mcp

MCP Servers for Business Tools: What AI Can Actually Reach

August 28, 2026

By , Founder, AI Automation Builder

You want to open a chat window and ask what you invoiced last month against what you collected, which jobs slipped this week, which deal went quiet. Then you want to say “create that task” or “send that invoice” and have it happen. Whether any of that works has almost nothing to do with which AI model you picked. It depends on whether the model can reach QuickBooks, Slack, HubSpot and whatever else you already pay for. Search for an MCP server list today and what comes back is developer directories sorted by GitHub stars, with no answer to the only question an owner is asking.

Below is the list we built, read from the buyer’s side. The connection layer decides whether an AI answers from your data or improvises around it, and the plain-language version of why is in how grounded answers work. This page is the other half: 28 tools that US small businesses actually run, and what each one lets an AI touch as of August 27, 2026.

What is an MCP server, in business terms?

An MCP server is a standard connector between an AI assistant and one of your business tools. MCP stands for Model Context Protocol, an open standard for how AI software talks to outside systems. The practical effect is that connections stop being custom one-offs: instead of a bespoke integration per tool per AI product, every tool exposes the same plug shape, and any assistant that speaks the standard can use it.

There are two kinds, and the difference is what your project will cost.

A ready-made server is published by the vendor or by a credible open-source maintainer. You authorize it the way you authorize any app that connects to your account, and someone with admin rights can usually have it working the same day. This is what “plug in today” means in the table below.

You commission a custom-built server when no good one exists. Any tool with a public API, meaning a documented way for other software to read and write the tool’s data, can get one. Building it needs four things: an API that is actually available on the plan you pay for, a key or OAuth app that you issue and can revoke without calling anyone, a few days of developer work, and a small server running somewhere that stays patched. None of that is exotic. The part that stops projects is the first item, because API access is a pricing decision at a lot of vendors, and you find out after you have already scoped the work.

Which business tools have an MCP server today?

This is the list, grouped the way a business thinks about its stack rather than the way a directory sorts it. Four verdicts:

  • Plug in today. A working server exists. Setup is an admin task, not a project.
  • A connector can be built. No server worth trusting yet, but a public API you can reach on your plan. Days of developer work.
  • Exports only. No connector and no API you can use. Data moves as files, on a schedule someone maintains.
  • Closed. Nothing comes out programmatically on that plan at all.

Money

ToolStatusVerdictThe catch
QuickBooks OnlineOfficial (Intuit)Plug in todayYou authorize it yourself, no gatekeeper. The official server ships 145 tools, so the real decision is which of them you switch on.
XeroOfficial (Xero)Plug in todaySelf-hosted, so someone on your side runs it. 50+ tools.
StripeOfficial (hosted server plus toolkit)Plug in todayConnect sub-accounts need their own restricted key.
SquareOfficial (beta)Plug in todayThe hosted version is allowlist-gated, so you request access. The self-hosted version works now.
WaveCommunity, dormantA connector can be builtA self-serve token for your own account, no gatekeeper. The “Wave has no API” reputation is out of date. Reselling access to others needs Wave’s approval.

Projects, boards and docs

ToolStatusVerdictThe catch
ClickUpOfficial (public beta)Plug in todayThe popular community alternative went paid at $9/mo, which is a good reason to use the official one.
AsanaOfficial (GA)Plug in todayRequest limits scale with your plan, 150 to 1,500 per minute.
Monday.comOfficial, preinstalled on all accountsPlug in todayFree tier caps at 1,000 API calls a day, which a chatty assistant will hit.
TrelloOfficial (Atlassian)Plug in todayNo paid gate on API access.
NotionOfficial (remote)Plug in todayIt sees only the pages you explicitly share with it. The local server is being sunset.
AirtableOfficialPlug in todayThe official server is thin: no schema management, no delete. A community server is more capable if you need more.
MiroOfficialPlug in todayAvailable on all plans including free.
Google SheetsOfficial (developer preview)Plug in todayPreview status, six tools, 60 reads and 60 writes a minute.

CRM and sales

ToolStatusVerdictThe catch
HubSpotOfficial, GA April 2026Plug in todayHosted by HubSpot, so nothing runs on your side.
PipedriveOfficial, June 30, 2026Plug in todayAvailable on every plan, which is rarer than it sounds.
Zoho CRMOfficial, four serversPlug in todayIncluded free with your plan.
SalesforceOfficial, GA April 2026Plug in today on Enterprise and above. Buildable below itThe hosted server is Enterprise-only. Professional and below get the raw access to build on, so you build the connector. Many small-business Salesforce accounts sit below the line.
GoHighLevelOfficial on Unlimited ($297) and SaaS Pro ($497)Plug in today on those plans. Closed on StarterStarter ($97) has zero API access. No workaround, no bridge, nothing.
ShopifySplit: official Storefront server, no official Admin serverPlug in today for storefront. Buildable for store operationsStore operations run through the admin API, reached today by a community server.

Field service

ToolStatusVerdictThe catch
JobberSmall community server, realA connector can be builtNo paywall on API access, which makes it the cleanest build of the three.
Housecall ProSmall community serverBuildable on MAX. Closed below itAPI access exists only on the MAX plan. Below MAX there is no programmatic access at all.
ServiceTitanCommunity, unprovenBuildable, gatedThe API is there, but the partner program is required: dues, certification, annual recertification. The bottleneck is the paperwork, not the code.

Messages and mail

ToolStatusVerdictThe catch
SlackOfficial, GA February 2026Plug in todayRequires workspace admin approval. The bot reads only channels it is invited to, and there is no org-wide override.
Microsoft TeamsOfficial (preview)Plug in todayGated behind an M365 Copilot license. Reading channel messages is one tenant-wide admin consent.
Google ChatOfficial (developer preview)Plug in todayPer-space invite by default. Domain-wide delegation impersonates one user.
GmailOfficial (developer preview)Plug in todayNothing unusual to set up.
Google CalendarOfficial (developer preview)Plug in todayPreview status, so expect changes.
WhatsApp BusinessNo official serverA connector can be builtThe official business messaging API has a rule to design around: outside a 24-hour window from the customer’s last message, outbound is template-only. Inbound is unrestricted. Sending volume is gated by business verification.

Look back over the rows that came out closed and notice what closed them. Not one of them is closed by the technology: GoHighLevel Starter, Housecall Pro below MAX and Salesforce Professional are all blocked by a line on a price sheet, and one plan up each of those tools opens.

Read the whole thing at once and a pattern shows up that nobody expects. The office side of the business is nearly all green. Every one of the four money tools with an official server (QuickBooks, Xero, Stripe, Square) is vendor-built. The entire projects category is plug-in-today. And the tools closest to the actual revenue-generating work, the ones your technicians use in the field, have no official servers at all, plus plan gates and partner programs on top.

What can you actually ask it, category by category?

A connector is worth money only if it answers a question you currently answer by opening four tabs. Reading is the easy half and is where most of the value shows up in the first month. Writing is a separate decision, made per install, and the shortest write list that does the job is the right one.

Money. You can ask: what did we invoice last month against what we collected, which invoices are more than 30 days late and who owns those accounts, what did card fees cost us in July. You can also tell it to draft the invoice, log the payment against it, mark a bill paid. The official QuickBooks server ships 145 tools, so the surface is there. A sane project turns on a handful of them and leaves the rest off.

Projects and boards. You can ask: what is blocking this job, which tasks slipped past their due date this week and whose they are, how many hours went to this client in July. You can also tell it to create the task, assign it, log the time, set the priority. Worth knowing before you scope: Airtable’s official server will not delete anything or change your schema, which is a limitation on paper and a safety rail in practice.

CRM and sales. You can ask: which deals over $10,000 have gone quiet for two weeks, where last quarter’s closed-won actually came from, which customer emailed twice and never got an answer. You can also tell it to log the call, update the stage, write the note back onto the record. The argument worth having internally is not whether the AI may write to the CRM. It is which specific fields it may change without a human looking.

Field service. You can ask: which jobs got rescheduled twice this month, whose jobs run longest against the estimate, what we quoted versus what we billed on the last 20 jobs. The honest note for this category is that “tell it to” comes later. None of the three has a vendor server, and Jobber is the only one without a plan gate or a partner program in front of the API. Most of the payoff here arrives through the accounting side anyway, which is the subject of connecting field service software to accounting.

Messages and mail. You can ask: what did the client ask for in that channel last week that never became a task, what changed on this project since Monday. You can also tell it to post the update, send the reminder, book the meeting. On WhatsApp specifically, that outbound reminder is only free-form inside 24 hours of the customer’s last message. After that it has to be a pre-approved template, and a system designed without that rule in mind will look like it works right up until it silently stops.

Who has to say yes before AI reads your team’s messages?

Someone inside your company, and the terms differ so sharply by platform that the answer changes the project. This is the one row on the whole map where the constraint is governance rather than technology, and where a decision gets made that nobody can quietly reverse later.

Slack scopes by channel. The bot reads only the channels it has been invited into, and no org-wide override exists, so access grows one deliberate invitation at a time. It also needs workspace admin approval to exist at all.

Teams scopes by tenant. Reading channel messages is a single tenant-wide admin consent, and there is no per-channel narrowing underneath it. One person clicks approve and the permission covers every channel in the organization. That is not a reason to avoid it, but it is a conversation to have with a named owner before the click, not after.

Google Chat sits at the opposite pole from Teams: per-space invite by default, same shape as Slack. Its escalation path, domain-wide delegation, impersonates one user’s access rather than opening everything.

The practical reading: if the value of your project depends on an AI reading internal conversations, find out which of those three models you are on before you promise anyone a timeline. On Teams the approval is one meeting with one decision. On Slack and Chat it is an ongoing habit of inviting the bot where it belongs.

What are the traps in an MCP server list?

The biggest one is treating popularity as safety. Star counts measure attention, and attention on this list has repeatedly attached to exactly the wrong thing.

The most-starred WhatsApp server, sitting at around 6,200 stars, bridges a personal WhatsApp account rather than the Business Cloud API. Using it for company messaging risks the account being banned. The servers that wrap the actual sanctioned API have between zero and three stars each. Sort that category by popularity and you will pick the one that can get your number cut off.

The same inversion shows up in Slack. A community server with roughly 1,800 stars ships a “stealth mode” that uses scraped browser tokens to operate without workspace admin approval. It works. It also routes around your own security review and puts credentials somewhere they should never be. An official server exists specifically so that nobody needs this.

Three more failure modes, all cheap to check and expensive to discover late:

Plan gates. GoHighLevel Starter has no API. Housecall Pro below MAX has no API. Salesforce below Enterprise has no hosted server. Teams needs a Copilot license. Monday’s free tier stops at 1,000 calls a day. In every one of those cases the software you are looking at is not the software you are paying for.

Servers that start free and stop. The popular community ClickUp server moved to $9/mo. Small money, but it arrives as a surprise inside a system somebody already depends on.

Auto-generated fakes. Whole families of repositories exist that look like MCP servers and are not, mass-produced to farm attention. We ran this list three times over, independently, and all three passes threw out the same family of repositories, which tells you how visible it is once you look and how invisible it is in a directory listing.

Then freshness, which is its own trap. Slack’s official server went GA in February 2026. HubSpot and Salesforce in April. Pipedrive at the end of June. All six CRM tools on this list went from mostly community-only to officially supported inside roughly six months. Any MCP server list published before this spring is describing a different landscape, and this one will need re-checking by winter.

What if your tool is not on the list?

Then you look at a bridge, and you read its pricing before its feature list. Three aggregators put thousands of long-tail apps behind one connection, and each carries a cost that does not appear in the pitch.

Zapier MCP covers 9,000+ apps and rides on your existing Zapier task quota, which sounds free. Each MCP call burns two tasks, not one, so an assistant that asks three questions to answer one costs six. Your data also round-trips through Zapier’s cloud on the way. If task burn is already why you are looking at alternatives, the arithmetic in migrating off Zapier to n8n is the same arithmetic.

Composio exposes 1,384 toolkits, with 20,000 calls a month free and 200,000 for $29. The billing is per call, so the bill scales with how chatty your agent is rather than how much work it completes. The item to bring to whoever handles your security: Composio holds your OAuth tokens.

Make’s MCP server is open source and exposes only the scenarios you have already built and marked on-demand. There is no dynamic discovery, so every action you want the AI to take has to exist as a finished Make scenario first. That is the highest setup cost of the three, and it undercuts the reason most people reach for a bridge in the first place.

For a genuinely long-tail tool that has a documented API, a purpose-built connector is often the cheaper end state than a bridge with a per-call meter attached to it. Bridges earn their keep when you need ten tools touched lightly, not one tool touched constantly.

How do you read your own stack in three questions?

Take the list of tools your business runs and put three questions to each one. It takes about twenty minutes and it produces a real project scope.

Does an official connector exist for this tool? Check the vendor’s own developer documentation, not a directory. Official means the vendor maintains it, which means it survives their next API change. If the answer is yes, this tool is not your problem.

Is there a public API on the plan I am actually paying for? Not on some plan. Mine. This is where GoHighLevel Starter, Housecall Pro below MAX and Salesforce Professional quietly break projects, and it is a five-minute check against a pricing page. If the answer is no, your two options are upgrading the plan or living with exports, and comparing those two numbers is a business decision rather than a technical one.

For anything carrying team conversations, who says yes and what does that yes cover? Slack means channel-by-channel invitations forever. Teams means one tenant-wide consent that reads everything. Google Chat means space-by-space. Name the person who owns that decision before anyone builds against it. Once you know which tools are reachable, the other half of the scope is which of your own questions are answerable at all, sorted by what an answer costs, row by row.

Whatever comes back as “no connector, no API” is not automatically dead. It is a tool where the data leaves as files on a schedule, and where the honest question is whether it is worth keeping at all.

So what do you do with this list?

Start where the connector already exists and the question already costs you time. On most stacks that means money and projects, because both categories are almost entirely plug-in-today and both hold the questions owners ask weekly. Getting real answers out of QuickBooks and your project tool inside a week is a better use of the first month than a heroic build against the one system that fights back.

Then handle the gate before you scope anything else. If a plan tier is standing between you and your own data, that is a line item to price against the value of the project, not an engineering obstacle to route around. Upgrading a GoHighLevel plan or moving off a Housecall Pro tier is a decision an owner makes in an afternoon. Nobody can code past it.

Field service is where this map disappoints people, and pretending otherwise would not help. Plan for reads first, treat writes as a later phase, and route the value through the systems that are open.

The last thing belongs in the plan rather than in a disclaimer. A map that expires in six months is also the argument against treating a directory lookup as a one-time job: whoever maintains your connections has to re-walk this list on a schedule, because a vendor moving one plan tier is enough to stop a workflow that has been running quietly all quarter. That standing re-check is part of what keeping AI connections current actually is, and it costs far less than finding out from a silent workflow in month seven.

We verified every row against vendor documentation on August 27, 2026. This map moves monthly: official servers launched across CRM, messaging and accounting within roughly six months of each other, several of the entries above are still in beta or developer preview, and plan gates change without notice. Re-check any row you are about to build on.

Need an automation built?

Tell us what is slowing your team down. We will scope it and send a fixed-price quote.