Claude Code: How to set up read-only access for MCP connectors

Updated . Posted . Visible to the public. Repeats.

Claude Code can connect to MCP servers to access additional information, like Linear issues or Figma designs.

Such MCP servers usually allow doing a lot of different things, from reading to modifying/destructive operations, and by nature usually just offer all tools to the agent. Usually, we don't want our agents to have full write access over such connections.

Claude allows restricting which tools the agent actually uses.
We recommend configuring this. Here is how.

Set up the MCP connection

  1. In Claude Code, run /mcp.
  2. Pick "Show unused connectors".
  3. Pick your desired service, e.g. "claude.ai Linear".
  4. Pick "Authenticate".

Click the link to open in your browser, and confirm the connection.
Note that this will set up a connection with full permissions.

Adjust permissions

  1. Visit claude.ai Show archive.org snapshot in your browser.
  2. Click your profile name (bottom left), and go to "Settings".
  3. Navigate to "Connectors".
  4. There, you should see an entry for each MCP service you connected to. Click it.
  5. You'll then see a list of tools that Claude can use.
    • They are usually classified as read-only and destructive write/delete tools, and possibly other categories, each as their own group.
    • For each group, there is a control to set permissions for all tools. Select "Blocked" for the write/delete group.
    • If you like, you may also change permissions for individual tools.

Settings

Note that "Needs approval" implies being allowed when using Auto Mode.

Profile picture of Arne Hartherz
Arne Hartherz
Last edit
Arne Hartherz
Attachments
License
Source code in this card is licensed under the MIT License.
Posted by Arne Hartherz to makandra dev (2026-07-27 06:11)