MCP integration: setup and scope
Model Context Protocol, or MCP, allows Claude Code to use approved tools and data sources beyond its built-in capabilities.
An MCP server can provide controlled access to systems such as:
- Issue trackers
- Source-control platforms
- Documentation systems
- Monitoring tools
- Databases
- Internal APIs
- Design platforms
- Approved enterprise services
How MCP works
- Connect — Register an approved local or hosted MCP server with Claude Code.
- Discover — Claude identifies the tools and resources exposed by the server.
- Approve — Review requests, permissions, parameters, and the data involved.
- Execute — Claude invokes the approved tool and uses the returned result.
Connect only MCP servers approved for enterprise use. Verify ownership, authentication, permissions, data handling, network access, and logging before enabling a server.
Add an approved HTTP server
Run MCP configuration commands in the terminal, outside the interactive Claude Code session.
General structure:
claude mcp add --transport http <server-name> <server-url>
Example using the public Claude Code documentation server:
claude mcp add --transport http claude-code-docs https://code.claude.com/docs/mcp
The server name is a local label. Use a clear name that identifies the system or purpose.
Verify the connection
List configured servers:
claude mcp list
Check a specific server:
claude mcp get claude-code-docs
Start Claude Code:
claude
Inside the session, inspect MCP availability:
/mcp
Then test with a read-only request:
Use the Claude Code documentation MCP server to find the official guidance for plan mode.
Summarise the result and identify the source used.
Do not perform any write actions.
Remove a server
claude mcp remove claude-code-docs
Select the correct scope
MCP configuration may be applied at different scopes:
- Local: Available to the current user in the current project
- Project: Shared through project configuration
- User: Available to the current user across projects
- Managed: Controlled centrally by the enterprise
Use the narrowest scope that meets the requirement.
For evaluation, begin with local scope and read-only capabilities. Expand access only after the integration, permissions, and business need have been reviewed.
MCP security checklist
Before using any MCP server, verify:
- The server comes from an approved and trusted source
- Authentication follows enterprise standards
- Only required permissions are granted
- Secrets are stored outside source control
- Tool descriptions and parameters are reviewed
- Write and destructive actions require approval
- External content is treated as untrusted input
- Logs do not expose credentials or restricted information
- Customer and proprietary data remain within approved boundaries
- The server can be disabled or removed safely
Prompt-injection risk
MCP servers that retrieve external content may expose Claude to malicious or misleading instructions embedded in that content.
Reduce risk by:
- Using approved servers and trusted data sources
- Starting with read-only access
- Reviewing tool requests before approval
- Separating retrieved data from trusted project instructions
- Preventing uncontrolled access to credentials and production systems
- Requiring human approval for write, delete, deploy, or communication actions
Continue after connecting an approved server, verifying its scope and permissions, completing a read-only test, reviewing the returned source, and confirming that the server can be removed safely.