Why there is no key to paste
Most MCP clients take two things: a URL and a bearer token. Claude.ai and ChatGPT take only the URL. They have no token field at all — they discover how your server is protected and run an OAuth flow against it, so you approve the connection the same way you would approve any app.
That means the instruction you may have seen elsewhere — "paste your mcph_ key when prompted" — does not apply here. Nothing will prompt you. Bearer keys are for the clients that do have a token field: [Claude Code](/guides/claude-code-mcp), [Claude Desktop](/guides/connect-claude-desktop), [Cursor](/mcp-servers/cursor), VS Code and goose. See Connect Claude, GPT & Gemini for those.
Connecting in four steps
1. Claude: open Connections → Your [MCP endpoint](/guides/expose-your-business-as-an-mcp-endpoint) in the dashboard and click Connect Claude. Claude.ai opens its Add custom connector dialog with the name and URL already filled in — click Add. (If it opens empty, the "Copy the URL" link under the button gives you the URL to paste.) 2. ChatGPT: click Connect ChatGPT on the same page — it copies the URL and opens Settings → Connectors; paste the URL there. Leave every other field alone. 3. You will be sent to a BusinessMCP consent screen. Sign in if you are not already. 4. Choose what the connector may see, then approve. You land back in Claude or ChatGPT with the connector live.
There is no client id or client secret to create. Our authorization server supports dynamic client registration, so the client registers itself the first time it connects.
The consent screen
The consent screen is the part worth reading rather than clicking through. It names the client that is asking, and it lists your workspace's access policies next to full access.
Whatever you pick there binds the key that gets minted. Pick Analytics-only and that connector can read traffic, funnels and SEO, and cannot read revenue, contact emails or your CRM — even if you later ask it to. The restriction is enforced where the tools execute: disallowed tools are never advertised to the model, and any field the policy withholds comes back as [redacted]. It is not a UI setting.
This is also the honest answer to "what can this thing actually do to my business?" — the tool list an agent receives is exactly the list your policy allows, and every call is logged against the policy that governed it.
Working your LinkedIn queue from Claude
This is the one thing a connected client can DO for you rather than analyse. LinkedIn's Messaging API is partner-gated and excludes cold outreach, and Sales Navigator's SNAP API closed to new partners — so no server, ours included, can send for you. What can happen is that the agent already running in your own session reads the queue we prepared, you send each message, and it records the result.
Ask for the work-linkedin-queue prompt, or just say "work my LinkedIn queue". It calls list_linkedin_queue, which returns a work order rather than a list: the touches that are safe to do right now, in order, each with the person, their company, the exact message, the kind of step (connection note, DM, or a public comment on their post), the URL to open and how many seconds to wait before it. Then complete_linkedin_touch afterwards, which meters the touch, logs it on the CRM contact and advances the cadence.
A queue of forty can legitimately return four. LinkedIn caps invitations on a rolling seven-day window, enforces a hard monthly quota on personalized connection notes, and starts refusing invitations once too many are left pending — and a low acceptance rate is what precedes a restriction. All of that is applied before you see the batch, so the number you get is the number that is safe, not the number that is waiting. The batch carries a budget block saying what is left today, this week and this month, and a withheld list saying why anything else was not included. More capacity arrives with time, not by asking again.
Three things worth knowing. Send each message as written: it has already been through your workspace's language, tone, length and compliance rules, and rewriting it undoes them — but if you do change one, pass it back as sent_text, or your CRM will record a message that was never sent. Check anything marked `profile_verified: false` by opening the profile before you send: it means we could not confirm that profile belongs to that person. And give that connection full access — both tools read outbound message content, so a no-send key cannot see either of them and a read-only key cannot record a send. Neither failure announces itself; the tools are simply not offered.
If LinkedIn shows any warning, restriction or checkpoint, report it with outcome: 'blocked'. That stops the session and pauses LinkedIn for the workspace until a person clears it, which is the correct response to a warning and is not something we leave to an instruction.
Why we do not just send it for you. We can build the transport — it is the same budget engine either way — and we have deliberately not turned it on. Sending from our servers means a datacenter IP, a hosted session and no organic browsing between actions, under your own name and on the account you actually use. That is the profile LinkedIn restricts, and no cap protects an account it has already decided is automated. So it stays off, it is not a setting you can reach, and switching it on takes a deliberate change by us with a written record and a notification to you. If you want it anyway, ask — the honest answer is to wait until there is real acceptance data behind the pacing.
Seeing and revoking access
Each connection appears as a key in Settings → API & access, and every call it makes is logged with the policy that governed it. Revoke a key there and the connector stops working immediately — you do not need to touch anything in Claude or ChatGPT.
Because each connection gets its own key, revoking one does not disturb the others: your CLI, your Claude Desktop config and a teammate's ChatGPT connector are independent.
If it will not connect
- "Could not connect" straight away. Check the URL is the endpoint exactly as the dashboard shows it, with no trailing path. A browser visiting it directly should return a 401 — that is correct, it means the server is there and asking for auth.
- The consent screen never appears. You are probably signed out of BusinessMCP in that browser. Sign in first, then retry.
- It connects but shows no tools. The policy you approved may allow none, or the workspace plan may gate them. Tools your plan locks are still listed, and return
plan_requiredwith an upgrade link when called. - Custom connectors are missing from your settings. They need Claude Pro, Max, Team or Enterprise.
Frequently asked questions
Where do I paste my mcph_ API key?
You do not. Claude.ai and ChatGPT have no field for a bearer token — they only accept a URL and then run the OAuth flow against it. The key is minted for you when you approve the consent screen. Bearer keys are for clients that DO have a token field: Claude Code, Claude Desktop, Cursor, VS Code and goose.
Do I need a paid Claude plan?
Custom connectors are available on Claude Pro, Max, Team and Enterprise. On Team and Enterprise an owner or admin can add the connector once for the whole organisation. Adding it to your own account only affects your chats.
Can I give a connector less than full access?
Yes, and this is the point of the consent screen. It lists your workspace access policies alongside full access, and the key it mints is bound to whichever you choose. A connector on an Analytics-only policy cannot read revenue or contact emails, and the limit is enforced at the tool layer — not in the UI.
What happens if I change the policy later?
Editing a policy changes what every key issued under it can do, immediately — there is nothing to reconnect. Deleting a policy does NOT promote its keys: resolution fails closed, so a key whose policy has gone is denied everything rather than falling back to full access.
Keep going
Turn your company into one AI-ready data platform on a single hosted MCP endpoint.