AI for Work

Connect Claude Code to One MCP Tool With a Read-Only Check

Cihan's view: Choose a trusted provider, add one MCP server with the documented command or URL, inspect the discovered tools, and run one harmless read before considering any write permission.

Choose another work task →

MCP is useful when copying information from another system into chat has become the slow part. It also adds another permission boundary. Start with one trusted server and one harmless read. Leave write actions for a separate review.

Advanced builder lesson. Evidence label: documentation-based guide with fictional inputs and illustrative output. The connection below was not executed here. The server URL is a placeholder, so this article does not claim a successful MCP connection.

What you need

  • Claude Code on a terminal, IDE, desktop app, or browser surface. The official overview lists the supported surfaces and notes that access requirements vary.
  • A trusted MCP provider with current setup instructions and a documented read-only test.
  • A disposable project folder. Do not begin in a production repository.
  • Permission from the data owner to connect the selected system.

Claude Code’s MCP reference says MCP servers can provide access to external tools and data sources. It also warns you to verify that you trust a server, especially when it fetches external content.

1. Pick the boundary before the command

Use this fictional task map:

Task: read the status of one fictional project ticket
Source: approved issue tracker workspace
Read needed: ticket title, status, and owner
Write needed: none
Data excluded: comments containing personal data, credentials, and all other projects
Acceptance check: the returned ticket ID and status match the source page

Do not choose a server from an arbitrary directory entry. Use the provider’s official documentation or a trusted organization directory, and record the exact URL and date you reviewed.

2. Add the server using its documented transport

Claude Code documents remote HTTP and local command based MCP setups. The exact provider details belong in the provider’s own instructions. The following is a shape example, not a runnable server:

# Replace the placeholder URL only after verifying the provider and scopes.
claude mcp add --transport http approved-tickets https://mcp.example.invalid/mcp

For a local server, the provider may document a command such as npx -y package-name. Do not copy a package name from this article. Check its provenance, version, authentication method, and requested scopes first.

If the provider gives JSON rather than a command, compare its mcpServers block with the current Claude Code MCP reference. Never put a token in a project file or a public repository.

3. Inspect discovery before using the tool

Ask Claude Code:

List the MCP server named approved-tickets and show the available tools.
Do not call a tool, write data, change permissions, or send a request yet.
For each tool, classify the action as read, write, delete, or unknown.
Stop if the server name, scopes, or tool descriptions do not match the approved task map.

The checkable artifact is a short table:

Tool Action class Inputs Scope match Human decision
get_ticket read project ID and ticket ID yes or no allow or stop
update_ticket write ticket ID and new status no for this task do not use

This table is an editor-defined acceptance artifact. It is not a captured MCP result.

4. Run one harmless read

Only after the tool list and scopes pass review, request one fictional record:

Use only the approved-tickets read tool.
Read ticket DEMO-17 in project DEMO.
Return the ticket ID, title, status, and owner exactly as returned.
Do not edit, comment, transition, create, delete, or fetch another record.
If the record is unavailable, report that without guessing.

Compare the returned ID and status with the source page. Stop if the server returns more data than the task map permits, if the scope is broader than approved, or if the tool is not clearly read-only.

No-code alternative

If you do not need a live connection, export one approved ticket or copy its non-sensitive fields into Claude Code. Use the same task map and acceptance table, but keep the data flow manual. Copy and paste is slower, but it avoids adding a new integration while you are still deciding whether the workflow is useful.

Troubleshooting

  • The server authenticates but no tools appear: check the configured transport, server name, account scope, and whether the provider exposes tools to this client.
  • A tool description is vague: classify it as unknown and stop. Ask the provider for current documentation.
  • The read returns too much information: disconnect or narrow the scope before trying again. Do not solve an overbroad permission with a longer prompt.
  • A local package asks for unexpected access: stop installation, inspect the official package documentation, and ask a technical owner to review it.
  • The command differs from this example: follow the current provider and Claude Code documentation. This article deliberately avoids claiming a universal command.

Limits and safe use

MCP access is not automatically safe because the connection works. Review server provenance, authentication, scopes, data retention, and every write-capable tool. Start with test data and least privilege. Keep consequential actions behind a human approval step.

TRY this with one trusted server, one fictional record, and one read-only tool. SKIP arbitrary servers, production data, and write actions during the first connection. USE the integration only when the task map, tool list, and source comparison all pass review.

Sources and next step

For a nontechnical starting point, use ChatGPT to review a draft against a written brief before adding an integration.

About Cihan

Creator and operator focused on practical AI for business professionals. Background and editorial approach →