How to Connect Claude Code to Company MCP Servers for a Whole Team

Last updated ·Read as Markdown
Answer

Claude Code adds MCP servers with the claude mcp add command and stores them in local, project, or user scope. The project scope writes a shared .mcp.json file, which is convenient for a team but tempts people to commit API keys. For a team, point that file at one managed MCP endpoint instead. Each person signs in to the company apps with their own account, an admin filters the tools, and every call is logged. With Metorial, that endpoint is a Magic MCP URL.

Claude Code makes it easy for one developer to add an MCP (Model Context Protocol) server. The difficulty starts when twenty people need the same company apps, each with their own access and no keys pasted into the repository.

If you are
Use
One developer trying a server
claude mcp add in local scope
A repo whose team shares the same servers
Project scope, which writes .mcp.json
One person using a server in every project
User scope
A team that needs per-person access and logs
One managed endpoint referenced from .mcp.json

How does Claude Code configure MCP servers?

You add a server from the command-line interface (CLI) with claude mcp add. The --transport flag sets how Claude Code talks to the server, and --scope sets where the definition is stored.

claude mcp add --transport http notion https://mcp.notion.com/mcp
claude mcp add --env KEY=value --transport stdio myserver -- npx server

Claude Code documents three main transports. http is recommended for remote servers, sse is deprecated, and stdio runs a local process on the person's machine. There are three scopes:

  • local is the default. It applies to the current project, is stored in ~/.claude.json, and is not shared.
  • project is stored in a .mcp.json file in the project root and is shared through git. Claude Code asks for approval before using servers from it in an interactive session.
  • user is stored in ~/.claude.json and loads in every project, but is not shared.

If the same server is defined in more than one scope, local wins over project, and project wins over user.

Why does this break down for a team?

Project scope is the shared option, which is where the trouble starts. The .mcp.json file accepts headers and env values, so the quickest way to make a server work for everyone is to paste a key into it. That key is committed, copied to every clone, and carries the permissions of whoever created it.

The alternative, where each person adds their own local servers, avoids the shared key but gives each person a different setup with their own credentials. Nobody can tell what is installed on which laptop, and nothing records who called what.

Claude Code can expand variables such as ${API_KEY} inside .mcp.json, so the file does not have to contain the secret. That keeps the value out of git. It does not fix the other problems: each person still has to obtain a key, and the key still has one set of permissions.

How do you set it up for a whole team?

The pattern is to commit one endpoint reference and let a managed endpoint handle identity, tools, and logs.

1. Choose the integrations and filter their tools. In Metorial, add the apps the team needs. In Tool Filters, allow the read tools and reject the rest to begin with.

2. Create a group and allow it. Under Access, select Groups, create a group for the team, and allow it on each integration.

3. Publish the integrations in a portal. In a portal, list each one as user-configured, so each person connects with their own credentials.

4. Have each person sign in and connect. People open the portal, sign in, and authorize each app with their own account.

5. Commit one shared reference. In .mcp.json, point to the endpoint through an environment variable rather than a literal URL:

{
  "mcpServers": {
    "company-tools": {
      "type": "http",
      "url": "${METORIAL_MCP_URL}"
    }
  }
}

Each person sets METORIAL_MCP_URL in their own shell to the Magic MCP server URL, so the value never lives in the repo. Metorial's documentation says to keep a server's endpoint and access token private, so treat the URL as a secret and do not commit its value.

6. Check the first call. In Claude Code, run /mcp to see the server's status. Ask for something specific, then find the call under Connection Logs, Tool Calls.

How do you keep it least-privilege?

Start with read-only tools and add write tools one at a time, as described in How to restrict AI agents to read-only tools. Because each person signs in with their own account, Claude Code can reach only what that person can reach in the app. For per-person access without keys, see How to connect AI agents to company apps without sharing API keys.

Claude Code also has its own controls. Its documentation describes administrator allowlists and denylists for servers, named allowedMcpServers and deniedMcpServers, which can match a server by name or URL. Use them to make the managed endpoint the one approved route.

What does it look like in Metorial?

An admin creates a portal for the team and publishes the approved integrations. Each integration has Tool Filters that limit what the tools can do, and groups that decide who sees it. People sign in to the portal, connect their own accounts, and receive a Magic MCP URL. Claude Code reaches every approved app through that one URL.

Under Connection Logs, the Sessions and Tool Calls tables show each call's tool, arguments, and result, and Tool Errors lists the failed ones. For background on the protocol itself, see What is MCP?.

Frequently asked questions

Which scope should a team use in Claude Code?

Use project scope for the shared server definition, because it is stored in .mcp.json in the project root and shared through git. Use local or user scope for anything personal. Keep secrets out of the project file, and reference them as environment variables instead.

Can I put an API key in .mcp.json?

Claude Code supports environment variable expansion such as ${API_KEY} in .mcp.json, so the file can reference a key without containing it. That keeps the value out of git, but each person still has to obtain and store a key, and it still carries one set of permissions.

Do I need a separate setup for each person?

Only a short one. The shared .mcp.json is committed once. Each person signs in to their company apps in a portal and sets their own endpoint URL as an environment variable.

Which transport should I use for a remote server?

Claude Code documents http as the recommended transport for remote servers. The sse transport is listed as deprecated, and stdio is for local processes that run on the person's own machine.

How do I see what Claude Code did through the endpoint?

In Metorial, open Connection Logs and select Tool Calls to see each call with its tool name, status, session, and result. Select a row to open the session and the call details.

Sources

  1. Claude Code documentation: Connect Claude Code to tools via MCP
  2. Metorial documentation: Set up a Magic MCP server
  3. Metorial documentation: Review connection logs

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.