Normally, Claude only knows what you type or paste into the chat. A connector changes that. It is a live, authenticated bridge between Claude and a real outside system: your QuickBooks file, your Gmail, your HubSpot pipeline.
Claude can read current data there and, if you allow it, take actions there too, instead of you copying numbers back and forth by hand.
Connectors run on MCP (Model Context Protocol), an open standard Anthropic introduced in November 2024 so any AI application can talk to any tool through one common interface, instead of every pairing needing its own custom integration. Anthropic has compared it to a USB-C port for AI: one plug, many devices.
MCP has since been adopted well beyond Claude, including by OpenAI and Google DeepMind, and thousands of MCP servers now exist across the industry.
Claude's own connectors directory launched in July 2025 with roughly 200 integrations and has kept growing since, covering finance (QuickBooks, PayPal), productivity (Google Workspace, Microsoft 365, Slack), CRM and marketing (HubSpot), design (Canva), signed paperwork (DocuSign), and databases (Airtable), among hundreds of others.
Anthropic does not publish a live count, and third-party trackers put the current total anywhere from the low 300s to over 400 by mid-2026, so treat any exact number, including this one, as approximate. The directory itself at claude.com/connectors is the source to check.
This is different from a Project's knowledge files. A file you upload to a Project is static until you replace it. A connector is live: ask about this month's QuickBooks balance and Claude queries the current file directly.
Both are ways of grounding Claude in your actual business instead of industry averages, the same idea behind a business knowledge base, but a connector's data moves and a Project's does not.
OAuth means Claude never sees your password. Scoping decides everything else.
Connecting a tool runs through OAuth, a standard hand-off where you log into the service itself (Intuit, Google, Microsoft, whoever runs the tool) on its own login page, approve a specific list of permissions, and that service hands Claude a token limited to exactly what you approved.
Claude never sees or stores your QuickBooks or Gmail password. That part is solid and is not really the risk.
The risk, and the part worth 5 minutes of attention, is scope. Claude's connector settings define 3 levels per tool or per permission: Always allow, Needs approval, and Blocked.
Always allow means Claude uses that tool without asking each time. Needs approval means Claude has to ask before every single use of that action.
Blocked hides the tool entirely, and Claude reports that it has no tool for the job rather than attempting a workaround.
A connector also inherits whatever you can already do inside that tool. If your own login can delete an invoice, a write-enabled QuickBooks connection can delete an invoice too, exactly as fast and exactly as wrong, the moment you approve the action.
Scoping is the only real safety control, because the connector itself has no independent judgment about which actions are safe to take.
Microsoft's connector for Claude is a useful example of the conservative end of this spectrum. As of mid-2026 it is read-only, with no exceptions: it can search Outlook mail, SharePoint, OneDrive, and Teams chat and calendar, but it cannot create, edit, or delete anything, send a message, or change a permission, regardless of what you approve.
That is the safest shape a connector can take, and a reasonable bar to hold every other connector to until you have watched it work correctly for a few weeks.
The practical rule: start read-only wherever the tool offers it. Move to draft-and-approve next. Save always-allow for actions you would not mind Claude getting wrong once, because eventually, on a long enough timeline, it will.
Which connectors are actually worth it for a small business
Not every connector in the directory earns a place in your business. These are the ones that come up most for an owner-operator, and the access level worth starting at.
What connectors cost: generally nothing on top of your plan
Connecting a tool does not carry its own price tag. Anthropic includes connector access across Free, Pro, Max, and Team, verified against Claude's pricing page and help center in July 2026.
Since a February 2026 update, even the Free plan includes basic app connectors (subject to daily usage limits), where before that remote connectors were paid-plan only. Paid plans mainly buy you more usage headroom for connector-heavy work, not extra connectors themselves.
So whatever you already pay for Claude is the entire cost. Pro runs $17/month billed annually or $20/month billed monthly: $17/mo x 12 = $204/yr.
A connector like QuickBooks or HubSpot adds $0 to that bill. The time cost is the setup walkthrough above, roughly 10 minutes per tool, plus the ongoing job of reviewing what it drafts.
If a QuickBooks connector saves you 15 min/day of manual report-pulling, that is 15 min/day x 5 days/wk x 52 wks/yr = 65 hrs/yr. At a $40/hr bookkeeping rate, 65 hrs x $40/hr = $2,600/yr in time back, against a $0 connector cost.
What a connector will not do: it grants access, not judgment
- A connector only grants access, it does not add judgment. It can now see your invoices, but it does not know which client relationship you cannot afford to lose or which number is the exception to your own rule.
- Write access to accounting or email is a real risk if Claude is ungrounded. QuickBooks integrations that support write access generally require your confirmation before a destructive action like deleting an invoice, but a rushed approval is still a rushed approval. See how to handle AI on customer comms safely before you widen scope on anything customer-facing.
- Some connectors have real, documented gaps. Claude's Gmail connector cannot read attachments, only their names and metadata, so a customer thread with an attached PDF still needs you to open it yourself.
- Microsoft 365 is read-only end to end right now. Useful for safety, but it means Claude can draft the email from what it finds in Outlook, and you still have to send it yourself.
- A connector inherits your own permissions, mistakes included. If your login can void an invoice or delete a contact, a write-enabled connector can too, exactly as fast, the moment it is approved to.
- An old, forgotten connection is a door nobody is watching. Disconnect anything you set up once and stopped using.
None of this is a reason to skip connectors. It is a reason to sequence them the way you would sequence a new employee: read-only access first, a track record next, wider access only once you have watched it get things right.
The setup itself is 10 minutes. The judgment about what it is allowed to touch is the actual work, and it is worth doing before the first connector, not after the first mistake.
If you want that sequencing built around your specific tools and rules rather than figured out alone, that is the kind of setup we do in month one.