Set Up Claude Code MCP Safely

By Rogier Muller10.06.26
Set Up Claude Code MCP Safely

This research library uses AI-assisted source research and drafting. Linked sources support product claims; analysis and proposed exercises are our interpretation. Unless an article documents a test and its results, do not read it as a hands-on review or an independently verified benchmark.

Start with one read-only integration, not a fleet of servers. For Claude Code MCP, the useful team decision is which boundary you are willing to let Claude cross during normal development, and which actions still need a person. This note gives you a setup path and a pasteable integration checklist for a Claude Code workshop, a team rollout, or one repo that has started to depend on external context.

MCP means Model Context Protocol. In practice, it is the connection layer that lets Claude Code call tools outside the repo, such as GitHub, Figma, document stores, issue trackers, or internal knowledge systems. A Claude Code MCP server is useful when it removes copy-paste context work, but it becomes risky when nobody can say what the server may read, write, or trigger.

Make the first server boring

Pick a server that helps Claude read context before you add anything that changes state. GitHub issues, pull request metadata, docs search, or Figma frames are better first candidates than production databases or deployment systems.

For a normal pull request workflow, I like the boundary to be plain: Claude may read the linked issue, inspect changed files, and summarize design notes, but it may not merge, deploy, rotate secrets, or edit an external tracker without approval. In a Figma MCP Claude Code workflow, the same rule applies: frame inspection can be useful, design-source mutation should wait.

The reason is not that write access is always wrong. The reason is that you need one integration where the team can learn the review pattern without also debugging permissions, credentials, and accidental side effects.

Set the boundary before Claude can act

Write down the boundary before installing the server. If the first record of the rule lives only in chat history, the next developer will not see it.

As of October 2026, I would still treat write-capable MCP as an explicit opt-in. Read access can still leak data, so it needs scoping too, but write access adds recovery work when the agent misunderstands the task.

In our methodology, this belongs to Review: Claude can gather context and propose work, but a person owns the irreversible step. If you want an example of why tool-call evidence matters, see homestead-memory Logs Claude Tool Calls.

Keep the convention near the repo

A team convention should say what the MCP server is for, who owns it, and what Claude is allowed to do with it. That belongs beside the engineering workflow, not in a private note.

Use your normal Team conventions path for the durable rule. A short CLAUDE.md note can help when the repo needs always-on context, but credentials, endpoints, and org-wide policy should live in the proper Claude Code configuration or managed setup, not in repository prose.

Keep the wording operational. For example: GitHub MCP may read issues and PRs for implementation context. It may not merge, close issues, or request reviews unless the human explicitly asks for that action in the current session.

Walk through the Claude Code MCP setup

Prerequisites before you start:

  • One repo where the team already uses Claude Code.
  • One external system with a clear owner.
  • A server package or endpoint you trust enough to run locally.
  • A decision on read-only, write with approval, or write blocked.
  • A reviewer who can check both code output and tool use.

Step 1: name the job. Say what problem the integration solves in one sentence. Context lookup is a good job. General access to company systems is not a job.

Step 2: choose the smallest server. Add one Claude Code MCP server, not several Claude Code MCP servers at once. If the team needs GitHub issue context and Figma design context, start with the one that removes the most manual copying this week.

Step 3: install it locally first. Add the server using the Claude Code MCP configuration path your team supports, then run it on one developer machine. For managed laptops or enterprise rollout, prefer managed MCP configuration so the server list and permissions do not drift across machines.

Step 4: set the permission rule. Default to read-only. If write actions are needed, require explicit human approval for each action and name the allowed verbs, such as create draft issue comment or update local branch metadata.

Step 5: write the team convention. Record the owner, allowed tasks, blocked tasks, and review evidence. This is the part that makes the setup repeatable for Claude Code for teams rather than a local experiment.

Step 6: verify with a harmless task. Ask Claude Code to use the server for a task that cannot damage anything, such as summarize the linked issue for the current branch and list the files it inspected. The setup works when the answer includes useful context, the tool use is visible, and no blocked action was attempted.

Paste this integration checklist

# MCP integration note

Integration name:
Repo or team:
Owner:
External system:
Server package or endpoint:

Purpose:
- 

Default permission mode:
- [ ] Read-only
- [ ] Write allowed only with explicit human approval
- [ ] Write blocked

Allowed Claude Code tasks:
- 
- 

Blocked actions:
- 
- 

Data limits:
- No secrets
- No production customer data unless approved by policy
- No broad workspace search unless the task needs it

Review evidence required:
- Tool calls are visible in the session
- Files changed by Claude are reviewed in diff
- External actions are listed in the PR or handoff note

Verification task:
- Ask Claude Code to use the MCP server for one harmless context lookup and explain what it read.

Rollback plan:
- Disable the server in Claude Code configuration
- Revoke external token or credential
- Notify the owner named above

This artifact is intentionally dull. A good MCP note should be easy to audit six weeks later, when someone asks why Claude can reach a system at all.

Further reading

Run one small integration

Pick one repo, one external system, and one read-only task, then paste the checklist into the PR or setup note that adds the server. For a guided version, use our hands-on training on Claude Code team setup and review practice.