Reference — security and data handling for Affinity MCP.
The server is stateless
The hosted MCP server doesn’t store your data. Every tool call is proxied to the Affinity API in real time.- No CRM records, notes, emails, or meeting content are persisted by the MCP server.
- Credentials (OAuth tokens and API keys) are not retained beyond what’s needed to authenticate the in-flight request.
Affinity doesn’t see your prompts
Your conversation with your AI tool stays between you and your AI provider. The MCP server only receives the structured tool calls your AI client decides to make — for example,search_companies_top_matches(query: "fintech") — not the natural-language prompts you typed. Your prompts and the AI’s responses are governed by your AI provider’s own data-handling policy.
Every call runs with your permissions
Tool calls execute as the authenticating user. List access, role permissions, and field-level visibility all apply.- You can’t read, create, update, delete, or merge anything through MCP that you couldn’t do directly in Affinity.
- There is no MCP-only privilege escalation.
- Permission changes (removing a user from a list, changing a role) take effect on the next tool call.
Limiting a connection to read-only
MCP can create, update, delete, and merge records, so you may want some connections to be read-only. Two options:- At OAuth consent: when you first authorize, uncheck the write scope to grant read-only access. All create, update, and delete calls are then blocked for that connection.
- In the AI client: some clients (for example, Claude) let you block individual tools — turn off the write, delete, and merge tools to keep a connection read-only, or turn off only the delete tools to allow edits but not deletion. Users or their AI-client admins can do this in the AI client’s settings.
Deletes and merges
MCP can delete list entries, opportunities, companies, people, and notes, edit notes, and merge duplicate people and companies. If you connected before September 24, 2026, restart your AI client or start a new session to load these tools.- Every delete and merge shows you what it will affect and waits for your explicit confirmation. Each merge needs its own approval.
- Deletes can’t be undone. Data-recovery options are the same as for deletes made in Affinity.
- Global (Affinity-enriched) companies can’t be deleted. Deleting an entry on an opportunity list deletes the opportunity itself.
- You can edit or delete only notes you created, and a note with @mentions can’t be edited. Deleting a note also deletes its replies and attached files.
- Merging people requires an org admin with the Manage Duplicates permission.
- Merges made through MCP appear in Settings → Duplicate Management → Merged, where an admin can undo a merge of local records. A merge involving a global company can’t be undone.
Admin controls
- Enable or disable MCP per client. MCP is available by default for Claude, ChatGPT, and Notion. An admin can turn each OAuth client on or off for the org under Settings → Affinity MCP. Turning a client off disconnects everyone in your organization who connected it through OAuth. It only affects OAuth connections: users can still connect a client manually with an API key. Each person can also disconnect from inside their AI client.
- Choose who manages these settings (Enterprise). The Manage MCP Agents permission, under Settings → Users & Permissions → Roles, controls which roles can change the Settings → Affinity MCP toggles (Enterprise Admins and Admins by default). It doesn’t limit who can use MCP.
- Manage API keys. Create API keys under Settings → Manage Apps (click + New App, then API Key if a menu opens), and revoke them there too. You can have more than one active key, so give each client its own key; revoked keys stop working immediately.
Hosted vs local
The hosted server (https://mcp.affinity.co/mcp) supports OAuth (with the read-only option) or an API key. The local server runs on your own machine over STDIO and uses an API key stored in a local config file — treat that file like a password and keep it off shared machines.
For the developer-level detail, see Security at developer.affinity.co.