How to Connect Claude or ChatGPT to Your CRM (and When You Need a Custom MCP Server)


Quick answer: start with your CRM's official connector if it has one. HubSpot, Salesforce, Pipedrive and HighLevel all publish MCP servers, and Keap has a Thryv-built connector for Claude that is still in beta. Those cover most "ask my CRM a question" and "update this record" jobs. Build a custom MCP server when you need tighter permissions than the official option allows, a log of what the AI changed, data from more than one system in the same conversation, or a CRM that has no connector at all.

What is MCP, in one paragraph?

The Model Context Protocol is an open standard for connecting AI assistants to outside tools and data. Anthropic released it in November 2024, and in December 2025 it moved under the Linux Foundation's new Agentic AI Foundation, which Anthropic co-founded with Block and OpenAI. An MCP server sits between the AI and one of your systems and exposes a defined set of tools, such as "search contacts" or "add a note," and nothing else. Claude calls these connectors. In ChatGPT, custom MCP servers are added as apps through developer mode on the web, with full read-and-write support in beta on Business, Enterprise and Edu plans. The point is that one integration works across AI tools instead of being rebuilt for each.

Which CRMs have official AI connectors?

CRMOfficial option (September 2026)Worth knowing
HubSpotRemote MCP server, generally available to all accounts since April 13, 2026, plus connectors for ChatGPT and ClaudeReads most CRM objects; creates and updates contacts, companies, deals, tickets and activities
SalesforceHosted MCP servers, generally available since April 29, 2026Enterprise Edition and above
PipedriveNative MCP server, launched June 30, 2026All Pipedrive plans; search, create and update records
HighLevelMCP serverConnects with a private integration token; OAuth is planned
KeapThryv-published connector for Claude, in betaPaid Claude plans only; can't delete records or create automations; no official ChatGPT app

What the official connectors do well

  • Answering questions across your records, such as which deals over $10,000 haven't moved in 30 days.
  • Updating records from a conversation: logging a call summary as a note, creating a follow-up task, moving a deal stage.
  • Drafting from real data, like a follow-up email that knows what the customer bought.

They typically come with the CRM and AI plans you already pay for, and the vendor maintains them as its API changes. For many small teams, that's enough.

Where they fall short

  • Permissions are broad. A connector generally acts with the permissions of the person who connected it. If that person is an admin, the AI can do whatever an admin can within the connector's tools.
  • One system at a time. Real questions cross systems: the CRM, the payment processor, the scheduling tool, the spreadsheet the office manager keeps. Several connectors can work in one conversation, but each adds its own set of permissions to reason about.
  • Your setup isn't in the tool list. Custom objects, unusual field conventions and "the way we do it here" rules are invisible to a generic connector.
  • Thin audit trail. Knowing exactly what the AI changed, when, and at whose request matters the moment it's allowed to write.

When a custom MCP server makes sense

A custom server exposes only the tools your business needs, written around your data and your rules. It's worth building when:

  • You want narrow, specific tools, such as "log a service call for this customer," rather than general write access to every record.
  • One assistant needs to work across several systems with consistent rules.
  • Every tool call has to be logged for review.
  • Your CRM has no official connector, or the official one doesn't cover what you use.
  • You want the same tools available in Claude, ChatGPT and whatever comes next, without rebuilding for each.

That's the work behind our MCP servers and API development service, where the pricing is published. For Keap specifically, if an older integration is part of the picture, read what Keap's XML-RPC retirement means first, because a new AI layer shouldn't sit on top of an API that's losing support.

The security part nobody should skip

Connecting an AI to a system it can write to creates new ways for things to go wrong, and the MCP specification is candid that the protocol can't enforce safety on its own. Each risk below has a published incident or proof of concept behind it.

  • Prompt injection. Text the AI reads, such as an email, a support ticket or a web page, can carry instructions. In a 2025 demonstration, researchers showed that a malicious public GitHub issue could steer an agent using GitHub's MCP server into leaking data from private repositories.
  • Too much access. OWASP's top risks for LLM applications include excessive agency: an AI holding more permission than its job requires.
  • Untrusted servers. In September 2025 a fake MCP package impersonating Postmark quietly copied its users' outgoing email to an attacker.
  • Vendor bugs. In June 2025 Asana disclosed a flaw in its MCP feature that exposed some customers' data to other organizations.

The practical rules follow from those: give the AI the narrowest tools that do the job, require a person to approve anything destructive, log every call, install servers only from sources you trust, and add write access only after you've watched it work read-only. The MCP specification itself says there should always be a human in the loop with the ability to deny tool calls.

If you're deciding whether any of this is worth it, start with a narrower question: which three questions do you ask your CRM every week that take more than five minutes to answer? That list is usually the whole business case, or the reason to wait. And if the answer is a report rather than a conversation, you may not need AI at all; we covered that in AI or Just Automation?

Frequently Asked Questions

Can ChatGPT connect to HubSpot?

Yes. HubSpot publishes an official connector for ChatGPT, and its remote MCP server, generally available to all HubSpot accounts since April 13, 2026, can read CRM records and create or update contacts, companies, deals, tickets and activities.

Can Claude connect to Keap?

Yes. Thryv, which owns Keap, publishes a Keap connector in Claude's connector directory. As of September 2026 it is in beta, requires a paid Claude plan (Pro, Max, Team or Enterprise), can read and update most records, and can't delete records or create new automations.

What is an MCP server?

An MCP server is a small service that exposes a defined set of tools from one of your systems, such as searching contacts or adding a note, to AI assistants that support the Model Context Protocol, including Claude and ChatGPT. The AI can use only the tools the server offers.

Is it safe to give AI write access to my CRM?

It can be, with limits. Use the narrowest tools that do the job, require human approval for anything destructive, log every action, and start with read-only access. Prompt injection, where text the AI reads contains hidden instructions, is the risk that matters most once an AI can write.

Do I need a developer to connect AI to my CRM?

Not for the official connectors; an admin can usually enable those in a few minutes. You need a developer for a custom MCP server, for a CRM without a connector, or when you want permissions and logging the official option doesn't provide.

Want AI working on your real business data?

We'll tell you whether an official connector covers it or a custom MCP server is worth building, and what it would take either way.

Book a 15-minute call →

Have a project in mind?

15-minute call. No sales pitch. We'll tell you straight what's worth building.

Book the call →