MCP Server for AI apps
The CRMSix MCP server lets AI apps such as Claude, Cursor and VS Code work with your CRM: “list my open cases”, “summarise this account”, “move this opportunity to Negotiation”. The AI app only sees and changes what the person or key it acts for could, and every change is recorded as theirs.
Turn it on
- An admin goes to Settings → MCP Server.
- Tick Enable the MCP server. When it’s off, AI apps are refused; the regular API isn’t affected.
- Decide whether to tick Allow AI clients to make changes. When it’s off, AI apps only get the read tools. Either way, there are no tools to delete records or send email.
- Save, and copy the server URL shown under Connect a client (it ends in
/api/mcp; Streamable HTTP).
Connect: each person signs in (recommended)
Each person connects their own AI app and signs in to CRMSix as themselves, so the app has exactly their permissions.
- In claude.ai or Claude Desktop, open Settings → Connectors → Add custom connector and paste the server URL.
- Choose Connect. A CRMSix sign-in page opens: sign in with your password or SSO.
- Review what the app is asking for and choose Allow. You can allow read-only access.
- Ask Claude something, for example “Use CRMSix to list my open cases”.
In Claude Code, add the server, then run /mcp and choose Authenticate:
claude mcp add --transport http crmsix https://<your CRMSix address>/api/mcp
Connect with an API key
For automations and shared tools that don’t belong to one person. First create an API key, ideally read-only and running as a user with only the access it needs. The AI app then acts as that key’s run-as user. A connected app’s access token works too.
Claude Code:
claude mcp add --transport http crmsix https://<your CRMSix address>/api/mcp \
--header "X-API-Key: <your API key>"
Cursor, VS Code and other clients (mcp.json):
{
"mcpServers": {
"crmsix": {
"type": "http",
"url": "https://<your CRMSix address>/api/mcp",
"headers": { "X-API-Key": "<your API key>" }
}
}
}
Claude Desktop (claude_desktop_config.json), through the mcp-remote bridge, which needs Node.js:
{
"mcpServers": {
"crmsix": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://<your CRMSix address>/api/mcp",
"--header", "X-API-Key:${SCL_API_KEY}"],
"env": { "SCL_API_KEY": "<your API key>" }
}
}
}
The Settings → MCP Server page shows each of these with your server URL filled in, ready to copy.
What the AI app can do
| Tool | What it does | Access |
|---|---|---|
search_records | Search cases, accounts, contacts, leads and opportunities by name, number, email or subject | Read |
list_cases, get_case | Find cases; a case with its comments, emails, tasks and events | Read |
list_accounts, get_account | Find accounts by name; an account with its contacts, opportunities and cases | Read |
list_contacts, get_contact | Find contacts by name or email; a contact’s details | Read |
list_leads, get_lead | List leads, newest first; a lead with its emails, tasks and events | Read |
list_opportunities, get_opportunity | List opportunities; an opportunity with its products, emails, tasks and events | Read |
run_report | Counts (and amounts, for opportunities) grouped by a field, plus the first matching records | Read |
get_forecast | A quarter’s forecast by category, with quotas, per owner and month | Read |
search_knowledge, get_knowledge_article | Search published knowledge articles; an article’s full text | Read |
list_picklist_values, list_users_and_queues | Valid statuses, stages and other values; active users and support teams | Read |
create_case, update_case, add_case_comment | Open a case (assignment rules route it), change or assign it, add an internal or public comment | Change |
create_lead, update_lead | Create a lead; change its status, rating, owner or contact details | Change |
create_opportunity, update_opportunity | Create an opportunity; change its stage, amount, close date, next step, probability or forecast category | Change |
create_task | Create a task | Change |
The Change tools are only offered when Allow AI clients to make changes is on and the connection isn’t read-only. Converting leads, deleting records and sending email are done in CRMSix itself.
Permissions and records
- Same access as the personObject permissions, field security and sharing apply, so hidden fields and records stay hidden.
- Changes are theirsRecords show the person (or the key’s run-as user) as Updated By, and field history records the change.
- Same rulesValidation rules, assignment rules, workflow rules and flows run as for any other save.
- Read-only connectionsRead-only sign-ins, keys and apps never get the Change tools.
See and disconnect AI apps
Admins see every sign-in connection under Connected AI apps on Settings → MCP Server: the app, the person, the access (read-only or read and change), when it was connected and last used. Disconnect stops it at once; the person can connect again. Connections made with an API key are stopped by revoking the key.
Troubleshooting
- The AI app says it can’t connect
- Check that the MCP server is enabled, and that the URL is the one shown on Settings → MCP Server, ending in
/api/mcp. - The AI app can read but not make changes
- Allow AI clients to make changes is off, or the sign-in, key or app is read-only.
- A record the person can see in CRMSix is missing
- With an API key, the app acts as the key’s run-as user, not as the person; that user may not have access to the record.
- It stopped working
- The connection was disconnected, the key was revoked or expired, or the user was deactivated. Connect again or create a new key.