MCP server development: let Claude and ChatGPT work with your systems on your terms
Your team already asks AI assistants for help, but the assistant can’t see your CRM, your calendar or your orders, so people paste Excel exports into the chat. We build an MCP server that gives Claude, ChatGPT and other AI clients narrow, logged access to your systems: they read only what the user is allowed to see, and change nothing without confirmation.
- Built in Netanya, maintained after launch
- Read-only by default, changes only after confirmation
- Tested in the AI clients your team actually uses
What is an MCP server, and what do we build?
An MCP server is a connector built on the Model Context Protocol, an open standard that lets AI assistants such as Claude and ChatGPT use the tools and data of other systems. We build MCP servers for Israeli businesses and software companies: your CRM, booking system, database or SaaS product becomes a set of narrow tools, with OAuth sign-in, read-only access by default, confirmation before any change and a log of every call.
Why companies start asking about MCP
Customer lists are already being pasted into chat windows
Someone exports last month’s orders to Excel and uploads the file to a personal ChatGPT account, “just for a quick summary”. You don’t know which data has left the company, and by tomorrow the answer is based on a stale file anyway.
Your customers ask whether your product works with Claude
If you run a SaaS product, the question is starting to come up in sales calls and support tickets. Without a connector, customers copy data out of your product into their AI tool, and your product becomes the place they export from, not the place they work in.
One integration per AI tool doesn’t scale
A custom action for ChatGPT, a separate plugin for another assistant, a script for the developers’ code editor: each one describes the same API differently and breaks on its own schedule. With MCP, one server works with every AI app that supports the standard.
The only key you have is an admin key
Your system’s API has one all-powerful token. Handing it to an AI assistant means it can read every customer record and, in theory, delete it too. Nobody signs off on that, so the AI stays disconnected.
How we build an MCP server
Start from questions, not endpoints
We collect the questions and actions your team or your customers actually need: “who hasn’t paid this month?”, “what’s free on Thursday?”, “open a follow-up task”. If your system already offers an official MCP server that covers them, we’ll tell you and help you set that up instead.
Design narrow tools
Each question becomes a tool with a clear name, description and inputs, returning only the fields the answer needs. Every tool is marked as read or write, and we agree together which write actions should exist at all.
Set up access
Users sign in with OAuth using their own accounts, and the server enforces the permissions they already have in your system. Scopes, rate limits and the audit log are part of the first version, not a later add-on.
Build and deploy
A remote MCP server on your cloud or ours, connected to your API or database through a dedicated account with the minimum rights. Secrets stay on the server.
Test in real AI clients
We try every tool in Claude, ChatGPT and the other AI clients your team uses, with real questions in Hebrew, English and Russian, including vague ones, typos and requests the server should refuse.
Launch and maintain
Your team gets a short guide to connecting the server. We watch the logs, sharpen tool descriptions wherever the AI picks the wrong tool, and keep up with changes in the protocol and in the AI clients.
What you get
- A tool map: every tool, what it reads or changes, and who is allowed to use it
- A remote MCP server with its source code, deployed on your cloud or ours
- OAuth sign-in, scopes and per-user permissions that mirror your system’s
- A confirmation step for every write action, and no tool at all for actions that should stay manual
- An audit log of every call, plus rate limits and alerts
- Testing in the AI clients you use, and a connection guide for your team or your customers
- Support after launch as the protocol and the AI clients change
What an MCP server looks like in practice
An Israeli SaaS adds “Connect to Claude and ChatGPT”
A company selling management software to studios and gyms wants its customers to ask their own AI assistant about their schedule and revenue. We build a public MCP server with OAuth: each customer signs in with their existing account and sees only their own business’s data. Write tools stay off until the product team decides otherwise.
A distributor stops exporting to Excel for every question
The owner of an import and distribution business wants to ask “which customers ordered less this quarter than last?” without waiting for a report. Read-only tools over the orders database answer from live data, and the owner can ask in English even though most customer names are stored in Hebrew.
An office manager books meetings from the AI assistant
At a law or accounting firm, the assistant checks free slots in the calendar and the client’s file in the CRM, then suggests a time. Holding the slot is a write action, so the user sees exactly what will be created and confirms it before anything changes.
Developers give their coding assistant the right context
A product team connects Claude Code or Cursor to its internal API docs, a read-only view of the staging database and recent error logs. Developers get answers grounded in their own system, and production data stays out of reach.
How access is controlled
An MCP server is only as safe as its design, so we design access first and add tools second. The rules live in the server itself, not in a prompt that the AI could misread or that someone could try to talk it out of.
- OAuth sign-in: every user connects with their own account, and no shared master key sits inside an AI client
- Scopes and least privilege: each tool gets only the rights its job needs, and a user never sees more through the AI than they see in your system
- Read-only by default: write tools are added one at a time, on purpose
- Human approval for every write: the user sees the exact change before it happens, while actions such as messaging a customer, refunds or deletions stay outside the AI or need a second confirmation in your system
- Rate and size limits per user and per tool, so nobody can pull your whole customer database through a chat
- An audit log of who called which tool, when, with which inputs and what came back, with passwords and keys kept out of it
- Text from your own data, such as customer notes or emails, is treated as untrusted, because it can contain instructions aimed at the AI
- Access can be revoked for one user or for the whole server in one place
Do you actually need an MCP server?
MCP is the right tool when people already work inside an AI assistant and need it to reach your systems. For other goals there is a simpler route, and we’ll say so on the first call.
- Your SaaS tool already has an official MCP server: connect it and set the permissions, there’s nothing to build
- Two systems need to exchange data with no AI in the middle: that’s an API integration or an automation
- Customers need answers on your website or in WhatsApp: that’s a chatbot, not an MCP server
- A task should run by itself every day, without anyone asking: that’s an AI agent, which may use an MCP server under the hood
- Your team wants to question its own data, or your customers want your product inside their AI assistant: that’s where MCP fits
Tell us which system you work in (or send a link to its API docs) and five questions your team would like to ask it. We’ll reply with a draft list of MCP tools and what each one is allowed to do.
AI clients and systems we connect
- Claude
- ChatGPT
- Claude Code
- Cursor
- VS Code
- REST API
- PostgreSQL
- Firebase / Firestore
- Google Sheets
- Google Calendar
- n8n
If a system has an API, we can usually connect it. If it doesn't, we'll tell you upfront.
How a project with us runs
The same four steps, whether it's a bot, an integration or a whole system.
Short call
You tell us what's slowing you down and how you work today. We ask questions — and if a ready-made tool fits, we'll say so.
Your partDescribe the task in your own words
Written proposal
Scope, stages and a cost estimate in writing, including who owns the code, the accounts and the data.
Your partReview, ask questions, decide
Build in stages
You see working parts early and try them on real cases. Your feedback goes straight into the next stage.
Your partTest and give feedback
Launch and support
We launch, watch how it behaves in real use and stay on for fixes and improvements.
Your partUse it and tell us what to improve
What affects cost and timeline
- How many tools you need, and how many of them change data rather than just read it
- The state of your system: a documented API, a database only, or no way in yet
- Who connects: your own team, or many customers through a public server with separate accounts and data
- Which AI clients must be supported and tested
- How sensitive the data is: personal data needs a privacy review and careful logging
- Where the server runs and how much traffic it has to handle
- The level of support you want after launch
The build is a one-time cost; running it means hosting and support. The AI itself usually runs in each user’s own Claude or ChatGPT subscription, so there’s typically no per-message model fee on your side. We estimate cost and timeline in writing after a short call: call or WhatsApp us on 050-854-2579.
Ownership, privacy and accessibility
Your code and data
Ownership of the code and data is agreed in writing before we start: who owns the source code, the accounts and the information is in the agreement — not something you find out at the end.
Privacy by design
We build with Israel's Privacy Protection Law and Amendment 13 in mind: we collect only what's needed, keep secrets on the server and agree with you where the data is stored.
Accessibility built in
Interfaces built with IS 5568 and WCAG AA in mind: keyboard navigation, contrast, screen-reader labels and right-to-left layouts.
Questions about MCP servers
What is MCP, and how is it different from our regular API?
MCP, the Model Context Protocol, is an open standard for connecting AI assistants to tools and data. Your API is written for programs that already know what to call. An MCP server sits on top of it and describes a small set of tools in words a model understands, so the assistant can pick the right one for the user’s question. You usually keep both: the API for your systems, MCP for AI clients.
Which AI tools can connect to our MCP server?
Claude and ChatGPT can connect to remote MCP servers, and so can many developer tools, including Claude Code, Cursor and VS Code. Support differs by client and by plan: some offer custom connectors only on certain plans or after a workspace admin enables them, and some handle write actions differently. We check this against the tools your team actually uses before we start, and test in each of them.
What if the AI misunderstands a question or picks the wrong tool?
It happens: a model can misread a vague question or call a tool with the wrong filter. That’s why the limits live in the server, not in the model. Tools are read-only by default, every change needs the user’s confirmation, and the AI never gets more rights than the person using it. The audit log shows every call, so we can see where it went wrong and sharpen that tool’s description.
Where does our data go, and who owns the server?
The data stays in your systems. The server returns only what a tool asks for, and that answer passes through the AI provider the user works with, so we review that provider’s business terms on data retention and training with you. When personal data is involved, we design with Israel’s Privacy Protection Law and Amendment 13 in mind. Ownership of the code, the accounts and the keys is agreed in writing before we start.
Does it work with Hebrew and Russian data?
Yes, if the tools are built for it. People can ask in Hebrew, English or Russian, and current models handle all three well. The tricky part is the data: a customer saved as “כהן” won’t turn up in a search for “Cohen” unless the tool is designed for that. We build search tools with this in mind and test them on your real records, including mixed-language names and addresses, before launch.
How much does an MCP server cost, and how long does it take?
It depends mostly on the number of tools, how many of them write data, the state of your API and whether the server is for your team or for many customers. The fastest route is a first version with a few read-only tools, adding more once people use it. We keep maintaining the server after launch, because AI clients and the protocol keep changing. You get a written estimate after a short call.
Which system should your AI assistant be able to open?
Tell us on WhatsApp or in the short form which system you work in and what you’d like to ask it. We’ll tell you honestly whether MCP is the right route, or whether an existing connector or a simple integration will do the job.
Tell us which system you work in (or send a link to its API docs) and five questions your team would like to ask it. We’ll reply with a draft list of MCP tools and what each one is allowed to do.
Prefer to talk? Call050-854-2579