anfloy.AcademyBook a call

Foundation · 04 · Connect your stackLesson 1 of 4

MCP: plugging tools into Claude

60 min working time · Week 4

By the end of this lesson you can
  • Connect your first MCP servers (Slack, Notion, Drive...)
  • Understand scopes: personal vs project vs team connections
  • Evaluate whether a connector is safe to add

What MCP is and why it changes the job

Today your first business tool gets wired into Claude Code and starts answering real questions, with a shareable team connection committed to git. Until now, Claude could only touch files on your machine. MCP - the Model Context Protocol - is the open standard that connects it to the systems your work actually lives in: Notion, Slack, HubSpot, Stripe, GitHub. Each connection is a server that exposes tools Claude can call: search pages, read channels, update records.

Once your CRM is connected, "pull this week's new deals and summarize what changed" stops being a copy-paste exercise and becomes a sentence. Every vertical track in this course runs on connections you set up this week.

Add your first server

  1. Pick a tool your team uses that has an official server - Notion is a good first one.
  2. In the terminal: claude mcp add --transport http notion mcp.notion.com/mcp
  3. Open a session and run /mcp - it lists your servers, their status, and tool counts.
  4. The server needs your permission to act as you: /mcp starts the OAuth login, your browser opens, you approve, done.
  5. Test with a real ask: "Search our Notion for the onboarding checklist and summarize it."
The MCP management commands
claude mcp add --transport http notion https://mcp.notion.com/mcp
claude mcp list
claude mcp get notion
claude mcp login notion      # OAuth from the terminal, no session needed
claude mcp logout notion
claude mcp remove notion

HTTP is the recommended transport for hosted servers; the older SSE transport is deprecated, so if a tutorial shows --transport sse, use http instead. Local servers that run on your machine use stdio - you will meet one eventually; hosted HTTP covers the mainstream business tools. The GTM stack has caught up: Apollo, HubSpot, Attio, Instantly and lemlist all publish hosted MCP servers as of September 2026, and the sales track wires them in.

Scopes: who gets the connection

  • local (default) - yours, this project only. Right for trying things out.
  • user - yours, every project. Right for your personal daily tools.
  • project - written to a .mcp.json file in the project, committed to git, shared with the team. Teammates get an approval prompt before it activates - nobody silently inherits a connection.
.mcp.json - team-shared, secrets stay out via ${VAR}
{
  "mcpServers": {
    "github": {
      "type": "http",
      "url": "https://api.githubcopilot.com/mcp/",
      "headers": {
        "Authorization": "Bearer ${GITHUB_PAT}"
      }
    }
  }
}

That ${GITHUB_PAT} placeholder is the standard pattern: the file in git names the variable, each machine supplies its own value from the environment. The connection is shared; the credentials never are. This rhythm - config in git, secrets in env - repeats in the next lesson.

Connectors you already have flow in for free

Big recent change: connectors set up in the claude.ai web app automatically appear in Claude Code when you are logged in with your subscription. If you connected Gmail or Google Drive at claude.ai, your Claude Code sessions can already use them - zero terminal setup. Some Anthropic-hosted connectors (Gmail, Google Calendar, Microsoft 365) can ONLY be authorized through claude.ai, not locally.

Is this connector safe to add?

A connection is a grant of power, so evaluate before adding. The questions that matter:

  • Who publishes it? Official vendor servers and the reviewed directory beat a random repo from a forum post.
  • Read or write? A server that can send messages or modify CRM records deserves more caution than one that only searches. Check what the OAuth grant asks for.
  • Does it fetch external content? Anything that pulls web pages or emails into context can carry prompt injection - hidden instructions in the fetched content. Treat write-capable servers that also read external content as the highest-risk combination.
  • Does the team need it, or just you? Default to local scope; promote to project scope deliberately.
  • Does it spend money when called? An enrichment or data server that bills per lookup needs the same rule as an API key: no batch calls through it without the per-unit cost times count stated first.

Do this now

Sources and further reading

We set it up with you

Want us to set it up with you, end to end?

Three one-on-one sessions. We train you on your real stack and build your first agents together, until you can run it yourself. You keep everything.