Skip to main content
Reference — security and data handling for Affinity MCP.
Affinity MCP is built on the same authentication, permissioning, and data-handling controls as the Affinity API. The MCP layer doesn’t add new ways to read or change data — every request goes through the Affinity API as the authenticated user. For certifications, data residency, and incident response, see the Affinity Trust Center.

The server is stateless

The hosted MCP server doesn’t store your data. Every tool call is proxied to the Affinity API in real time.
  • No CRM records, notes, emails, or meeting content are persisted by the MCP server.
  • Credentials (OAuth tokens and API keys) are not retained beyond what’s needed to authenticate the in-flight request.

Affinity doesn’t see your prompts

Your conversation with your AI tool stays between you and your AI provider. The MCP server only receives the structured tool calls your AI client decides to make — for example, search_companies_top_matches(query: "fintech") — not the natural-language prompts you typed. Your prompts and the AI’s responses are governed by your AI provider’s own data-handling policy.

Every call runs with your permissions

Tool calls execute as the authenticating user. List access, role permissions, and field-level visibility all apply.
  • You can’t read, create, update, delete, or merge anything through MCP that you couldn’t do directly in Affinity.
  • There is no MCP-only privilege escalation.
  • Permission changes (removing a user from a list, changing a role) take effect on the next tool call.

Limiting a connection to read-only

MCP can create, update, delete, and merge records, so you may want some connections to be read-only. Two options:
  • At OAuth consent: when you first authorize, uncheck the write scope to grant read-only access. All create, update, and delete calls are then blocked for that connection.
  • In the AI client: some clients (for example, Claude) let you block individual tools — turn off the write, delete, and merge tools to keep a connection read-only, or turn off only the delete tools to allow edits but not deletion. Users or their AI-client admins can do this in the AI client’s settings.

Deletes and merges

MCP can delete list entries, opportunities, companies, people, and notes, edit notes, and merge duplicate people and companies. If you connected before September 24, 2026, restart your AI client or start a new session to load these tools.
  • Every delete and merge shows you what it will affect and waits for your explicit confirmation. Each merge needs its own approval.
  • Deletes can’t be undone. Data-recovery options are the same as for deletes made in Affinity.
  • Global (Affinity-enriched) companies can’t be deleted. Deleting an entry on an opportunity list deletes the opportunity itself.
  • You can edit or delete only notes you created, and a note with @mentions can’t be edited. Deleting a note also deletes its replies and attached files.
  • Merging people requires an org admin with the Manage Duplicates permission.
  • Merges made through MCP appear in Settings → Duplicate Management → Merged, where an admin can undo a merge of local records. A merge involving a global company can’t be undone.

Admin controls

  • Enable or disable MCP per client. MCP is available by default for Claude, ChatGPT, and Notion. An admin can turn each OAuth client on or off for the org under Settings → Affinity MCP. Turning a client off disconnects everyone in your organization who connected it through OAuth. It only affects OAuth connections: users can still connect a client manually with an API key. Each person can also disconnect from inside their AI client.
  • Choose who manages these settings (Enterprise). The Manage MCP Agents permission, under Settings → Users & Permissions → Roles, controls which roles can change the Settings → Affinity MCP toggles (Enterprise Admins and Admins by default). It doesn’t limit who can use MCP.
  • Manage API keys. Create API keys under Settings → Manage Apps (click + New App, then API Key if a menu opens), and revoke them there too. You can have more than one active key, so give each client its own key; revoked keys stop working immediately.
A connection gives the AI tool the same data visibility as the user who authorized it. If a user can see restricted lists or sensitive opportunities, so can their AI client. Grant MCP access carefully — especially for senior users with broad access.

Hosted vs local

The hosted server (https://mcp.affinity.co/mcp) supports OAuth (with the read-only option) or an API key. The local server runs on your own machine over STDIO and uses an API key stored in a local config file — treat that file like a password and keep it off shared machines. For the developer-level detail, see Security at developer.affinity.co.