The 10 Best MCP Servers for Business in 2026 (Tested Criteria, Pros & Cons)

10 best MCP servers for business

The 10 Best MCP Servers for Business in 2026: A Fact-Checked Ranking with Pros, Cons and a Security Playbook

Last verified: October 5, 2026. Every capability claim below was checked against vendor documentation, official changelogs or release notes. Where only a secondary source was available, we say so.

TL;DR

The best MCP servers for business in 2026 are the official, vendor-hosted ones that inherit your existing permissions. Our ranking, in order:

  1. Salesforce Hosted MCP Servers: best for enterprise CRM
  2. HubSpot Remote MCP Server: best for mid-market sales, service and marketing
  3. Atlassian Rovo MCP Server: best for Jira and Confluence teams
  4. Slack MCP Server: best for team conversation context
  5. Notion MCP Server: best for knowledge and project workspaces
  6. Zapier MCP: best for reaching apps that have no native server
  7. Stripe MCP Server: best for payments and billing
  8. Basis Desk MCP Server: best free, no-key crypto news and market data feed
  9. Snowflake-Managed MCP Server: best for governed analytics
  10. Google Workspace MCP Server: best for Gmail, Drive and Calendar, but still in preview

Three rules cover most of the decision. Pick the server for the system where your team already spends the most hours. Prefer OAuth-based servers that respect user-level permissions. Keep write access narrow until you have logs and approvals in place.


What is an MCP server, and why does it matter for business?

The Model Context Protocol (MCP) is an open standard that lets AI applications connect to external tools and data. An MCP host (such as an AI assistant or IDE) creates an MCP client for each MCP server it uses. The server advertises its tools, the model decides when to call them, and the results flow back into the conversation. Client and server talk over JSON-RPC 2.0.

For a business, the practical meaning is simple. Without MCP, an assistant answers from its training data and whatever you paste into the chat. With MCP, the same assistant can look up a deal in your CRM, summarize a Jira epic, search Slack threads, check a Stripe customer or query a governed warehouse, using your credentials and your permissions.

That shift creates two things at once: real productivity and real risk. A server that can read your CRM can also leak it. A server that can issue refunds can issue the wrong refund. The best servers on this list are best not because they expose the most tools, but because they pair useful tools with sound governance.

How we ranked these servers

We scored each server on five criteria. Weighting reflects what business buyers told the market they care about most: trust first, breadth second.

  • Official status and maturity. Is the server built and hosted by the vendor? Is it generally available (GA), or still in beta or preview?
  • Authentication and permission model. Does it use OAuth, and does it inherit the user’s existing access rather than bypass it?
  • Governance and auditability. Can admins enable, restrict, log and revoke it?
  • Business reach. How many real workflows does it unlock, and for how many teams?
  • Friction and cost. What plan, edition or setup does it require?

Quick comparison table

# Server Best for Auth Status (as verified) Main caveat
1 Salesforce Hosted MCP Enterprise CRM OAuth 2.0 + PKCE GA (April 2026) Enterprise Edition or above
2 HubSpot Remote MCP Sales, service, marketing OAuth 2.1 + PKCE GA (April 2026) Sensitive-data accounts block activity objects
3 Atlassian Rovo MCP Jira, Confluence, Compass OAuth 2.1 (API token for some products) GA No FedRAMP or HIPAA support
4 Slack MCP Team context and messaging OAuth GA (February 2026) Admin approval; exposes whatever the user can see
5 Notion MCP Wikis, specs, trackers OAuth only Hosted, actively maintained No bearer-token option
6 Zapier MCP Long-tail app coverage OAuth or token Available (beta badge on one page) Two tasks billed per call
7 Stripe MCP Payments and billing OAuth or restricted API key Official hosted server Write scopes need strict limits
8 Basis Desk MCP Crypto news, prices, whale transfers None (read-only, free) Live; very new Attribution required
9 Snowflake-Managed MCP Governed analytics OAuth 2.0 GA (November 2025) No dynamic client registration
10 Google Workspace MCP Gmail, Drive, Calendar Google auth Public developer preview (May 2026) Preview status; quota tiering

1. Salesforce Hosted MCP Servers

Short answer: the strongest option for organizations whose revenue operations already run on Salesforce.

Salesforce’s hosted MCP servers reached general availability in April 2026. A hosted server is a Salesforce-managed endpoint that exposes your org’s data, flows, Apex actions and queries to any AI client that speaks MCP. Salesforce hosts and scales it the way it does its REST APIs, so there is nothing to provision or keep running. You can use prebuilt standard servers for areas such as the Agentforce 360 Platform, Tableau Next and Data 360 SQL, or configure custom servers that expose your own flows, Apex actions and Named Query APIs.

How it is secured. Authentication uses OAuth 2.0 with PKCE. The platform is secure by default: servers must be explicitly enabled (in Setup, under API Catalog, then MCP Servers), and the server defines exactly which operations exist, so an assistant cannot call an API that was never exposed. Salesforce’s existing permission model and audit trails apply, and MuleSoft AI Gateway can add centralized governance across all of your MCP servers, not just Salesforce.

Pros

  • Governance is the headline feature. Existing permissions, audit trails and an explicit allow-list of operations.
  • Zero infrastructure. No hosting, uptime or scaling work on your side.
  • Extensible. Custom servers can wrap the flows and Apex logic your team already trusts, so AI inherits your business rules instead of reinventing them.
  • Broad client support. Works with any MCP-compatible client, including Claude and ChatGPT.

Cons

  • Edition gate. Hosted servers require Enterprise Edition or above.
  • Only useful if you live in Salesforce. The value is tied to how much of your process is already modeled there.
  • Naming confusion. “Salesforce MCP” can mean the hosted servers, the local Salesforce DX developer server, Agentforce’s own MCP client, or a Marketing Cloud Engagement server. They solve different problems.
  • Admin work up front. Enabling and scoping servers is an admin task, not a self-serve click.

Best for: RevOps and sales teams on Enterprise Edition or higher. Skip if: you are on a lower edition or your CRM is elsewhere.


2. HubSpot Remote MCP Server

Short answer: the most accessible CRM server for small and mid-sized teams.

HubSpot’s remote MCP server, hosted at mcp.hubspot.com, graduated from beta to general availability in April 2026. The release added write capabilities, activity history, marketing content objects and organizational context. It authenticates with OAuth 2.1 and PKCE, and every action respects the user’s existing HubSpot permissions. Users can only read or change records they could already read or change in the app.

A fact-checking footnote worth knowing. HubSpot updated its own changelog on April 15, 2026 to correct information about read and write access. Several early write-ups predate that fix, so when you evaluate scope, rely on the current documentation rather than older blog summaries. In general, core CRM objects and engagements support create and update, while some objects, including marketing content and organizational context, are read-only.

Pros

  • Real two-way CRM access through natural conversation, not just search.
  • Permission-aware. No privilege escalation through the assistant.
  • Hosted by HubSpot. No local install, no infrastructure.
  • Clear separation from the developer server. The remote CRM server is distinct from the local Developer MCP server used to build apps and CMS content.

Cons

  • Sensitive-data restriction. If your account has Sensitive Data enabled, activity objects (calls, emails, meetings, notes, tasks) and conversation data are blocked through the MCP server. This restriction is specific to MCP and does not apply to the standard CRM APIs.
  • Setup requires an MCP auth app. It is straightforward, but it is not a one-click experience for every client.
  • Some capabilities depend on plan. Certain access is documented as available only with Marketing Hub Professional or Enterprise.
  • Write actions need monitoring. The ability to update contacts, deals and tickets in bulk is powerful and worth putting behind review.

Best for: sales, service and marketing teams on HubSpot. Skip if: your compliance posture requires sensitive-data mode and you need activity history in the assistant.


3. Atlassian Rovo MCP Server (Jira, Confluence, Compass)

Short answer: the default choice for engineering and operations teams that run planning in Jira and documentation in Confluence.

The Atlassian Rovo MCP Server is generally available for Jira, Confluence and Compass on Atlassian Cloud. A consolidated tool set lets assistants search, create, update and link Jira issues, Confluence pages and Compass components. Atlassian describes it as enterprise-first: it uses OAuth 2.1, always respects existing permissions, and provides MCP usage logs so administrators can see how AI is interacting with Jira and Confluence. Atlassian says the server does not store or cache your content. Jira Service Management and Bitbucket Cloud are also reachable, but only through API token authentication, and an organization admin has to enable that option.

A secondary source dates general availability to February 4, 2026. Atlassian’s own announcement confirms GA but we could not confirm that exact date from a first-party page.

Pros

  • Bulk work from one prompt. Create an epic and linked issues, then tie them back to a Confluence page, without copy and paste.
  • Strong audit story through usage logs and admin controls.
  • Broad client compatibility. Atlassian lists a long roster of partner clients.
  • Permission-faithful. An agent cannot open a project or space its user cannot.

Cons

  • Compliance gaps. The server does not currently support FedRAMP or HIPAA requirements. Regulated buyers should stop here and check.
  • Cloud-first. The official server targets Atlassian Cloud. Teams on Server or Data Center typically look at community alternatives, which carry their own trust trade-offs.
  • Rate limits vary by plan. Site-level limits depend on your Jira and Confluence plan.
  • IP allowlists can block it. If you restrict by IP, you must add the egress IPs of your AI tools and proxies.
  • Stale-content risk. An agent will faithfully return an outdated Confluence page or a Jira ticket whose requirement changed elsewhere. The server cannot tell you which source is current.

Best for: product, engineering and IT teams on Atlassian Cloud. Skip if: you need FedRAMP or HIPAA coverage today.


4. Slack MCP Server

Short answer: the best way to give an assistant live context on what your team is actually discussing.

Slack’s official remote server lives at mcp.slack.com/mcp and reached general availability on February 17, 2026, alongside Slack’s Real-Time Search API. It lets AI clients search messages, files, members and channels, read channel and thread history, send messages, and create or read canvases. It is hosted by Slack, uses standard OAuth and inherits the authenticating user’s permissions, and a workspace admin must approve the integration. Connecting is free, since you are authorizing an AI client against your own account.

Slack’s server replaced a long-running ecosystem of community projects and Anthropic’s original reference server from November 2024. Community servers still exist, but the official one is the safer baseline for business use.

Pros

  • Official and admin-gated. IT controls who connects what.
  • Context nobody else has. Decisions, objections and half-finished plans live in threads, not in tickets.
  • Two-way. Assistants can summarize a channel and then post the summary.
  • Wide client support. Slack points to a large partner list of AI clients.

Cons

  • Exposure by design. Any MCP server that reads Slack surfaces whatever the connected account can see, including sensitive messages and files. Many enterprises add a data-loss-prevention layer on top.
  • Plan and contract questions. Verify plan availability and any separate contracts for partner AI clients before an org-wide rollout.
  • Noise. Chat is unstructured. Summaries are only as good as the conversation.
  • Prompt-injection surface. Messages written by others are untrusted input to your assistant. Treat them that way.

Best for: any team where decisions happen in channels. Skip if: you cannot get admin approval or lack DLP controls for sensitive channels.


5. Notion MCP Server

Short answer: the cleanest way to put your wiki, specs and project trackers in front of an assistant.

Notion runs an official hosted server at mcp.notion.com/mcp (with a legacy SSE endpoint for older clients). Authentication is browser-based OAuth, you choose which pages to share, and there is nothing to deploy. Tools return Notion-flavored Markdown designed for agents rather than raw block JSON. Notion states that this hosted server is its actively maintained path and that the older open-source server is no longer actively maintained. One third-party count puts the hosted server at 18 tools covering search, fetch, page creation and updates, database creation, views, queries, comments and user lookups.

Pros

  • Frictionless setup. One command or one connector click, then OAuth.
  • Scoped access. You pick what is shared.
  • Agent-friendly output. Markdown keeps token use reasonable.
  • Free to connect on any Notion plan, subject to standard API rate limits.

Cons

  • OAuth only. The hosted server requires user-based OAuth and does not support bearer tokens, which makes fully headless or background agents awkward.
  • Cross-tool search needs Notion AI. Searching connected tools such as Slack or Google Drive through Notion requires Notion AI.
  • Stale-doc trap. Agents read an out-of-date spec as confidently as a current one.
  • Token cost. Large pages and verbose tool descriptions can burn context quickly.

Best for: teams whose knowledge base and planning live in Notion. Skip if: you need unattended agents with static credentials.


6. Zapier MCP

Short answer: the universal adapter for apps that have no native MCP server.

Zapier’s documentation describes a connection to more than 9,000 apps and 40,000 or more actions. (Some older third-party listings still say 30,000+. We use the figure from Zapier’s current docs.) A Zapier MCP connection links one AI client to one server on your Zapier account, and each call runs through your existing Zapier app connections. Zapier holds the app credentials, so the client never touches a third-party API key. After OAuth, Zapier can auto-provision actions for the apps you have already connected, and actions are logged in the History tab. Each client gets its own server, and a server has no limit on actions or tool calls beyond your plan’s task allowance.

Pros

  • Unmatched breadth. If an app exists, Zapier probably connects to it.
  • Credential isolation. The assistant never sees your third-party keys.
  • Fast to start. Auto-provisioning from connected apps.
  • Revocable. You can cut a connection from the client or from mcp.zapier.com.

Cons

  • Metered cost. Each successful tool call uses two tasks from your plan. Heavy agent loops get expensive fast.
  • Transport limit. Zapier MCP supports Streamable HTTP only. A client that can only use SSE cannot connect.
  • Mixed status signals. The zapier.com/mcp page badges it as beta while the pricing page lists it as a plan feature without a beta marker. Ask your account contact which applies to your contract.
  • A middleman in the data path. Convenience means another vendor sits between your assistant and your apps.

Best for: operations teams stitching together long-tail SaaS. Skip if: a native server already covers the app, since native servers are usually richer and cheaper.


7. Stripe MCP Server

Short answer: the right way to let an assistant look up customers, subscriptions and payments, as long as you control the scopes.

Stripe hosts a Streamable HTTP MCP server at mcp.stripe.com, using OAuth Dynamic Client Registration to connect MCP clients per the MCP specification. OAuth connections are managed through a Stripe App in the Dashboard, where admins can view connected clients and revoke access. Unusually among hosted servers, Stripe also documents passing an API key as a bearer token for agentic software, and strongly recommends restricted keys that grant only the functionality the agent needs. A local @stripe/mcp package is also available.

Pros

  • Two supported auth paths. OAuth for interactive use, restricted keys for headless agents.
  • Dashboard-level control. See and revoke connected clients.
  • Good fit for support and finance workflows. Customer lookup, payment intents, subscriptions and disputes.

Cons

  • Money is on the line. If your OAuth grant or key has write permissions for refunds and the server supports it, an assistant can initiate refunds. Scope tightly.
  • Client allow-listing. Stripe maintains a list of approved MCP clients, and others must request allow-listing.
  • We found no first-party GA date. Treat maturity claims from third parties with care.
  • Key hygiene. A secret key (sk_live_) grants full access. Use restricted keys (rk_live_) instead.

Best for: finance, support and RevOps teams on Stripe. Skip if: you cannot enforce restricted keys and human approval on write actions.


8. Basis Desk MCP Server

Short answer: a free, no-key, read-only feed of source-checked crypto news and market data. It is a niche pick, but a useful one if your business touches digital assets.

Not every business-relevant data source sits inside your own systems. Exchanges, fintechs, payment processors, treasury teams and compliance functions often need an outside view of crypto markets and regulation. Basis Desk exposes its newsroom as a remote MCP server at basisdesk.news/mcp over Streamable HTTP, and says it is also listed in the official MCP Registry as news.basisdesk/mcp.

What the tools do (per the project’s own documentation):

  • search_news: full-text search over stories checked against primary sources such as SEC and CFTC filings, court records and company or protocol releases
  • latest_news: newest stories, filterable by category (bitcoin, ethereum, defi, regulation, institutions, security and more)
  • get_article: one story as Markdown with key points and numbered source links, designed for citation
  • market_snapshot: prices refreshed every minute, with 1h, 24h and 7d change, market cap, dominance, Fear and Greed index, ETH gas and BTC fees
  • whale_transfers: large ETH and stablecoin transfers (at or above $5M) and BTC transfers (at or above 100 BTC) from its own chain scanner, with exchange labels
  • token_safety: contract risk signals such as honeypot behavior, taxes, mint, pause and blacklist powers, and proxies, sourced from GoPlus Security
  • daily_brief: the five to seven stories that mattered that day

All tools are annotated as read-only. The server runs as a stateless JSON-RPC handler on Cloudflare Workers, and the project also publishes an OpenAPI spec for plain JSON endpoints, a server card and an llms.txt file. Setup is a single URL in any client that supports remote MCP servers, or a bridge through mcp-remote for stdio-only clients.

How the content is produced. Basis Desk states that an automated pipeline clusters primary-source documents, drafts stories with an LLM, then runs a grounding audit and deterministic checks (citations, n-gram overlap, banned phrases) before publishing. Stories carry source links so a human or an agent can verify them.

Pros

  • Free and keyless. No procurement, no credentials to rotate, no secrets in config.
  • Read-only by design. Nothing can be written anywhere, which sharply limits blast radius.
  • Source-linked. get_article returns numbered sources, which suits compliance and research workflows that must cite.
  • Useful safety tooling. A token-safety check is a practical first screen before anyone on a treasury or listings team looks at an unfamiliar contract.
  • Easy to try. One URL, any major client.

Cons

  • Narrow scope. It is crypto-only. If your business has no digital-asset exposure, skip it.
  • Terms to respect. Free use, including commercial use, requires attribution (“Basis Desk” plus the article URL), and the project asks you to keep requests to a few per second.
  • Not investment advice, and data can be delayed. Do not wire trading or treasury decisions directly to its output.

Best for: compliance, research and treasury teams with crypto exposure that want a free, citable feed in their assistant. Skip if: you need audited data, SLAs or anything beyond news and market context.


9. Snowflake-Managed MCP Server

Short answer: the best choice when your most valuable business data already sits in Snowflake and you need governed, auditable access for agents.

Snowflake’s managed MCP server went generally available on November 4, 2025, after a preview. It lets AI agents retrieve data from Snowflake accounts without separate infrastructure. You create an MCP server object in SQL (CREATE MCP SERVER) and configure which tools it serves: Cortex Analyst, Cortex Search and Cortex Agents, plus custom tools and SQL execution. It supports OAuth 2.0 and role-based access control over both the server and its tools. On August 7, 2026, Snowflake also made Cortex Agents and MCP servers inside Snowflake Native Apps generally available, so app providers can expose their own search services, semantic views, procedures and UDFs as MCP tools.

Pros

  • Governance inherited from the warehouse. RBAC applies to discovery and invocation.
  • No servers to run. Snowflake manages the infrastructure.
  • Good fit for “ask the data” use cases. Text-to-SQL, semantic search and agent orchestration behind one interface.
  • Ecosystem direction. Native Apps can now ship MCP servers of their own.

Cons

  • No dynamic client registration. Some clients need manual OAuth configuration.
  • Tools only. The server currently supports tool capabilities, not the other MCP primitives.
  • Runaway loops and cost. Snowflake itself warns that an external client calling an agent tool that invokes another MCP server can produce expensive, unbounded loops. Put limits in place.
  • Requires a Snowflake investment. The value depends on how much of your data and semantic modeling already lives there.

Best for: data and analytics teams on Snowflake. Skip if: your analytics stack is elsewhere.


10. Google Workspace MCP Server

Short answer: potentially the most widely useful server on this list, but it is not GA yet, so treat it as a pilot.

At Cloud Next '26, Google announced a suite of agent tools for Workspace, including a Workspace MCP server, a command-line interface and remote MCP integrations. On May 1, 2026, it opened the Workspace MCP server to public developer preview. The tools cover Gmail (profile access, drafting, searching, read and write), Drive (fetching, permissions management, listing, uploading), Calendar (finding availability, managing events), Chat (finding conversations, searching, reading and sending replies) and People (contacts and profile information). Google said the rollout would be gradual and that updated API and MCP usage quotas would apply to new projects only.

Pros

  • Reach. Email, files, calendar and chat are where most knowledge work happens.
  • First-party direction. Google is investing in an official path rather than leaving it to the community.
  • Granular tool groups for Gmail, Drive, Calendar, Chat and People.

Cons

  • Preview, not GA. Features, quotas and terms can change. We could not confirm a GA announcement as of this writing, so check Google’s current documentation.
  • Quota tiering. New projects face updated usage quotas.
  • Community alternatives are tempting but riskier. Several third-party Workspace servers exist, with varied maintenance and security postures. Review any you consider the way you would any code that touches your inbox.
  • High-sensitivity data. Email and Drive contain contracts, HR matters and credentials. The blast radius of a mistake is large.

Best for: teams on Google Workspace that can run a controlled pilot. Skip if: you need a GA support commitment today.


Which MCP server should you choose? A decision framework

If your biggest pain is… Start with Then add
Pipeline visibility and CRM hygiene Salesforce or HubSpot Slack
Planning, tickets and documentation Atlassian Rovo Notion or Slack
Team knowledge scattered across tools Notion Slack
Apps with no native server Zapier Whichever native server fits
Billing and payment questions Stripe HubSpot or Salesforce
Crypto market and regulatory awareness Basis Desk Slack (to share findings)
Governed analytics Snowflake Notion (for definitions and docs)
Email, files and meetings Google Workspace (pilot) Slack

A practical rule: most teams get most of the value from three to five servers. For a typical software company, that is the CRM, the billing platform, the data store and the issue tracker. Add more only when a specific workflow demands it.

The security playbook for business MCP

Choosing the right server is half the job. The other half is deploying it safely.

  1. Prefer official, hosted, OAuth-based servers. They inherit user permissions, can be revoked centrally and are maintained by the vendor. Treat unverified community servers as untrusted code.
  2. Start read-only. Grant write scopes only after you have seen how the assistant behaves with read access.
  3. Use restricted credentials. Where API keys are unavoidable (Stripe, for example), use restricted keys scoped to the minimum.
  4. Require human approval for irreversible actions. Refunds, deletions, outbound messages and bulk updates should pause for a person.
  5. Log everything. Use vendor usage logs (Atlassian), history views (Zapier), dashboards (Stripe) and your own gateway where you have one.
  6. Treat retrieved content as untrusted. Slack messages, Confluence pages, emails and web content can contain instructions aimed at your assistant. Design workflows so that retrieved text cannot trigger sensitive actions without confirmation.
  7. Mind data-loss prevention. If a server can read it, an assistant can repeat it. Add DLP for sensitive channels and drives.
  8. Check compliance fit early. FedRAMP, HIPAA and sensitive-data modes can rule a server in or out before you invest time.
  9. Watch for loops and cost. Metered tools (Zapier tasks, Snowflake compute) can balloon when agents call each other.
  10. Review quarterly. This ecosystem moves fast. Servers move from beta to GA, scopes change and documentation gets corrected, as HubSpot’s changelog fix showed.

Common mistakes to avoid

  • Connecting everything at once. More servers mean more tools in the model’s context and more ways to go wrong. Start narrow.
  • Trusting old listicles. Several widely shared lists predate the 2026 GA releases and describe beta behavior, retired URL patterns or superseded servers.
  • Confusing similar names. HubSpot’s remote CRM server and its Developer MCP server are different products. Salesforce has at least four things called “MCP.”
  • Ignoring plan requirements. Edition and plan gates (Salesforce Enterprise, certain HubSpot features, Zapier task limits) decide whether a pilot is even possible.
  • Skipping the human in the loop for money, customer communications and compliance decisions.

Frequently asked questions

What is the best MCP server for business overall? There is no single best, because the right server depends on where your work lives. For CRM, Salesforce and HubSpot lead. For planning and docs, Atlassian Rovo and Notion. For breadth across apps, Zapier.

Are MCP servers safe for business use? Official, OAuth-based servers that inherit user permissions are a reasonable foundation, provided you add scoping, logging and approvals. The protocol itself does not make a deployment safe. Your configuration does.

What is the difference between a hosted and a local MCP server? A hosted (remote) server runs on the vendor’s infrastructure and you connect by URL, usually with OAuth. A local server runs on your machine or network, typically started by a command, and often uses tokens you manage yourself. Hosted servers are easier to govern. Local servers give you more control and sometimes cover cases hosted servers do not.

Do I need developers to set up MCP servers? For most hosted servers on this list, no. Setup is usually a connector click and an OAuth sign-in, plus an admin approval step. Custom servers (for example, wrapping Salesforce flows or Snowflake objects) do take technical effort.

Which MCP servers are free? Connecting to Slack and Notion is free, subject to your plan and standard rate limits. Basis Desk is free with attribution. Zapier MCP has no separate price but consumes your plan’s tasks. Salesforce hosted servers require Enterprise Edition or above. HubSpot access depends on your account, plan and the scopes you grant.

Which clients work with these servers? Most support Claude, ChatGPT, Cursor and other MCP-compatible clients. Details differ: Zapier needs a client that supports Streamable HTTP, and Stripe maintains an approved-client list.

Can an MCP server make changes in my systems? Yes, if it exposes write tools and you grant the scopes. HubSpot, Salesforce, Atlassian, Slack, Notion, Zapier and Stripe all offer some form of write access. Basis Desk is read-only by design.

How often should I re-evaluate my MCP setup? Quarterly at minimum. GA dates, scopes, quotas and security guidance have all changed during 2026.

How we verified this article

We checked each server against first-party sources: Salesforce’s developer blog, HubSpot’s developer changelog and documentation, Atlassian’s announcement and product pages, Slack’s developer documentation, Notion’s developer docs, Zapier’s documentation, Stripe’s documentation, Snowflake’s release notes and documentation, Google’s Workspace Updates blog and Basis Desk’s published developer materials. Where a figure came only from a third-party source (Notion’s tool count, the exact Atlassian and Slack GA dates), we say so. Where sources disagreed (Zapier’s action count, its beta labeling), we explain which we used and why. Pricing, quotas and statuses change often, so confirm current terms with each vendor before you commit.