Skip to content

Limited-time launch: lifetime access from $49.

View lifetime deal

Connect Claude and ChatGPT to a support inbox via MCP

Udit Goenka
Udit Goenka

Connect Claude and ChatGPT to a support inbox via MCP, step by step from official docs, plus a safe first-week triage routine.

TL;DR: To connect Claude or ChatGPT to a support inbox, you add your help desk's remote MCP server as a custom connector, sign in with OAuth, and then set which tools may run without asking. In Claude you use Customize > Connectors, or the claude mcp add command in Claude Code. In ChatGPT you turn on developer mode and create an app from the server URL. Start read-only, ask for summaries and drafts, let people send replies, and treat every ticket as untrusted text.

This guide is written for the cautious operator, the person who has to turn a connector on and live with it on Monday morning. Every setup step below comes from the vendors' own documentation as of October 2026, and I note where an interface label may differ from yours. If you are new to the protocol, the MCP server guide for customer support explains what a server and a tool are before you start.

One clarification belongs up front. communicate.so publishes a small MCP server, but it is a read-only documentation and API discovery server and does not expose your inbox. The worked example here uses Intercom's official MCP server, because its documentation is public and specific. The steps for Claude and ChatGPT are the same for any remote server, so you can substitute your own help desk.

Different help desks differ in what their servers allow, as the comparison of help desk MCP servers shows. Check your vendor's current documentation before you copy any endpoint from this page.

Before you connect: what you are handing the assistant

A support inbox has the same three ingredients that Simon Willison calls the lethal trifecta. It holds private customer data, it contains text written by strangers, and with a send tool connected it can communicate outward. Willison's advice for people who mix tools is that "the only way to stay safe there is to avoid that lethal trifecta combination entirely."

You cannot remove the first two from a support inbox, so the practical move is to remove the third. Connect the server for reading and drafting, and keep sending in human hands. That single decision shrinks most of the risk in this guide.

Both vendors warn you in their own words. Anthropic's connector documentation says in a security notice that "custom connectors allow connections to unverified services." OpenAI's developer mode page calls the feature "powerful but dangerous" and tells users to watch for prompt injection, model mistakes on write actions, and malicious MCPs.

OpenAI's guide to building MCP servers goes further and names your exact use case. For a customer support MCP, it says, "an attacker could send you a customer support request with a prompt injection attack." Assume that some of the tickets you read will contain text meant to steer the assistant.

Keep the security guide open as you work through setup. The MCP security guide for support agents explains scopes, tokens, and audit logs, and this article applies them to a first connection.

Choose the server and note its limits

Start with the vendor's own documentation, not a third-party list. Intercom's developer page describes a remote MCP server that follows the authenticated remote MCP specification. It gives separate endpoints by data region.

Item to checkIntercom example, as of October 2026Why it matters
Endpointhttps://mcp.intercom.com/mcp for US workspacesYou paste this URL into the client
EU endpointhttps://mcp.eu.intercom.com/mcpRequests are processed in the EU for EU-hosted workspaces
Unsupported regionAU-hosted workspaces are not yet supportedThe connection will fail for those workspaces
TransportStreamable HTTP recommended, SSE deprecatedUse the /mcp path, not the legacy /sse path
AuthenticationOAuth, scoped to your existing Intercom permissionsThe assistant can see only what your user can see
ToolsThe docs list 14, including search and fetchMore tools mean more to review

Treat the table as a snapshot, because this area moves quickly. Intercom's MCP documentation lists 14 tools today, while an older README in the company's GitHub repository still describes six tools and US-only support. Whenever two sources disagree, trust the one on the vendor's developer site, and check the date.

Read the tool list before you connect anything. Intercom's integration page says the server provides read access to conversations, contacts, and companies, plus read and write access to Help Center articles. That tells you a write path exists even though your use case is triage, so you will want to control it.

If your inbox is communicate.so's shared inbox, note that no inbox MCP server is published as of October 2026. The shared inbox is where AI and human replies are managed together, and the published MCP server stays limited to documentation.

Add the server to Claude

Claude connects to remote servers from Anthropic's cloud infrastructure, not from your device. Anthropic's help center states this applies across claude.ai, Claude Desktop, Cowork, and the mobile apps. The practical effect is that the server must be reachable on the public internet, and a server on your laptop will not work through this route.

For an individual Free, Pro, or Max account, the steps in Anthropic's documentation are short.

  • Open Customize and then Connectors.
  • Choose Add custom connector. The help center describes a plus button that opens this option.
  • Enter the remote MCP server URL, for example the Intercom endpoint for your region.
  • Optionally open Advanced settings to enter an OAuth client ID and secret, if your vendor gave you one.
  • Click Add, then complete the vendor's sign-in page when Claude sends you there.

On Team and Enterprise plans, an Owner adds the connector for the organization. The documented path is Organization settings, then Connectors, then Add, then Custom, then Web. Members then connect with their own account, and organizations can disable custom connectors entirely, as described in the Anthropic help center article.

The Free plan allows one custom connector, according to Anthropic's page on connectors that are not in the directory. If the Add option is grayed out on a work plan, an administrator has likely turned custom connectors off. Ask them rather than looking for a workaround.

For Claude Code, you add a remote server from the command line. The Claude Code MCP documentation gives the syntax as claude mcp add --transport http followed by a name and a URL, and it recommends HTTP servers for remote services.

For the Intercom US endpoint, the command looks like this: claude mcp add --transport http intercom https://mcp.intercom.com/mcp. Claude Code prints a confirmation and the file it modified. The quickstart in the same docs describes a connected status as the ready state, and says claude mcp get with the server name shows error detail when tools fail to load.

Claude Code also supports a project file named .mcp.json that you can commit for a team. For an HTTP server, the entry takes the form {"mcpServers": {"intercom": {"type": "http", "url": "https://mcp.intercom.com/mcp"}}}. The documentation notes that connectors you add on claude.ai load in the command line automatically when you sign in with the same account.

Open the connector's page after adding it. You should see the tool list, and you should be able to connect your account. Do not start a conversation until you have set permissions in the next section.

Add the server to ChatGPT

ChatGPT treats custom MCP servers as developer features. OpenAI's developer mode documentation describes the sequence for an individual account.

  • In ChatGPT, open Settings, then Security and login, and turn on Developer mode.
  • Go to ChatGPT Plugins, select the plus button, and create a developer-mode app for your remote MCP server.
  • Enter the server URL. The supported protocols are SSE and streaming HTTP.
  • Choose the authentication mode. OAuth, no authentication, and mixed authentication are supported.
  • Find the new app under Drafts in the app settings, and open its details page.

The labels in this area have changed over time, and the page I read uses the plugins wording. If your account shows apps or connectors instead, follow the same idea. Developer mode is on, and you create an app that points at the server URL.

Workspaces on Business, Enterprise, and Edu plans add an admin step. The OpenAI help center article says workspace admins must first enable developer mode in workspace settings, under Permissions and Roles, then Connected Data, in the developer mode toggle or the option to create custom MCP connectors.

The same article says OpenAI-built apps are search-only today and do not support write actions, and that custom MCP apps are the route for write or modify capabilities. It also says some especially risky actions may be blocked instead of being presented for approval. If you are on a managed workspace, ask your admin how developer mode is configured.

To use the app in a conversation, choose Developer mode from the plus menu in the composer and select the app for that chat. OpenAI's page suggests being explicit with the model, for example by naming the app and the tool, and by telling it not to use other tools. That habit also keeps a triage chat from wandering into web browsing.

Set tool permissions before the first message

Both products let you control which tools run. This is the most important setup step, and it is the one people skip. Do it before you type a question.

Anthropic's custom connector guide says Claude asks for approval before it uses a connector tool. You can click Allow always on an approval request, and the guide advises doing that only for servers and tools you trust to run unsupervised. You can also switch individual tools off for a conversation from the Search and tools menu.

One exception matters: in Research, the guide says Claude can call connector tools without asking again.

In ChatGPT, the app details page lets you toggle individual tools on or off and refresh the app to pull new tools and descriptions from the server. Write actions require confirmation by default, and OpenAI says it respects the readOnlyHint annotation, so tools without that hint are treated as write actions. You can expand the tool call card to see the full JSON input and output.

ControlClaude (claude.ai)Claude CodeChatGPT developer mode
Add by URL✓✓✓
OAuth sign-in to the vendor✓✓✓
Per-tool allow, ask, or block✓✓✓
Confirmation on write actions by default✓✓✓
Works for a server on your own machine✗✓✗
Needs an admin to enable on managed plans✓✗✓

I mark the last two rows from the vendors' descriptions, but treat the Claude Code permission details as something to confirm in your own session. Permission handling differs by client version, and a feature you rely on should be tested once with a harmless tool. A habit of testing the guard before trusting it is worth more than any table.

For a first week, a sensible configuration looks like this.

  • Allow search and fetch tools to run, because reading is what you want.
  • Never click Allow always on a tool that creates, updates, or sends, and switch it off when you do not need it.
  • Block anything that edits Help Center content unless you are doing that task on purpose.
  • Leave the skip-approvals option off for the entire first week.

The reasoning behind those choices is in the guide to runtime authorization for agents. It covers budgets, risky tool pairs, and idempotency keys for the days when you do allow writes.

Your first triage prompts

Start with questions that only need reading. The goal is to learn what the connection returns and how the assistant behaves, before it touches anything. Intercom's documentation shows the search tool taking a query in a compact syntax that you can reuse.

The Intercom documentation gives examples such as object_type:conversations state:open source_type:email, and object_type:conversations source_body:contains:"refund" limit:20. You do not need to type the syntax yourself, since the assistant builds the query from your request. Knowing it helps you read the tool call card and check what was searched.

Here are prompts I would use in order, each a little broader than the last.

  • Search open email conversations from the last two days and list the five most common topics, with a count for each.
  • Find open conversations that mention a refund, and summarize what each customer is asking in one sentence.
  • Show conversations that look urgent, and explain which words in the message made you flag them.
  • For the three oldest open conversations, summarize the history and suggest the next step, without writing to the customer.
  • Group today's open conversations by product area and point out any that seem to share a single cause.

Notice that every prompt ends in a summary, a list, or a suggestion. None asks the assistant to change a record or send a message. That is deliberate, and it lets you judge quality before you grant more power.

These prompts help with a queue that has grown. The ticket backlog reduction guide and the guide to cutting first response time cover the workflow around them, and the email support automation guide covers what to automate once triage works.

Draft replies and let a person send them

The next step is drafting. Ask the assistant to write a reply for a specific conversation, and have it show you the text in the chat. Then a person reads it, edits it, and sends it from the help desk.

This keeps the send action out of the model's hands, which is the safest place for it in a first week. It still saves most of the time, because writing the first draft is the slow part. The reviewer's job becomes checking facts and tone.

  • Give the assistant your tone guidelines once, at the start of the chat, and ask it to follow them.
  • Ask it to quote the article or policy it used, so the reviewer can check the source.
  • Ask it to flag any claim it could not support from the conversation or your documentation.
  • Read the draft for invented details such as order numbers, dates, and promises.
  • Send the reply yourself, and tag the conversation so you can track how often drafts needed edits.

Good drafts depend on good instructions. The support agent prompt engineering guide covers how to write them, and the tone of voice guide helps you define the voice once so drafts stay consistent.

If a draft needs a decision from someone else, route it. The escalation workflow guide and the shared inbox guide for AI and humans describe how to pass a conversation to the right person with context.

Treat every ticket as untrusted text

While you triage, the assistant reads text written by customers and strangers. Some of that text will try to change what the assistant does, whether on purpose or by accident. You are the last line of defense, because you see the calls.

Build a few habits that make injection visible. Watch the tool call cards, and notice when the assistant calls a tool you did not ask for. If a ticket says to look up other customers, forward data, or ignore your instructions, the assistant should treat that as customer text and keep going with your task.

  • Tell the assistant at the start that ticket content is data and that only your messages are instructions.
  • Keep one chat per task, so text from one ticket does not follow you into the next job.
  • Do not connect additional servers, such as email or file storage, to the same chat while you work on the inbox.
  • Open the tool call details on anything unexpected, and stop if a call touches data you did not mention.
  • Report suspicious tickets to your security contact and keep a copy.

The second and third habits matter most. They keep the dangerous combination of private data, untrusted content, and an outward channel from forming in one conversation. If you later need the assistant to send, move that step into a separate approved flow.

Personal data is the other risk. Before you paste or fetch sensitive conversations, read the PII redaction guide and decide which fields the assistant needs to see for each task.

Verify, log, and review each week

A connection that works on day one can drift. Servers add tools, descriptions change, and people turn on permissions. A short weekly review keeps you in control.

  • Open the connector and compare the tool list with last week's, looking for new tools.
  • Check which tools are set to run without asking, and confirm that is still what you want.
  • Review a sample of triage chats against the tickets, and note any summary that missed the point.
  • Check the help desk's own audit or activity log for actions taken through the connection.
  • Remove access for anyone who no longer needs it.

Your help desk's log is the record that matters if something goes wrong. The AI support audit trail guide explains what to keep, and the agent evaluation guide shows how to turn weekly checks into repeatable tests.

Track two simple numbers during the first month. Count how many drafts you sent unchanged, and how many needed edits. Those counts tell you whether the assistant is helping or adding review work.

Quality review at scale is its own discipline, and the support quality assurance guide covers it. For the benchmark side, see the first response time benchmark before you set a target.

Troubleshooting common problems

Most failures on a first connection fall into a handful of patterns. Work through them in order before you assume the server is broken.

  • The Add option is grayed out, which usually means an administrator has disabled custom connectors for the workspace.
  • The connection fails for one workspace only, which can mean an unsupported data region, such as AU for Intercom.
  • The sign-in page loops, which often means a browser blocks pop-ups or third-party cookies for the vendor.
  • No tools appear, which can mean the server loaded but could not list tools. In Claude Code, claude mcp get with the server name shows detail.
  • The tool list looks out of date in ChatGPT. Refresh the app on its details page to pull new tools and descriptions.
  • A local server does not work in the web apps, since Claude connects from Anthropic's cloud and cannot reach your machine.
  • An old SSE path fails, so switch to the streamable HTTP endpoint ending in /mcp.

If none of these apply, test the endpoint with the MCP inspector, which the vendor documentation suggests. A server that works in the inspector but not in a client points to a client or plan setting. A server that fails in both points to the endpoint or your credentials.

When you build or tune your own server, the lessons run the other way. The help center MCP server guide shows what a small public server looks like, and the tool curation guide explains how to keep the tool list short.

When a general assistant is the wrong tool

Chat-based triage is a good way to start, and it has limits. It depends on one person's session, it does not run on a schedule, and it relies on that person to watch every call. Those traits are fine for a pilot and awkward for a team.

A purpose-built agent changes the shape. It runs inside the help desk with scoped permissions, it hands off to people through a defined path, and it keeps a record of every action. The trade-off is setup effort, and you give up the flexibility of asking anything in a chat window.

The comparison of AI chatbots and agents explains the difference, and the guide on when not to use AI support lists the cases where neither belongs, such as sensitive disputes that need a person from the start.

If you decide to move from a chat pilot to a standing agent, communicate.so's AI agents page shows how a workspace agent is configured, and the human handoff guide covers how conversations move to your team.

A sample first-week plan

A plan keeps the pilot honest. The schedule below is an illustration of how I would pace it, not a result from a real deployment. Adjust the days to your queue size.

  • Day one. Add the server to one client, set every write tool to Block, and run the first three read-only prompts on open conversations.
  • Day two. Compare the assistant's summaries with ten tickets you read yourself, and write down every miss.
  • Day three. Add a tone guide to the chat and ask for drafts on five low-risk conversations. Edit them and send them yourself.
  • Day four. Test one hostile ticket that you write yourself, containing an instruction aimed at the assistant, and note whether it follows it.
  • Day five. Review the tool list and the help desk activity log, then decide whether any tool you switched off should be turned back on with approval prompts.

The hostile test on day four is worth the effort. You learn how your chosen client behaves before a stranger runs the same experiment for you. Write the test ticket in a sandbox or a test inbox, not in a live customer thread.

At the end of the week, write a one-page note for your team. List what the assistant did well, what it got wrong, and which permissions you granted. That note becomes the start of your policy.

Write a short team policy

Once more than one person uses the connection, informal habits stop working. A short policy removes guesswork. It can fit on a single page.

  • Who may add or change connectors, and who approves new ones.
  • Which tools may run without asking, listed by name.
  • Which actions always need a person, such as sending, closing, refunding, and editing public articles.
  • Which data categories must not be pasted into a chat.
  • Where the audit record lives and who reviews it each week.
  • How to report a suspicious ticket or an unexpected tool call.

Treat the policy as a living document and date it. The guide to AI agent guardrails covers the rules an agent must follow and how to review them.

Keep the list of approved connectors short. Every added server brings its own tools, descriptions, and failure modes. Two well understood connectors are safer than six that nobody reviewed.

Which client should you start with

Both clients can do the job. The choice usually comes down to where your team already works and who controls the account. Here are the questions I would ask.

  • Does your organization already pay for Claude Team or Enterprise, or for a ChatGPT Business workspace? Start where an admin already manages access.
  • Does anyone need a local or private-network server? Claude Code can reach one, while the web apps connect from the vendor's cloud.
  • Does the team want a terminal workflow with scripts and a committed project file? Claude Code with a .mcp.json file fits that.
  • Does the workspace admin allow developer mode? If not, you cannot start in ChatGPT until they do.

You can run both clients against the same server and compare. Use the same prompts, the same tickets, and the same permission settings, then judge the summaries and drafts side by side. Keep the comparison small and time boxed.

If you want to see how results hold up over time, the agent evaluation guide describes a simple scoring routine you can reuse for each client.

What to record about your own setup

Your setup will differ from the one in this guide, because vendors change labels and limits. Keep a short record so the next person does not repeat your detective work.

  • The date, the client version, and the server URL you connected.
  • The exact menu path you used, since labels change between releases.
  • The permission setting for each tool and the reason for it.
  • Any error you hit and what fixed it.
  • The link to the vendor documentation page you followed.

That record also helps during an incident. If a strange message appears in a customer thread, you can check which tools were enabled on which date.

Frequently asked questions

Can I connect Claude to my support inbox?

Yes, if your help desk publishes a remote MCP server. Add it as a custom connector in Claude by entering its URL, then sign in with the vendor. In Claude Code, use the claude mcp add command with the HTTP transport.

Can ChatGPT connect to a help desk MCP server?

Yes, through developer mode. Turn it on in Settings under Security and login, then create an app from the server URL. Business and Enterprise workspaces need an admin to enable developer mode first.

Does communicate.so have an inbox MCP server?

As of October 2026, its published MCP server is read-only and covers developer documentation and API discovery. It does not expose workspace conversations or product actions. The shared inbox is a product page, not an MCP connection.

Which help desks have official MCP servers?

Several do, and the list changes often. Intercom documents one with US and EU endpoints. See the comparison of help desk MCP servers and check each vendor's own documentation for the current state.

Do I need a paid plan?

It depends on the client and your plan. Anthropic documents custom connectors across Free, Pro, Max, Team, and Enterprise plans, with limits such as one custom connector on Free. OpenAI developer mode availability depends on plan and workspace settings, so check the help center.

Is it safe to let an assistant read my customer tickets?

It is safe enough when you control the permissions and the data. Start with read-only tools, keep sending in human hands, and treat ticket text as untrusted. The security guide explains the risks in detail.

What is the safest first setup?

Allow search and fetch tools, set every write tool to ask or block, and leave skip-approvals off. Use one chat per task and connect no other servers to it. Review the tool list weekly.

Can the assistant send replies for me?

It can if you connect a send tool and allow it. I recommend that you do not in the first week. Have it draft, and have a person send.

What is a prompt injection in a ticket?

It is text in a message that tries to give the assistant instructions, such as asking it to reveal other customers' data. Models cannot reliably tell instructions from content, according to Willison. Tell the assistant that ticket text is data, and watch the tool calls.

Why does Claude need a public server?

Anthropic's help center says Claude connects to your remote MCP server from Anthropic's cloud infrastructure, not from your device. A server that is reachable only on your machine or your private network will not connect through claude.ai. Claude Code can reach local servers.

Why is my Add custom connector option disabled?

On Team and Enterprise plans, your organization may have turned custom connectors off. Anthropic's documentation says the options are grayed out with a note when an admin has disabled them. Ask your administrator.

What does developer mode do in ChatGPT?

It enables full MCP client support, including write tools, for custom apps. OpenAI describes it as powerful but dangerous and intended for people who can configure and test apps safely. Write actions require confirmation by default.

How do I limit which tools run?

In Claude, approve each tool call when asked, use Allow always only for tools you trust, and switch tools off per conversation from the Search and tools menu. In ChatGPT, toggle tools on or off on the app's details page. Both products ask before acting by default, with exceptions such as Claude's Research mode.

Which region endpoint should I use?

Use the one for your help desk's data region. Intercom lists a US endpoint and an EU endpoint, and says AU workspaces are not yet supported. Check your vendor's documentation for the equivalent.

Should I use SSE or streamable HTTP?

Use streamable HTTP when the server offers it. Intercom marks its SSE endpoint as deprecated, and Anthropic says the older HTTP+SSE transport is being deprecated in favor of streamable HTTP. ChatGPT supports both.

How do I disconnect the server?

Remove the connector in Claude's connector settings, or delete the app in ChatGPT, and revoke the authorization in your help desk's connected apps list. In Claude Code, the claude mcp remove command removes a server by name. Do all three if you want the access fully gone.

How should I test before trusting it?

Run read-only prompts on a small, low-risk slice of tickets, and compare the output with the tickets themselves. Try one test ticket that contains an instruction, and see what the assistant does. Expand only when the results hold up.

Can several people share one connection?

On managed plans, an Owner or admin adds the connector and members connect with their own accounts. That means each person sees only what their help desk role allows. Avoid sharing one login among several people.

What if the tool list changes?

Review it. New tools can add new powers, and a changed description can change behavior. Refresh the app in ChatGPT to pull changes, and check the connector page in Claude.

When should I move from a chat pilot to a real agent?

When the work needs to run without one person watching, or when more than one team depends on it. A workspace agent with scoped permissions and handoff rules fits that better. The pilot teaches you what to automate.

Start read-only, then earn more access

Connecting an assistant to your inbox takes minutes, and the setup that matters is the permission and habit work around it. Add the server, set every write tool to ask or block, run read-only prompts, let people send replies, and review weekly. When you are ready for a standing agent with handoff and records, start with the shared inbox where AI and your team work side by side.