ai
Using Claude with your CRM via MCP: setup, example prompts and permissions
What MCP is in plain language, how to connect Claude to SparkDesk, prompts that map to real tools, and how permissions and the request log keep it accountable.
By SparkDesk team
AI assistants are good at reading, summarizing and drafting. Until recently, they could not do much with the system where your client work actually lives. You could paste a spreadsheet into a chat, but the assistant could not look up an account, start a timer or draft an invoice.
The Model Context Protocol (MCP) changes that. This article explains what MCP is, how to connect Claude to SparkDesk, what you can ask it to do, and how permissions and logging keep it accountable.
What MCP is, in plain language
MCP is an open standard that lets an AI assistant use tools provided by another application. The application publishes a set of tools (“search records”, “record a payment”, “run a report”), each with a clear description of its inputs. The assistant reads those descriptions, decides which tool fits your request, and calls it.
A useful way to think about it: MCP gives the assistant the same buttons you have, described in words it can understand. It does not give the assistant direct access to your database, and it does not let it bypass the application’s rules.
For a CRM, that means you can ask in plain English for things you would otherwise click through several screens to do.
What you need
- A SparkDesk workspace. The MCP server and REST API are included on every plan at no extra cost.
- Claude, or another AI assistant that supports custom MCP connectors. ChatGPT and other MCP clients work too.
- A SparkDesk user with permission to do the things you plan to ask for.
Setup: five steps
- Copy the MCP URL. In SparkDesk, go to Settings > Integrations > API Keys > Connected apps. The MCP server URL is shown there. Copy it.
- Add a custom connector in Claude. In Claude, add a new custom connector and paste the URL.
- Sign in. Claude opens a SparkDesk sign-in. Sign in with your normal account. There is no API key to copy.
- Approve the connection. Review what the connection can do and approve it.
- Pick the organization. If you belong to more than one SparkDesk workspace, choose which one this connection works in.
That is it. You can review and disconnect connections at any time from the same Connected apps page.
If you use an MCP client that cannot sign in with OAuth, you can create a personal API key in Settings > Integrations > API Keys and pass it to the client instead. The API & MCP reference covers both options.
What the assistant can do
By default, SparkDesk exposes a lean set of about 60 tools across CRM, projects, time, invoices, transactions and reconciliation, forms, Flows, custom objects, reports and admin settings. A consolidated set of record_* tools (search, get, create, update, delete, delete preview, restore) covers most record types with one set of verbs, and each area adds tools for the actions that are specific to it.
Here are example prompts and the tools behind them:
| You ask | Tool the assistant uses |
|---|---|
| “Find every open opportunity for Northwind and summarize where each one stands.” | record_search |
| “Convert the lead from yesterday’s web form into a new account and contact.” | lead_convert |
| “Start a timer on the Harbor website project, task: homepage copy.” | timer_start |
| “Stop my timer and tell me how long I worked.” | timer_stop |
| “Create a draft invoice for the Harbor project from its unbilled hours.” | invoice_generate_from_hours |
| “Record a 2,500 bank transfer payment against invoice INV-2026-0042.” | invoice_record_payment |
| “Run our saved overdue invoices report and list anything more than 30 days late.” | report_run |
| “Export the signed contract for Northwind as a PDF.” | contract_export |
The names are real tool names from the SparkDesk MCP server. In practice you do not need to know them; you just ask, and the assistant picks the tool. Before writing a record, a well-behaved assistant will usually call metadata_get_object to learn which fields exist, which are required and which values are allowed.
A few things worth knowing:
- Invoices are drafted, not sent automatically.
invoice_generate_from_hourscreates a draft from the project’s unbilled, invoice-eligible time. You review it before it goes to the client. - Payments are recorded, not collected.
invoice_record_paymentrecords a payment you received and updates the amount due. SparkDesk does not take payments online. - Deletes can be previewed and undone.
record_delete_previewshows what a delete would affect, and deleted records go to trash whererecord_restorecan bring them back.
For more on the billing side, see how to invoice from timesheets.
The permissions model
This is the part that matters most for a team.
The assistant runs as you. An OAuth connection uses your role and your permissions in SparkDesk. If you cannot see an account in the app, the assistant cannot see it either. If your role cannot create invoices, the assistant cannot create invoices. Admin-only tools return a permission error for anyone who is not an admin.
Flow permissions apply too. Roles control who can build, clip and run Flows, and those same rules apply to requests made through MCP.
Personal keys behave the same way. A personal API key runs with your exact role and permissions. Service keys, which act at the organization level, can only be created by Admins and Owners.
This means you can let everyone on the team connect their own assistant without creating a new security problem. A contractor’s assistant sees what the contractor sees, and nothing more. You can read more on the permissions and security page.
The request log
Every API and MCP request, including errors, is recorded once in a request log: the client (API or MCP), the MCP tool, who made the request, which key or connection, the record, the result and how long it took. You can review it in the API & MCP Activity report.
Admins see their whole organization’s activity. Other members see their own. Writes made through the API and MCP are also recorded on each record’s timeline, so “who changed this?” has an answer even when the change came from an assistant.
Tips for getting good results
- Be specific about the record. “The Harbor website project” works better than “that project”.
- Ask for a preview first. “Show me what you would put on the invoice before creating it” is a good habit for anything that writes data.
- Start with read-only questions. Searching, summarizing and running reports are a low-risk way to get comfortable.
- Review the activity report weekly for the first few weeks, especially if several people have connected assistants.
MCP and Orbit
SparkDesk also has Orbit, an in-app assistant that works inside SparkDesk itself. MCP is for when you want to work from Claude, ChatGPT or another assistant you already use. Both work under your permissions. More on both on the AI page.
Try it in your own workspace
Connect Claude to a SparkDesk workspace and ask it to summarize your open opportunities. Start a 14-day free trial, no card needed.
