From Madhur Jain | Product & Market Analysis

MCP Server List: Which SaaS Incumbents Opened the Workflow and Which Stalled

On this page

We read the official Model Context Protocol documentation of 13 large SaaS vendors on 9 October 2026. 8 of them run a generally available, vendor-hosted MCP server that lets an agent create or change records. The other 5 are in preview, expose only a narrow slice, or send agents through a gateway they control. This MCP server list scores each one on scope and write access, because those two columns say more about who is opening the workflow than any launch announcement does.

Key takeaways

  • 8 of 13 incumbents now let agents write through an official MCP server. Stripe, HubSpot, GitHub, Notion, Atlassian, Linear, Asana and Salesforce all document create or update actions on a hosted server a customer admin can switch on.
  • Only 2 of the 13 document delete as an agent action. Stripe exposes any DELETE method in its API, and Microsoft's Dynamics 365 ERP server ships a delete tool. Everyone else stops at create and update.
  • The real gate is metering, not the protocol. Microsoft charges 0.1 Copilot Credits per ERP tool call outside Copilot Studio, and Atlassian bills enriched MCP calls in Rovo credits with overage at $0.01 per credit from 3 December 2026.
  • The vendors that stalled hold the most sensitive data. Workday requires every third-party agent to route through its Agent Gateway, ServiceNow makes admins build the tools, and SAP has announced plans rather than a customer-facing server.
8 of 13Incumbents with a generally available, vendor-hosted MCP server that allows agent writes. Source: Zan Digital review of vendor documentation, October 2026.
0.1Copilot Credits charged per Dynamics 365 ERP tool call from non-Microsoft agent clients. Source: Microsoft Learn, 2026.
24 hoursHow long a Stripe refund or payout waits for a human to approve it before the agent's request expires. Source: Stripe docs, 2026.

The short answer: most collaboration, CRM and payments incumbents now publish an official MCP server with write access. The systems of record for people, IT service and ERP are the exceptions.

For protocol background, read how MCP became the default agent interoperability standard.

How this MCP server list was built and scored

Most MCP directories mix official servers with community wrappers of the same API, which makes them useless for procurement. A wrapper can disappear, change owner or ship a backdoor, and the vendor carries no responsibility.

So this list counts only servers the vendor documents on its own developer or support site. Where we could not open the vendor's own page, we say so in the row.

What counts as an official, open server

A vendor counts as open if three things are true. The server is hosted by the vendor at a public endpoint. It is labelled generally available rather than preview, beta or early access. And it lets an agent create or update records once a customer admin enables it.

Previews do not count, because a preview can change its tools, pricing and endpoint without notice. Microsoft's Dynamics 365 ERP server is the clearest case: it is labelled "production ready preview" and is excluded from the 8 for that reason alone.

The two scores, and why rate limits are a separate column

Scope runs from 0 to 3. A 3 reaches most of the product's public API, a 2 the core objects of the main product, and a 1 a narrow preset or buyer-facing surface. A 0 means no generally available official server.

Writes also run from 0 to 3. A 3 means create, update and delete, and a 2 means create and update with no documented delete. A 1 means writes only through admin-built tools or a shopper-facing surface, and a 0 means none.

Rate limits and metering sit outside the score on purpose. A vendor can open everything and then price each call so unattended use is uneconomic, which is a different decision.

The MCP server list: 13 incumbents in one table

Each vendor name links to its own MCP documentation. Scores reflect what that page said on 9 October 2026.

Official MCP servers at 13 SaaS incumbents, scored on scope and write access, October 2026
VendorStatusScopeWritesGuardrail or meter worth knowing
StripeHosted, live33Human approval for refunds and outbound payments
Microsoft Dynamics 365 ERPProduction ready preview330.1 Copilot Credits per call outside Copilot Studio
HubSpotGA, 13 April 202632User confirmation before any CRM create or update
GitHubHosted, live32Read-only mode by URL suffix or header
NotionHosted, live32Interactive OAuth only, no headless agents yet
Atlassian (Jira, Confluence, Compass)GA, rollout from December 202522IP allowlists, audit logs, Rovo credit metering
LinearHosted, live22Separate read-only endpoint
AsanaV2 hosted, live22Per-client allow or block on Enterprise+ only
SalesforceGA April 2026, secondary sources22Runs as the signed-in user, Enterprise Edition and up
ServiceNowMCP Server Console, Zurich11Requires Now Assist; admins build write tools
ShopifyMoved to UCP11Shopper-side carts; checkout requests must be signed
WorkdayGateway live; MCP tools in early access00All third-party agents must route through Agent Gateway
SAPAnnounced, not shipped as a customer server00MCP used inside Joule and Integration Suite

Scores are our own reading of each vendor's documentation, not the vendor's claims.

Scope plus write access, out of 6 Dark bars are generally available. Pale bars are preview, gated or not shipped. Stripe6 Dynamics 365 ERP (preview)6 HubSpot5 GitHub5 Notion5 Atlassian4 Linear4 Asana4 Salesforce4 ServiceNow2 Shopify2 Workday0 SAP0 Scored by Zan Digital from vendor documentation read on 9 October 2026. Scope 0 to 3 plus writes 0 to 3.
The split is by data type, not company size. Payments, CRM and work management opened up. HR and ERP systems of record either sit in preview or have not shipped a customer server at all.

Who shipped an MCP server with write access

All 8 open vendors host the server, authenticate with OAuth, and execute every tool call as the signed-in user. So the agent inherits that user's permissions rather than a separate super-credential.

They differ on reach, and on what stops an irreversible action.

Stripe and Microsoft expose almost the whole API

Stripe's hosted server at mcp.stripe.com offers a generic read tool covering "any Stripe API GET method", per Stripe's MCP documentation. Its generic write tool covers "any Stripe API POST, PATCH, PUT and DELETE method". The listed write methods include creating refunds, cancelling subscriptions, voiding invoices and deleting coupons.

It also has the strongest guardrail in this list. Certain write actions, including refunds and outbound payments, require a human to click a confirmation link. An unapproved action expires after 24 hours. Admins can also turn MCP access on or off separately for live mode and sandboxes.

Microsoft's Dynamics 365 ERP server goes as far. Its data tools let an agent "create, read, update, and delete data". It runs under the user's security role and rejects calls to objects that role cannot reach. It is still labelled a preview.

HubSpot and Atlassian open the core, with confirmation and allowlists

HubSpot moved its remote server to general availability for all accounts on 13 April 2026, adding write capabilities in the same release, according to HubSpot's developer changelog. Agents can create and edit contacts, companies, deals, tickets, line items, products and activities. No delete tool is described.

HubSpot's CRM write tool "requires explicit user confirmation before executing any create or update". Accounts with sensitive data enabled also lose MCP access to activities and conversations.

Atlassian's server covers Jira, Confluence and Compass, and its release note describes searching, creating, updating and linking items. Admins get the controls security teams ask about first. These are domain allowlists for which AI clients may connect, enforcement of existing Cloud IP allowlists on every tool call, and audit log entries for tool invocations.

Developer tools ship a read-only switch, and you should use it

GitHub and Linear both let you pin an agent to read-only at the connection level. GitHub's remote server accepts a /readonly suffix on any URL or an X-MCP-Readonly header, per its public repository. Linear offers a separate endpoint "which only ever exposes read tools".

This is the most useful feature in the inventory, and I would not connect an unattended agent to a server without it. A read-only endpoint enforced by the vendor is a boundary. A prompt telling the agent not to write is a suggestion.

GitHub's lockdown header is described as a "best-effort content filter, not a security boundary". Its remote server is not available on GitHub Enterprise Server, which leaves self-hosted customers on the local build.

Notion and Asana each carry one catch. Notion "currently requires you to complete the OAuth authorization flow", so a scheduled agent with no human present cannot connect yet. Asana lets customers allow or block specific MCP clients, but only on its Enterprise+ and Legacy Enterprise tiers.

Salesforce belongs in this group on the evidence available, with a caveat. Its developer site refused our automated requests. The April 2026 general availability date and the Enterprise Edition requirement come from secondary coverage quoting Salesforce's developer blog, including a May 2026 analysis by Peliqan. Treat that row as reported, not verified. How Salesforce's wider agent strategy fits is covered in whether Salesforce becomes the agent platform or the roadkill.

Which guardrails each open server documents Filled = documented on the vendor's MCP page. Hollow = not found there. Red = delete is exposed. Read-only Human confirm Admin allowlist Delete exposed Stripe Dynamics 365 ERP HubSpot GitHub Linear Atlassian Notion Asana (Enterprise+) Salesforcen/vn/vn/vn/v n/v = Salesforce's own page could not be opened. Stripe's allowlist is a team-wide live and sandbox toggle.
No vendor documents all three protective controls. The two servers that expose delete differ sharply: Stripe adds human confirmation on money movement, while Microsoft relies on the user's security role.

Rate limits and metering are where MCP adoption gets priced

Most vendors' MCP pages state no rate limit. Stripe's MCP page lists none. HubSpot's lists result caps instead: 200 records per search page and 100 object IDs per fetch. Notion says its server "uses the standard API request limits" and that every tool call counts toward them.

Stripe's general limit is 100 requests per second in live mode, with most individual endpoints capped at 25, per Stripe's rate limit page. Those limits apply per account, and the MCP page names no separate budget. Plan as if an agent loop draws from the same pool as your checkout.

Two vendors have moved past silence to pricing. Atlassian now meters its MCP server in Rovo credits. Its usage limits page lists write operations such as updating a Jira work item as free. "Enriched" search and context calls cost 1 to 10 credits per call in the vast majority of cases.

Jira and Confluence include 25, 70 or 150 credits per user per month on Standard, Premium and Enterprise. Extra usage billing at $0.01 per credit takes effect on 3 December 2026.

Microsoft charges per call outright. Agent clients other than Copilot Studio pay 0.1 Copilot Credits for each Dynamics 365 ERP tool call, while Copilot Studio agents run the same tools inside a fixed agent action rate. I think this is the clearest case in the list of an incumbent keeping the protocol open while tilting the economics toward its own agent.

Atlassian's line is telling: writes are free and retrieval is metered. That rewards agents that act inside Jira and taxes agents that mine it for context to use elsewhere. The case for publishing rate limits and per-call pricing like price lists is made in the case for a rate limit and pricing transparency standard.

Which enterprise SaaS vendors stalled on MCP adoption, and why it looks deliberate

"Stalled" is only half right. The three vendors at the bottom of this list are not ignoring agents. Each has chosen a design where the vendor, not the customer's agent, decides what is exposed.

Workday routes every agent through its own gateway

Workday's admin guide is unambiguous: "All third-party agents interacting with Workday APIs must route their API traffic through Agent Gateway using Agent System User (ASU) security." Agents must first be registered in Workday's Agent System of Record. The gateway offers built-in rate limiting and tracks API consumption "for accurate billing", per the Workday Agent Gateway documentation, last updated 21 August 2026.

Workday has not shipped a generally available MCP server that any client can use. A vendor blog from Hirevire, which sells its own Workday connector, reports that Workday's MCP tools were announced on 2 June 2026. It says they sit in early access through the paid Extend Professional SKU. That source has a commercial interest, so treat its timing as directional.

I think Workday's design is right for payroll and personnel data, even though it scores zero here. Registration plus a metered gateway is the control an HR leader should want before any agent writes to a compensation record.

ServiceNow makes the admin build the tools

ServiceNow's MCP Server Console arrived in the Zurich release and requires activation of a Now Assist application, per its release notes. The preconfigured Quickstart Server includes tools "for looking up and summarizing incident and case records". That is a read surface.

Writes arrive only when an administrator builds them. From April 2026, admins can create tools from subflows, actions, REST APIs, knowledge graphs and Now Assist skills. It is the opposite of Stripe's model: nothing is exposed until someone in your company decides so.

SAP consumes MCP before it serves it

SAP's MCP activity so far points inward. At Sapphire 2026 it announced plans to integrate Claude agents into its Business AI Platform "using MCP standards", according to SAPinsider's May 2026 report. The same report notes that HANA Cloud added MCP support in early 2026 and that Integration Suite APIs "can be converted" into MCP tools.

SAPinsider adds its own caveat, that "can be converted" is not the same as production-supported. We found no SAP-documented, customer-facing MCP server for S/4HANA comparable to the ones above. Until one exists, agents reach SAP data through Joule, Integration Suite or a third-party connector.

Shopify scored low for a different reason. It moved its storefront catalog and cart tools to the Universal Commerce Protocol, and its checkout tools require every request to be authenticated or signed. That server serves shopping agents acting for buyers, not your operations team.

MCP server deadlines landing in the next six months

Several vendors have dated changes that will break or reprice existing connections.

Dated MCP changes across the inventory Above the line: already happened. Below: still ahead as of 9 October 2026. Today Dec 2025Atlassian GA 13 Apr 2026HubSpot GA 2 Jun 2026Workday early access 31 Aug 2026Rovo credit pricing 1 Oct 2026: Dynamics static server retired 31 Oct 2026Stripe key cutoff 3 Dec 2026Rovo overage billing 1 Mar 2027Atlassian v1 to v2 Sources: Stripe, Atlassian and Microsoft documentation; HubSpot changelog; Workday date from a third-party vendor blog. Spacing is approximate and not to scale.
The three dark points are the ones to diary. Two change what an existing connection is allowed to do, and one changes what it costs.

The nearest is Stripe. "Beginning 31 October 2026, Stripe MCP no longer accepts full-access secret keys or restricted API keys without the Agent tag." Any agent still using a plain secret key will start receiving a 401 error on that date.

Atlassian has two. Extra usage billing for Rovo credits starts on 3 December 2026, and on 1 March 2027 existing v1 connections will automatically start using v2 tools at the new endpoint. A tool set that changes underneath a running agent is a behaviour change, not a version bump.

Microsoft already retired its static 13-tool Dynamics 365 ERP server on 1 October 2026. If an agent built on it went quiet this month, look there first.

Where this inventory is weakest

This list is a documentation review, and documentation is not behaviour. We did not test each server under load, so every score is what the vendor says, not what we observed.

Three weaknesses stand out. First, the Salesforce row rests on secondary sources because Salesforce's developer pages refused automated access. Second, several vendors publish no date on their MCP page, so "live" in the table means "documented without a preview label", not "GA since a known date". Third, the Workday early access date comes from a vendor with a commercial interest in the gap.

The counter-case: breadth is not openness

The strongest objection to this scoring is that it rewards breadth, and breadth is not obviously good. A server that exposes every API method to an agent hands the same blast radius to a confused model as to a careful one. On that view, ServiceNow's build-your-own design is mature and Stripe's generic write tool is risky.

I think that objection is half right. Breadth without a vendor-enforced read-only mode or confirmation step is a liability, and these scores are not a safety ranking. Where I disagree is on who holds the decision. A narrow server makes every customer wait for the vendor or build the tools. A broad server with confirmation on irreversible actions, as Stripe ships, lets the customer decide.

An official server removes the risk of a malicious community wrapper, covered in the analysis of MCP servers as a supply chain risk. It does not stop an agent misusing a legitimate tool.

What to ask a vendor before you connect an agent

Most of these differences are invisible in a sales demo. Five questions surface them, each answerable from the vendor's own documentation.

Five questions for any vendor's MCP server, and what a good answer looks like
QuestionGood answerWeak answer
Can I pin a connection to read-only at the server?A separate endpoint or header, as GitHub and Linear offer"Use your client's tool approval settings"
Which actions need a human to confirm?A named list, as Stripe and HubSpot documentNone, or "the model will ask"
Whose identity does each call run as?The signed-in user, with existing permissions enforcedA shared integration account with broad scopes
How are calls counted and billed?A published per-call or credit rate with a dateNot stated on the MCP page
Can an unattended agent authenticate?A documented non-interactive method an admin controlsInteractive OAuth only

Running calls as the signed-in user is safer for permissions, but the audit trail then shows a person doing what an agent did. The trade-offs between that pattern and a dedicated agent identity are worked through in agent credentials versus user impersonation.

Where a system of record has no MCP server at all, granting write access is a harder decision. That case is covered in how to give agents write access to legacy systems.

Frequently asked questions

Which SaaS companies have an official MCP server?

As of October 2026, Stripe, HubSpot, GitHub, Notion, Atlassian, Linear, Asana and Salesforce run generally available, vendor-hosted MCP servers that allow agents to create or update records. Microsoft offers a Dynamics 365 ERP server in preview. ServiceNow ships a console for building tools, Shopify moved its tools to the Universal Commerce Protocol, and Workday and SAP have not shipped a generally available customer-facing server.

Does the Salesforce MCP server allow write access?

Secondary coverage of Salesforce's April 2026 announcement describes hosted MCP servers for Enterprise Edition orgs and above, with tools that create, read, update and query records. Every call runs as the authenticated user, so existing object permissions, field-level security and sharing rules apply. Salesforce's own developer pages could not be opened for this review, so confirm the tool list in your org's Setup before relying on it.

What are the Atlassian MCP server rate limits?

Atlassian now meters its Rovo MCP server in Rovo credits rather than publishing a flat call limit on its usage page. Write operations, such as updating a Jira work item, are free. Enriched search and context calls usually cost 1 to 10 credits each. Jira and Confluence include 25, 70 or 150 credits per user per month by plan, with overage billed at $0.01 per credit from 3 December 2026.

Can the HubSpot MCP server delete records?

HubSpot's documentation describes create and edit access for contacts, companies, deals, tickets, line items, products and activities, but it does not describe a delete tool for CRM records. Its CRM write tool also requires explicit user confirmation before any create or update runs. Accounts with sensitive data enabled lose MCP access to activity and conversation data entirely.

Does Workday have an MCP server?

Workday has not shipped a generally available MCP server that any client can connect to. Instead, all third-party agents must register in Workday's Agent System of Record and route API traffic through its Agent Gateway using Agent System User security. Third-party reporting says Workday's MCP tools are in early access through the paid Extend Professional SKU, with no confirmed general availability date.

How do I make an MCP server read-only?

Use a vendor-enforced setting wherever one exists. GitHub's remote server accepts a /readonly suffix on its URL or an X-MCP-Readonly header, and Linear provides a separate endpoint that only exposes read tools. Where the vendor offers neither, restrict the OAuth scopes you grant, or connect with a user account whose own permissions are read-only, since most servers execute calls as that user.

Where to start

Pull the list of MCP connections your teams already use and mark each one official or community. Replace any community wrapper for a vendor in the table above with the vendor's own server this month. The official version runs under your users' permissions, and the wrapper may not.

Then put 31 October 2026 in the diary if anyone connects agents to Stripe. Rotate those connections to an Agent-tagged key or OAuth before that date, and test a refund in a sandbox so you see the confirmation step before a customer does.

Related analysis

Why integration depth, not model quality, decides which software survives agents is argued in integration depth as the real AI moat.

References

  1. Stripe, Model Context Protocol (MCP) and Rate limits, read 9 October 2026. Used for tools, human confirmation, key cutoff and API rate limits.
  2. HubSpot, Remote HubSpot MCP server is now generally available, 13 April 2026, updated 15 April 2026. Used for GA date and write scope.
  3. HubSpot, Integrate with the remote HubSpot MCP server, read 9 October 2026. Used for confirmation, result caps and sensitive data rules.
  4. Atlassian, Rovo usage limits and Use Atlassian Rovo MCP server, read 9 October 2026. Used for credit metering, free writes, overage date and v2 migration.
  5. Microsoft Learn, Dynamics 365 ERP MCP server, updated September 2026. Used for CRUD tools, per-call credits and static server retirement.
  6. Workday, Concept: Workday Agent Gateway, last updated 21 August 2026. Used for mandatory gateway routing and registration.
  7. ServiceNow, MCP Server Console release notes, Zurich, updated through April 2026. Used for requirements and tool types.
  8. SAPinsider, SAP Joule, Claude and MCP, 20 May 2026. Used for SAP's announced plans and HANA Cloud support.

The weakest part of this source base is Salesforce: its row relies on secondary coverage, including a competitor-adjacent vendor blog, because Salesforce's own pages could not be opened. Atlassian's December 2025 GA timing comes from a third-party mirror of its release note. Several vendor MCP pages carry no publication date.

AV
Madhur Jain
Contributing Analyst, Zan Digital. Writes about AI agents, enterprise software integration and what vendor documentation actually commits to.

Related reading