AI Guides › Playbooks

The Three-Door Check for Connecting Claude to Outside Tools

By Nigel Guy · 7 min read

Most people who want Claude to read their calendar, files or CRM search for "MCP server for X", paste the first URL or install command they find, and click through the sign-in. It feels fine because the tool works within a minute. What you have done is hand a stranger's code a route into your accounts, with no record of why you trusted it.

Claude already has a catalogue of connectors, and it is the sensible first stop. But it is not a list of "pre-approved" tools in the sense most people assume, and that gap is where the trap sits.

The rule: look for the connector in the directory first, read its label, and only go to a custom URL or command when the directory has nothing, treating each step down as a step up in how much you must check yourself.

What the directory actually is

The Connectors Directory is one catalogue of MCP servers (Model Context Protocol, the standard that lets Claude talk to outside tools) that serves claude.ai, Claude Desktop, mobile, Claude Code and Cowork. Anthropic's documentation says it holds two kinds of listing, and that "verification isn't a security audit". Listings are also subject to Anthropic's Software Directory Policy.

So the honest description is "screened and labelled", not "approved and safe".

The Three-Door Check

Door What it is What Anthropic has done What you must still do
1. Verified Directory listing with a checkmark Tested the tools for quality and compatibility; met the directory policy at time of review Read the permissions at sign-in; remember the developer can change tools later
2. Community Directory listing with a "Community" label Screened before listing, not reviewed in depth; Claude shows a reminder before you connect Decide whether you trust the developer; check what the tools can do
3. Custom A URL or command you add yourself Nothing All of it: who runs it, what it can read and write, where your data goes

Work down from Door 1. Stop at the first door that has the tool.

Step 1: Search the directory

In claude.ai, open Customize > Connectors. That is the browse-and-add surface, and it is the same catalogue Claude Code draws on. Search for the product by name.

On a Team or Enterprise plan, an Owner adds the connector for the organisation in Organization settings > Connectors, and each member then connects with their own account. On a Team plan, if you are not allowed to enable connectors you will see a Request button instead; it goes to your Owners. Do not work around that by adding a custom connector yourself.

Step 2: Read the label

A checkmark means Verified. A "Community" label means a third party built it and Anthropic has not reviewed it in depth. In both cases, once connected, the connector has the access you grant, regardless of label. The label changes how much review it got, not how much it can do.

Step 3: Read the sign-in screen

When you authenticate, the service shows the permission scopes it wants. Anthropic's advice is to review them carefully. If a connector for reading your calendar asks to delete things, stop and ask why.

Step 4: Go to Door 3 only if the directory has nothing

A custom connector is a remote server added by URL. Availability, at time of writing: Free, Pro, Max, Team and Enterprise plans, with Free limited to one custom connector. On Pro or Max, use Add custom connector at the bottom of the Connectors section. On Team and Enterprise, an Owner uses Add, then Custom, then Web, enters the server URL, and optionally opens Advanced settings for an OAuth client ID and secret.

In Claude Code the equivalent is the command line:

claude mcp add --transport http <name> <url>
claude mcp add --transport stdio <name> -- <command> [args...]
claude mcp list

Then run /mcp inside Claude Code to see status and sign in. Scope matters: local (the default) is private to you in the current project, project writes a shared .mcp.json your team will load, and user applies across all your projects. A stdio server runs as a process on your own machine, so it deserves more suspicion than a remote one, not less. If you are signed in to Claude Code with a claude.ai account, the connectors you set up at claude.ai are available there automatically.

Step 5: Record the decision

Keep a one-line ledger entry per connector: name, door, who built it, scopes granted, date. It takes a minute and is the only way you will remember in three months why something has access to your drive.

Worked example

Hypothetical scenario: you run a small design studio and want Claude to draft replies from your project-management tool. You search Customize > Connectors and find the tool listed with a checkmark. Door 1. You connect, and the sign-in asks for read and write on tasks and comments. You only want drafts, so you note that write access is broader than needed. If the tool offers a read-only option, you pick it; if not, you accept the write scope knowingly and keep Claude's actions in manual-approval mode. Ledger entry: "PM tool, Door 1, vendor-built, read/write tasks, 2026-10-04."

Had it been a Community listing from an individual developer, you would check who they are and whether the tool has a maintained public repository before connecting. Had it been absent from the directory, you would ask whether the vendor publishes its own official remote MCP URL, and use that rather than a third-party wrapper.

A prompt for vetting a Door 3 server

Paste this into a fresh chat, with the server's documentation or README attached.

You are a cautious technical reviewer helping a non-specialist decide whether to connect an MCP server to Claude.

Context: I want to connect [SERVER_NAME_OR_URL] so that Claude can [WHAT_I_WANT_IT_TO_DO]. I will connect it through [CLAUDE_AI_CUSTOM_CONNECTOR / CLAUDE_CODE_CLI]. The data it could touch is [DATA_TYPES_AND_SENSITIVITY].

Using only the documentation I have attached, work through these steps:
1. List the tools the server exposes and mark each as read-only or able to change things.
2. State who publishes it and whether the documentation says who operates the server.
3. List the permissions or scopes it requests and say which, if any, exceed my stated purpose.
4. Say where my data goes, if the documentation says.
5. Flag anything the documentation does not say.

Output a table (tool, read or write, needed for my purpose: yes or no), then a verdict of Connect, Connect with reduced permissions, or Do not connect, with three sentences of reasoning.

Rules: do not guess. If a fact is missing, write "not stated". Ask me for any missing input above before starting. Before answering, check that every claim in your verdict traces to the attached text.

Fill in the server, your purpose, the connection method and the data involved.

What to skip

Guardrails

Sources

All 751 AI guides · JulieMango plans from £17/mo