People on a team work in five or six tools. An AI assistant that cannot see those tools is a copy-paste machine, and the copy-paste is where company data leaks into chats nobody controls. This project is one MCP server that connects Claude to the tools where the work happens, for three separate workspaces (one personal, two company), without letting one workspace see another’s data.
At a glance
- 150+ tools over Gmail, Drive, Docs, Sheets, Calendar, Slack, GitHub, Jira, Confluence and Linear
- Isolation in the tool name itself: every tool carries its workspace prefix, so a request for one workspace can never be routed to another’s token
- One sign-in: OAuth 2.1 with PKCE and dynamic client registration, backed by a passkey login (Face ID / Touch ID) instead of passwords and shared API keys
- Write actions are dry-run by default: anything that sends, edits or deletes returns a preview until it is called again with explicit confirmation
- Runs on Cloudflare Workers: no servers to patch, tokens stored in Workers KV
- Used every day from Claude desktop, web and mobile
Product decisions
- Flat tool list over grouped tools. Grouping the tools by domain (one
mail_searchwith an account parameter) looked tidier, so it was planned and measured first. On the measured tasks the flat list already picked the right tool every time (11 of 11), and grouping would have moved workspace isolation from the tool name into a runtime parameter, oneifaway from mixing two companies’ inboxes. The list stays flat. - Read first, write later. Each connector shipped read-only; write tools were added only after the dry-run pattern existed.
- Per-workspace hosts for strict setups. The same code also serves one host per workspace, for machines that must only ever see one company’s data.