claude/for
Search
Subscribe
Work & Tools

Claude connectors: what they are and how to use them

A Claude connector links Claude to an app like Gmail or Slack so it can read and act there. Here's how they work, what's free, and the security model.

A Claude connector links Claude to an outside app or service, Gmail, Slack, Notion, Linear, so it can search, read, and sometimes act inside that service instead of just talking about it. Connectors ship on every plan now, from Free through Enterprise, and Claude can only reach what you could already see or do yourself in that app.

A connector: click to authenticate, then Claude can search and act inside that app
A connector: click to authenticate, then Claude can search and act inside that app

What a connector actually does

Per Anthropic's own Help Center, a connector lets Claude "access your apps and services, retrieve your data, and take actions within connected services," working the same way across Claude.ai, Claude Desktop, Claude Code, and the API.

There are two flavors. Standard connectors are pre-built and listed in Anthropic's Connectors Directory, reviewed before they go live, available to everyone. Custom connectors point Claude at a remote MCP server URL of your own choosing, a service Anthropic hasn't reviewed. Same mechanism, different trust level.

Connector vs. MCP: the part people mix up

MCP, the Model Context Protocol, is the open standard underneath all of this. Anthropic announced MCP in November 2024 as a way to build "secure, two-way connections between data sources and AI-powered tools," and it's since spread well past Claude: ChatGPT, Cursor, Gemini, Microsoft Copilot, and VS Code all support it now. In December 2025, Anthropic donated MCP's governance to a new Linux Foundation body, the Agentic AI Foundation, co-founded with Block and OpenAI, reporting "over 97 million monthly SDK downloads" and "10,000 active" public servers at the time.

A connector is Anthropic's product wrapper around that protocol: click to authenticate, no configuration, no server address to type in. MCP is the plumbing any AI tool-builder can use; a connector is what you actually click. Directory connectors are Anthropic-reviewed implementations of MCP servers. Custom connectors let you skip the review and point at any MCP server URL directly, which is exactly where the security section below applies.

Notable connectors, first-party and directory

Google Workspace and Microsoft 365 are Anthropic's own, with dedicated setup docs separate from the general directory. Google Workspace covers Gmail (search, read, draft, but not send), Google Calendar (view, create, modify events), and Google Drive (search, read, upload, create folders), available to all users on Claude and Claude Desktop per Anthropic's current documentation. Microsoft 365 covers SharePoint, OneDrive, Outlook mail and calendar, and Teams. Read/search tools are available as before; since July 7, 2026, an admin can also enable write tools for email, calendar, mailbox settings, OneDrive, and SharePoint. Teams remains read-only.

The third-party Connectors Directory launched in July 2025 with Notion, Canva, Stripe, Figma, Socket, and Prisma as founding partners. Anthropic's last published count, in April 2026, was "over 200 connectors," naming Linear, Slack, Spotify, Uber, Instacart, and Booking.com among others. Larger numbers from third-party trackers disagree with one another, so "200+ as of April 2026" is the defensible figure—not an estimate of today's exact total.

What's free, and how to add one

Every plan gets connectors. The gate is on custom ones: Free-plan users are capped at one custom (remote MCP) connector, per the Help Center article on custom connectors. Pro, Max, Team, and Enterprise aren't stated to carry that cap. Standard directory connectors are open to every plan regardless, a change from the July 2025 launch, when remote third-party connectors were paid-only. On Team and Enterprise, only an Owner can enable a connector org-wide; individual members then authenticate themselves, and Owners can restrict scopes, disable specific actions, or limit connections to approved domains.

now

Open the Connectors Directory

Use Customize → Connectors, or open the + / slash menu inside a chat and choose Manage connectors.

now

Click Connect and authenticate

You'll go through that service's normal OAuth login. Claude never sees your password.

now

Review and grant the requested scope

The permission prompt shows exactly what Claude can read or do. Read it before accepting, especially for anything with write access.

next

Adding a custom connector instead

Pro/Max: Customize → Connectors → + → Add custom connector. Team/Enterprise Owners add Custom → Web under Organization settings. Paste the remote MCP URL and configure OAuth only if needed.

The security model

Many hosted connectors use OAuth, so Claude authenticates through the service's login flow without seeing your password. Custom and local MCP servers can use other authentication methods or none, so review each connector's setup. The part worth internalizing in every case: Claude inherits the permissions granted by the connected service. If someone cannot access a file, channel, or record in the source system, the connector cannot reach it from Claude either.

That's a real ceiling, not marketing language, but it isn't the whole picture. A connector granted write scope can genuinely take actions on your behalf, sending a Slack message, filing a Linear issue, so the scope prompt at authorization time is the moment that matters, not something to click through.

Directory connectors go through an Anthropic review before listing: tool design, authentication, privacy, allowed external links, documentation, and how the connector behaves when every tool gets called. Custom connectors skip that review entirely, which is why Anthropic's own guidance is blunt about it.

Only connect custom MCP servers you actually trust. Anthropic's guidance: connect only to servers from organizations you trust, review the permission scopes at authorization, and watch for prompt injection or unexpected tool behavior. Unlike directory connectors, nobody has reviewed the other end. You can revoke access at any time from Settings.

This site isn't run by Anthropic. We're an independent guide to using Claude well, and where the official numbers conflict, like the directory's exact connector count, we cite Anthropic's own figure rather than repeating whichever third-party total sounds biggest.

Are Claude connectors free?

Yes, connectors are available on every Claude plan including Free. Free accounts are capped at one custom remote connector; higher plans are not stated to carry that cap. Claude does not add a separate connector line item, but a connected service or third-party provider may still require its own paid account.

What is the difference between a connector and MCP?

MCP is the open protocol, the actual technical standard for connecting an AI system to outside data and tools. A connector is Anthropic's product layer on top of it: a listing you click to authenticate, with no server URL or configuration required. Every connector is built on MCP, but not every MCP server is a listed connector, custom connectors let you point at one directly.

Are Claude connectors safe?

Standard directory connectors go through an Anthropic review before listing, covering tool design, authentication, and privacy. Custom connectors don't get that review, so Anthropic's own advice is to only add ones from sources you trust. In both cases, Claude can only reach what you could already access in that service, it can't escalate beyond your existing permissions.

Do I need Claude Code to use connectors?

No. Web connectors are available in Claude, Cowork, Claude Desktop, and mobile; Claude Code and API clients use the MCP connector path. If you're setting up Claude for the first time, how to use Claude walks through your first session, and Claude Projects and Claude Skills cover the other two pieces people mix up with connectors. For the wider set of write-ups, browse more reviews.

If you are deciding between a connector, a direct API call, and a command-line tool, use the API vs MCP vs CLI decision guide before adding another integration.

One Claude move in your inbox, every Sunday

Four minutes, tested on a real job, then back to your weekend. Free.