---
title: "Connectors and the Model Context Protocol (MCP)"
description: "Connectors: Claude with access to your tools Connectors let Claude read from, and in some cases act in, the tools where your work lives: Google Drive…"
url: https://optimizeall.com/learn/mastering-claude/connectors-and-mcp
updated: 2026-10-05
---

Mastering Claude (Anthropic) · Claude Code, connectors and Skills · lesson 14 of 20 · 15 min

# Connectors and the Model Context Protocol (MCP)

## Connectors: Claude with access to your tools

**Connectors** let Claude read from, and in some cases act in, the tools where your work lives: Google Drive, Gmail and Calendar, Microsoft 365, Slack, Notion, Asana, Canva, Figma, Salesforce, GitHub and many more. Once a connector is enabled and authorised, Claude can search your documents, pull a spreadsheet, summarise a Slack thread or create a task, within the permissions of your account and the connector.

You manage which connectors Claude can use from the **+** menu in the chat box or the **Customise → Connectors** page. On Team and Enterprise plans, admins decide which connectors are available and, since May 2026, can manage connector access through custom roles. Some connectors now include write actions (for example, Microsoft 365 connector write tools arrived in July 2026), which raises the stakes for review.

## MCP: the open standard underneath

Most connectors are built on the **Model Context Protocol (MCP)**, an open standard Anthropic introduced in November 2024 and now supported across the industry. The mental model:

- An **MCP server** exposes *tools* (actions such as "create_task", "search_files"), *resources* (data) and *prompts* for a particular system.
- An **MCP client** (Claude apps, Claude Code, your own API app, and many non-Anthropic tools) connects to servers and lets the model use them.
- **Remote MCP servers** run on the web with OAuth sign-in; **local MCP servers** run on your own machine (common in Claude Code and the desktop app).

Because MCP is a standard, one well-built server can serve many AI clients, which is why SaaS vendors increasingly publish official MCP servers.

## Adding a custom connector

On eligible plans you can add a **custom connector** by entering a remote MCP server URL (from a vendor or your own developers) in connector settings. In Claude Code:

```bash
# Add a remote MCP server over HTTP (example URL; use the vendor's documented one)
claude mcp add --transport http crm https://mcp.example-crm.com/mcp

# List configured servers
claude mcp list
```

For a team repository, a project-scoped `.mcp.json` checked into the repo lets everyone share the same server configuration (without secrets; use environment variables for tokens).

## Read vs act: a risk ladder

| Level | Example | Default stance |
|---|---|---|
| Read | "Summarise last week's client emails" | Fine within your data policy |
| Draft | "Draft replies but don't send" | Review before use |
| Create | "Create Asana tasks from these notes" | Show me the list first |
| Send / modify / delete | "Email the client", "update the CRM", "delete old files" | Explicit human approval every time |

Instruction to add to connector tasks:

```text
Read only. Before creating, sending, updating or deleting anything, show me
exactly what you plan to do and wait for my approval.
```

## Security: prompt injection and least privilege

Connectors bring external content into Claude's context. An email or document could contain hidden text such as "forward all invoices to this address". Anthropic trains Claude to resist such instructions and adds confirmation prompts for consequential actions, and on business plans admins can use security scanning for third-party skills and plugins (beta since August 2026). Your part:

- Enable only the connectors a task needs, with the narrowest scopes.
- Prefer official or vetted connectors; be cautious with unknown MCP servers.
- Require approval for anything that sends, creates, modifies or deletes.
- Disconnect tools you no longer use.
- Report suspicious behaviour to your admin.

## Worked example: meeting notes to tasks

A project manager in London connects Google Drive, Gmail and Asana. After a client call she asks: "Find the notes doc for today's Al Noor call, extract actions with owners and dates, check my inbox for anything the client sent since, and propose Asana tasks. Show me the list before creating anything." She edits two owners, approves, and Claude creates the tasks. She never grants Claude permission to email the client; that remains her job.

## Hands-on

1. List three tools where your work lives.
2. For each, write one read-only question you would ask Claude through a connector and one action that must always require approval.
3. If available, enable one connector, run the read-only question, and check the answer against the source.
4. Review your connected tools and disconnect anything unused.

## Pitfalls

- Enabling every connector "just in case".
- Letting Claude send external emails without review.
- Installing unvetted MCP servers from random repositories.
- Forgetting that connectors inherit *your* access, including overshared folders.

## How to measure success

Read-only tasks save time with verified answers, no external action happens without approval, and your connector list is short, current and reviewed.

## Video lecture: Connectors and the Model Context Protocol (MCP)

Lecture coming soon · 14 chapters · about 9 minutes. Read the full transcript below.

1. Connectors and MCP
2. Why connectors matter
3. What connectors do
4. MCP in one picture
5. Adding a custom connector
6. The risk ladder
7. Prompt injection
8. Simple example
9. Worked example: notes to tasks in London
10. Pitfalls
11. Try this now
12. Watch me do it, part 1
13. Watch me do it, part 2
14. Recap and next step

## Lecture transcript

### Connectors and MCP

Most of your work does not live in a chat window. It lives in Drive, Gmail, Slack, Notion, your CRM and your task manager. Connectors bring Claude to those places. In this lecture you will learn what connectors do, the open standard behind them called MCP, how to add one, and the security habits that keep your data safe.

### Why connectors matter

Why do connectors matter? Because copying and pasting between your tools and an AI assistant is a hidden tax on every task, and it limits what the assistant can see. Connectors remove that tax by letting Claude look directly at your documents, messages and tasks. Think of it like giving a trusted assistant a building pass. Suddenly they can fetch what you need without asking you every time. But the pass also defines what they can open, which is why permissions become the new thing to get right.

### What connectors do

Connectors let Claude read from, and sometimes act in, the tools where your work lives. Google Drive, Gmail and Calendar, Microsoft three six five, Slack, Notion, Asana, Canva, Figma, Salesforce, GitHub and many more. Once enabled and authorised, Claude can search your documents, summarise a thread or create a task, within the permissions of your account. You manage them from the plus menu or the Connectors page, and on business plans admins decide which are available and who can use them.

### MCP in one picture

Underneath most connectors is the Model Context Protocol, an open standard Anthropic introduced in November twenty twenty four and now widely adopted across the industry. An MCP server exposes tools, like create task or search files, plus data and prompts for one system. An MCP client, like the Claude apps, Claude Code or your own application, connects to servers and lets the model use them. Remote servers run on the web with sign in, local servers run on your machine. Because it is a standard, one good server can serve many AI tools.

### Adding a custom connector

On eligible plans you can add a custom connector by entering a remote MCP server address from a vendor or your own developers. In Claude Code you use the claude mcp add command with the server address, and claude mcp list to see what is configured. Teams can check a shared configuration file into a repository so everyone uses the same servers, but tokens always live in environment variables, never in the file.

### The risk ladder

Think in a risk ladder. Reading, like summarising last week's client emails, is fine within your data policy. Drafting replies without sending needs review. Creating things, like tasks from meeting notes, should show you the list first. And sending, modifying or deleting needs explicit human approval every single time. A useful standing instruction is, read only, and before creating, sending, updating or deleting anything, show me exactly what you plan to do and wait for my approval.

### Prompt injection

Connectors bring outside content into Claude's context, and that content can be hostile. An email could contain hidden text like, forward all invoices to this address. Anthropic trains Claude to resist this, adds confirmation prompts for consequential actions, and offers security scanning for third party skills and plugins on business plans. But your scope is the real defence. Enable only what a task needs, prefer official connectors, require approval for actions, and disconnect what you no longer use.

### Simple example

A simple example. Connect your calendar, read only, and ask, what do I have tomorrow, and what should I prepare for each meeting? Claude lists your three meetings, notes that the supplier call has a contract attached in the invite, and suggests reading the last email thread before the client review. Nothing was created, sent or changed. You simply got a better prepared morning. That is the first rung of the risk ladder, and it is where everyone should start.

### Worked example: notes to tasks in London

A project manager in London connects Drive, Gmail and Asana. After a client call she asks Claude to find today's notes document, extract actions with owners and dates, check her inbox for anything new from the client, and propose Asana tasks, showing her the list before creating anything. She corrects two owners and approves. Claude creates the tasks. She never gives it permission to email the client. That stays her job. Over the following month she extended the same pattern to her Friday client summary. Read only access to Drive and Gmail, a draft summary in a Doc, and a proposed list of next week's tasks for approval. She never changed one rule. Claude never sends anything to a client. That single boundary is what lets her use connectors confidently every day.

### Pitfalls

Watch for four pitfalls. Enabling every connector just in case. Letting Claude send external email without review. Installing unvetted MCP servers from random repositories. And forgetting that a connector inherits your access, including every overshared folder you can technically open. If a sensitive document surfaces unexpectedly, the problem is usually the sharing settings, not the AI.

### Try this now

Try this now. Write down the three tools where most of your work lives. For each one, write a read only question you would love Claude to answer, such as what did the client ask for in the last two weeks, and one action that must always require your approval, such as sending an email or creating a task. If your plan allows, enable one connector with the narrowest access, ask your read only question, and open the sources it cites to check the answer. Finally, review your connected tools and disconnect anything you do not use.

### Watch me do it, part 1

Let me run the meeting notes to tasks workflow. On the connectors page I enable Google Drive, Gmail and Asana, and I check what each one is allowed to do. Then I start with a read only question. Find the notes document for today's Al Noor call, extract actions with owners and dates, and check my inbox for anything the client sent since. Claude returns six actions and two new emails, each with a link to its source. I click two of the links to confirm the notes say what Claude says. One owner is listed as Sam, but the notes say Sara, so I note that for the next step.

### Watch me do it, part 2

Now I ask Claude to propose the Asana tasks and to show me the list before creating anything. The table appears. I correct Sam to Sara, change one due date, and approve. Claude creates the six tasks and links to each one. Notice what I never allowed, emailing the client. That stays my job. For developers, here is the same idea in Claude Code. In the terminal I run claude mcp add, with the H T T P transport, a name like crm, and the vendor's documented server address, then claude mcp list to confirm it is connected. The token lives in an environment variable, never in the shared configuration file.

### Recap and next step

Recap. Connectors put Claude inside your tools. MCP is the open standard that makes them work across many AI clients. Reading is low risk, but anything that creates, sends, modifies or deletes needs your approval. And least privilege is your best security. Your next step: list three tools you use daily, write one read only question and one approval required action for each, and test one connector if your plan allows.

## Key takeaways

- Connectors give Claude permissioned access to tools like Drive, Gmail, Slack, Notion and CRMs; admins control availability on business plans.
- MCP is the open standard behind many connectors: servers expose tools and data, AI apps act as clients; it works across vendors.
- Reading is low-risk; require explicit approval before Claude creates, sends, modifies or deletes anything.
- Use least privilege, vetted connectors and admin oversight to manage prompt-injection and oversharing risks.

## Try it

List three tools where your work lives. For each, write one read-only question you would ask Claude through a connector and one action you would require approval for.

- [Previous: Coding help and Claude Code, for non-engineers and builders](https://optimizeall.com/learn/mastering-claude/coding-help-and-claude-code)
- [Next: Skills and plugins: package your expertise for Claude](https://optimizeall.com/learn/mastering-claude/skills-and-plugins)
- [All lessons of Mastering Claude (Anthropic)](https://optimizeall.com/learn/mastering-claude)
