The security model behind clariBI's MCP integrations
Connecting an AI tool to Stripe or HubSpot raises fair questions. What clariBI's MCP integrations can and cannot do: read-only tools, a vetted catalog, OAuth with PKCE, encrypted credentials, per-organization scoping, and what disconnecting actually removes.
Letting an AI product connect to your payment processor or CRM is a reasonable thing to be nervous about. This post sets out how clariBI's MCP integrations work, what they can and cannot do, and where the limits are, so you can decide with the facts in front of you.
A quick recap first. The Model Context Protocol (MCP) is a standard way for AI tools to read other systems. Many vendors now run an MCP server that exposes "tools", such as listing charges or fetching deals. clariBI connects to those servers to sync data and to answer questions. Our introduction to MCP covers the protocol itself.
1. Only read tools are used
A vendor's MCP server may offer tools that change things: create a refund, update a deal, send an email. clariBI does not use them.
The filtering happens in two ways:
- An explicit allowlist per vendor. For vendors whose tools we have reviewed, the catalog entry lists the tool names clariBI may call. Anything else the vendor publishes is ignored.
- A name filter for everything else. Where there is no allowlist, clariBI drops any tool whose name indicates a change, such as names containing create, update, delete, send, refund, cancel, archive, assign or execute_sql.
This filtering happens before the language model sees the tool list. The model plans which tools to call, but it can only choose from the tools that passed the filter, and clariBI only dispatches calls to those same tools. There is no path where the model asks for a write tool and gets it.
Where a vendor offers read-only permissions at its end, clariBI uses them. For example, it asks Close only for its read scope, and connects to Aiven's server in its read-only mode. Other vendors grant broader access on their consent screen than clariBI will ever use; in those cases the read-only rule is enforced on clariBI's side by the filtering above.
2. A vetted catalog, run by the vendor
The catalog lists 86 apps, and each one was checked by us before it was listed. The server itself is run by the vendor, not by clariBI or a third party. What an app returns depends on what that vendor's server exposes: some expose many tools, some only a few.
On Starter and up you can also connect a custom MCP server by URL, for example one your team runs. The URL must use HTTPS, and addresses in private networks, loopback addresses and cloud metadata addresses are refused. The same read-only rule applies.
3. Sign-in without copying secrets around
Most apps connect with OAuth: you sign in at the vendor and approve access, and the window closes. clariBI registers itself with the vendor's authorization server using dynamic client registration, so you do not create an app or paste client IDs. The flow uses PKCE, which protects the authorization code in transit. Our post on OAuth 2.1 with dynamic client registration explains both in plain terms.
A few apps use an API key instead, which clariBI checks before saving, and a few use an OAuth app you registered yourself.
4. Credentials are encrypted at rest
Access tokens, refresh tokens and API keys are encrypted with Fernet (AES-128 in CBC mode with an HMAC-SHA256 integrity check) before they are written to the database. The encryption key is supplied to the application through its configuration and is not stored in the database, so a copy of the database alone does not reveal the credentials. Credentials are decrypted on the server when clariBI needs to call the vendor, and the settings page shows them masked.
5. Every connection belongs to one organization
Each MCP connection is tied to a single clariBI organization, and every lookup of a connection is filtered by the organization of the person making the request. Guessing another connection's ID returns "not found". Data synced from the connection lands in your organization's data sources and is not visible to other clariBI customers.
Inside your organization, roles decide who can do what. Disconnecting an app is limited to Owners and Administrators; the roles article lists what each role can do.
6. What disconnecting removes, and what it keeps
When an Owner or Administrator disconnects an app:
- the stored access tokens, refresh tokens and API keys are erased
- the data sources built on the connection stop syncing
- if you used your own OAuth app, its client ID is kept so that reconnecting does not require registering it again
- the connection record itself stays, for the audit history; connecting the same account again reuses it
Disconnecting does not delete data that was already synced. If you want that removed too, delete the data source, which deletes its synced rows. On Professional and Enterprise, data source creation and deletion appear in the organization audit trail.
You can also revoke clariBI's access from the vendor's own settings, for example the connected apps page in your Stripe dashboard. The next sync then fails with an authorization error until you connect again.
7. Who can use MCP apps
MCP integrations are available in the trial and on Starter, Professional and Enterprise. 52 apps are available from the trial up (including Stripe, HubSpot, Linear and PostHog), 32 more from Starter, and dbt Cloud and Microsoft Dataverse from Professional. The Free and Lite plans have no MCP access.
What clariBI does not do
- It does not write to your vendor accounts: no refunds, no edits, no messages sent.
- It does not share one organization's data with another.
- It does not keep tokens or keys after you disconnect.
Limits worth knowing
Security depends on both sides. clariBI cannot make a vendor's MCP server behave differently from how the vendor built it, and a name filter is a safety net rather than a guarantee for tools with misleading names; that is why reviewed vendors get an explicit allowlist. If a tool you expected is missing, it is usually because it was filtered as a possible write.
The MCP integrations documentation walks through connecting, the catalog and troubleshooting. If your security review needs more detail than this post gives, contact us before you connect anything; we would rather answer the questions first.