        }
      }
    }
  4. Or use Desktop Extensions for a simpler path. Anthropic ships .mcpb files for reviewed servers. Double-click one in Claude Desktop Settings under Extensions, and the server installs without any JSON editing. This is the better option for non-technical team members. Extensions in Anthropic's reviewed directory have passed a security vetting process.
  5. Restart Claude Desktop. Connected servers appear as tool icons in the chat interface. You are done. Test by asking Claude to search your Notion workspace or list recent files in Drive.

Connecting Notion, Google Drive, Slack, and Airtable

These four tools cover the majority of small business workflows. Here is what each integration actually delivers and how reliable it is.

Tool Server Tools exposed Maintained by Status
Notion makenotion/notion-mcp-server 22 (pages, databases, search, comments, move) Notion Production-ready
Google Drive Pre-built, shipped at MCP launch Nov 2024 Search, read, metadata fetch Anthropic Production-ready
Slack Official Slack MCP server (Feb 2026) + Slackbot as MCP client (Mar 31 2026) Query data, post messages, trigger cross-tool workflows Slack Production-ready
Airtable Community servers (no official vendor server) Varies by server Community Verify before use

The Notion server version 2.0.0, migrated to Notion API spec 2025-09-03, is 91% more token-efficient for database operations than its predecessor. It is one of the cleaner integrations to start with. The Slack integration is particularly interesting: since March 31, 2026, Slackbot is itself a full MCP client, meaning your team can trigger cross-tool workflows from a single Slack thread with no custom API code at all.

For Airtable, check the Anthropic Claude Connectors Directory first. It lists 343 verified integrations vetted for security across 30 categories as of July 2026. Pick from that list rather than running a random community server. The reliability picture for unverified servers is poor, and I will explain exactly why below.

For a broader guide to connecting Claude via tool use and API across data sources including Airtable, Notion, and live CRMs, see building a custom Claude AI assistant.

The Context Bloat Problem: What Breaks Two Weeks After Launch

This is the failure mode I see most often, and it is subtle enough that teams miss it for weeks.

A development team connects three well-regarded MCP servers: GitHub, Slack, and Sentry. They demo the setup internally. Everything works smoothly. They roll it out to the engineering team. Two weeks later, response quality has noticeably degraded. Claude picks wrong tools, truncates answers, and occasionally loops on tasks it handled cleanly before. Nobody changed any configuration.

The root cause is how MCP serializes tool schemas. Every MCP tool's full JSON schema is appended to the context window on every single request, before any user message is processed. Those three servers expose roughly 40 tools between them. An April 2026 production measurement of exactly this configuration found those tool schemas consumed 143,000 of a 200,000-token context window before any user query arrived. That leaves only 57,000 tokens for the actual conversation and Claude's output.

Scalekit's benchmark (75 comparisons on Claude Sonnet 4.6) confirmed that MCP costs 4 to 32 times more tokens than a direct CLI call for identical operations. The simplest task in their test consumed 1,365 tokens via CLI versus 44,026 via MCP. These numbers do not argue against MCP, but they do mean that cost modeling matters before you scale.

The fix has three parts:

  • Prefer vendor-maintained servers with narrow tool sets. Official vendor servers expose fewer, better-documented tools. Stripe's server focuses on payment operations rather than surfacing every API endpoint. Fewer active tool schemas means more context for actual work.
  • Stay under 20 active tools per session. If you need broader coverage, use progressive disclosure: load only the server relevant to the current query rather than connecting all servers simultaneously. The MCP Tool Search feature enables this pattern.
  • Enable prompt caching. Use cache_control on your system prompt. Cache reads on Claude Sonnet 4.6 cost 10% of the standard input price, so $0.30 per million tokens instead of $3.00. The repeated tool-schema payload is exactly the kind of static content that benefits from caching. A 5-minute cache write costs 1.25x base input price but pays back on a single cache hit. For workloads with sustained sessions, this typically cuts tool-schema cost by 85-90%.

Teams that apply all three generally recover full usable context and see response quality return to baseline within a session or two of making the change.

For a full cost breakdown by model tier and query volume with worked examples, see the custom Claude assistant guide which covers Haiku vs. Opus 4.8 economics in detail.

Security Risks and the Spec Break on July 28

Two security issues deserve explicit attention, not a footnote.

CVE-2025-54136 (MCPoison, August 2025) exposed a persistent code execution vulnerability in how tool descriptions are processed. A malicious MCP server can craft a tool description that causes the client to execute arbitrary code. This is structural: every MCP server you connect to has significant access to your local environment. Treat each server as a third-party dependency with full trust implications. Only connect servers you have audited or that appear in Anthropic's vetted connectors directory.

CVE-2025-68143, 68144, and 68145 (early 2026) found path traversal and argument injection vulnerabilities in Anthropic's own mcp-server-git server. An official Anthropic server. These have been patched, but they confirm that no server is exempt from review, including vendor-maintained ones.

Spec break: July 28, 2026

The MCP 2026-07-28 release candidate (effective today) eliminates the Mcp-Session-Id header, the initialize handshake, and sticky routing requirements in one sweep. The architecture moves from stateful sessions to fully stateless. Any production server not updated to this spec by today's date will break. If you run self-hosted servers, check their GitHub release notes now. Vendor-maintained servers will push updates promptly; community-maintained servers are considerably less reliable about tracking spec changes.

Choosing Servers That Will Actually Hold Up

The MCP ecosystem has a reliability problem that is not obvious from the outside. A Q1 2026 census indexed 17,468 servers across registries. An April 2026 audit of 1,847 of those found 52% are effectively dead: no commits in 90 or more days, broken endpoints, unpatched CVEs. Only 17% meet a reasonable production standard. The typical community server has 6 commits over its entire lifetime and 142 days since its last update.

The pattern is consistent across maintenance models. Vendor-maintained servers (Stripe, GitHub, Sentry) show only an 11% abandonment rate. Community and hobby servers run 74%. Only 12.9% of all servers score 70 or above on a composite trust score covering documentation, maintenance frequency, and endpoint reliability.

My filter when evaluating servers for a client engagement:

  • Start with the Anthropic Claude Connectors Directory (343 verified integrations vetted for security, organized across 30 categories).
  • Prefer servers where the tool vendor maintains the repository: Notion, Stripe, GitHub, and Slack are all vendor-owned.
  • Check the GitHub repo before committing: last commit date, open issue response rate, whether the server references the 2025-11-25 spec or later.
  • Skip servers with no documentation, no versioning history, and no maintainer response on open issues.

This due diligence takes about 15 minutes. It is considerably less painful than building a workflow on a server that quietly breaks three months later, after your team has come to depend on it.

Frequently Asked Questions

What is MCP (Model Context Protocol) and how does it work with Claude?

MCP is an open standard Anthropic published in November 2024. It defines how Claude connects to external tools using JSON-RPC 2.0 as the wire protocol. A small server handles translation between Claude's requests and a specific tool's API. Claude sends a tool call, the server executes it, and the result returns into the conversation. You declare which servers Claude connects to via a JSON config file in Claude Desktop, or via the connectors interface on claude.ai for remote servers.

Do I need to write code to connect Claude to Notion or Google Drive via MCP?

For major tools like Notion, Google Drive, Slack, and GitHub, no custom code is required. These tools have existing MCP servers you install via npx or as Desktop Extensions (.mcpb files). You will edit a JSON config file and supply API keys, but there is no programming involved. If you want to connect a tool that has no existing server, or need custom behavior, then you would build a server using the official Python or TypeScript MCP SDK.

Which Claude plan do I need to use MCP?

MCP connectors require Pro ($17/month billed annually), Max ($100+/month), Team, or Enterprise. The Free plan does not include MCP access. Remote MCP (cloud-hosted servers) is currently in beta. On Team and Enterprise plans, only account Owners can add MCP connectors at the organization level, so coordinate with whoever manages your Claude account.

How much does running Claude with MCP actually cost?

You pay standard token rates for the model you use. Claude Sonnet 4.6 is $3 per million input tokens and $15 per million output tokens. Claude Sonnet 5 runs at introductory pricing of $2/$10 per million tokens through August 31, 2026, then rises to $3/$15 from September 1. The key nuance: MCP tool schemas consume large numbers of tokens before your message even arrives. Three servers with 40 total tools can consume 143,000 tokens per request. Prompt caching (cache reads at 10% of standard input price) offsets this significantly on repeated payloads. Web search as a tool adds $10 per 1,000 searches on top of token costs.

Is MCP secure enough for business use?

It can be, with deliberate sourcing. Use vendor-maintained servers rather than community ones (74% abandonment rate, frequent unpatched CVEs). Only add servers you have reviewed or that appear in Anthropic's verified directory. Treat each MCP server as third-party code with full access to your local environment, because that is exactly what it is. CVE-2025-54136 (MCPoison) showed that a malicious server can exploit tool description parsing to execute arbitrary code. The risk is real; the mitigation is sourcing carefully and keeping servers updated.

What is the difference between MCP and just calling the Claude API directly?

The Claude API is stateless: you send context with every request and manage all tool calls in your own code. MCP adds a persistent, bidirectional connection to external tools that Claude can use autonomously within a session. The tradeoff: MCP is faster to set up for supported tools and enables real-time data access, but costs 4 to 32 times more tokens than a direct CLI call for identical operations per Scalekit's benchmark. For simple, high-volume batch processing, the direct API with manual context management is usually more cost-efficient. For complex, multi-tool workflows where you would otherwise copy-paste between applications, MCP earns its overhead.

Will my MCP servers break after the July 28, 2026 spec update?

Possibly, if you run self-hosted servers that have not been updated. The 2026-07-28 spec eliminates Mcp-Session-Id, the initialize handshake, and sticky routing requirements, shifting to a fully stateless architecture. Servers built against the old spec will stop working correctly. Check the GitHub release notes for each server you run. Vendor-maintained servers (Notion, GitHub, Slack) will update promptly; community servers are far less reliable about tracking spec changes. This is a concrete reason to prefer vendor-owned infrastructure.

MCP applies across any sector with fragmented tooling. If your business is in professional services, real estate, or retail and commerce, see the sector pages for which MCP connectors are most relevant to your workflow.

Aurélien Migeot is a freelance AI developer based in France. He has spent 8 years building Claude-powered tools and agents for small businesses. Founder of AppFlow Solutions. Book a free discovery call

Let's discuss your project, free 30-minute discovery call

Book a call
MCPModel Context ProtocolClaudeAI agentsNotion integrationGoogle DriveSlackClaude Desktop