Summary
MCP Plugins let Pi use tools and data from external applications (such as Slack and Google Drive) directly inside Planhat OS Sessions, using the open Model Context Protocol (MCP) standard
There are two connection types: "Central" (one shared authorization for the whole tenant) and "Individual" (each User authorizes their own account and only sees what they personally have access to). Individual is the right choice for apps that hold personal or per-user data, e.g. Slack and Google Drive
Setup is a two-part job: an Admin creates the MCP Plugin configuration in Planhat (from a template, or as a custom MCP connection to any MCP server) and sets up the credentials in the external application; then, depending on the connection type, each User either connects their own account (Individual) or is granted access by the Admin (Central)
Planhat records every tool call made through an MCP Plugin in audit logs, and Users can restrict which tools Pi is allowed to use on their behalf
MCP Plugins currently support Pi reading from and writing to external apps. Triggering Pi from inside the external app (e.g. from a Slack message) is not part of this feature
Who is this article for?
Planhat Admins (e.g. Ops, RevOps or CS Ops) who set up and manage MCP Plugins for their tenant
IT and Security teams who need to review or create the app or credentials in the external application (e.g. a Slack app, a Google Cloud OAuth client, or an API token)
If you are a Planhat User who just wants to connect your account and start using an MCP Plugin with Pi, see our shorter article Planhat OS - Using MCP Plugins with Pi instead
Series
Planhat OS - MCP Plugins: setup and management guide (for Admins) ⬅️ You are here
Article contents
Introduction
Pi - the multi-purpose, built-in AI Agent in Planhat OS - already comes with a large set of built-in tools for working with your Planhat data: searching Companies, reading Conversations, creating Tasks, writing notes and so on. A lot of the context your team relies on, however, lives outside Planhat: customer updates in Slack channels, account plans and QBR decks in Google Drive, and similar.
MCP Plugins extend Pi with tools from those external applications, via a library of 20+ pre-configured Plugins - Slack, Google Drive and GitHub are the featured starting points. Once an MCP Plugin is set up, a CSM can ask Pi things like "Summarize the latest updates in the Slack channel for Acme" or "Find the account plan for Acme in Google Drive and pull out the agreed next steps", and Pi will call the external tool, read the result, and continue working with it inside the Session - for example, by saving the summary as a note on the Company.
This article is the technical deep dive for the people who set this up for their organization. It covers the concepts you need to make good decisions (in particular which connection type to use), the step-by-step setup in Planhat and in the external application, and how to manage the connections afterwards.
📚 Further reading
We have additional documentation on related topics:
Planhat OS - MCP Plugins: overview - a short, non-technical introduction
Planhat OS - Using MCP Plugins with Pi (for Users) - the general User steps you can share with your team
Planhat OS - Sessions and Planhat OS - Skills - where and how Pi is used
How to connect Claude to Planhat, using OAuth and Planhat's MCP server and How to connect ChatGPT to Planhat, using OAuth and Planhat's MCP server - the opposite direction: letting an external AI read your Planhat data
Key concepts
What is MCP?
MCP (Model Context Protocol) is an open standard that defines how an AI assistant can discover and call "tools" exposed by another application. An application that exposes tools is an MCP server; the AI application that calls those tools is an MCP host (or client). The tools themselves are small, well-described operations - for example "search messages", "list files in a folder" or "read a document".
In the context of MCP Plugins, Pi is the MCP host and the external application (Slack, Google Drive, etc.) is the MCP server. When a User asks Pi something that requires external data, Pi selects the appropriate tool based on the tool descriptions and the User's request, calls it with the User's authorization, and uses the result in its reply.
🚀 Tip
You may sometimes hear MCP Plugins referred to as "MCP connections" or "MCP connectors". If you have connected Planhat to Claude or ChatGPT before, the concepts are the same - Planhat is simply on the other side of the connection this time (see the next section).
MCP Plugins v. Planhat's MCP server
Planhat participates in MCP in two directions, and it is worth being clear about which one you are setting up:
| MCP Plugins (this article) | |
Direction | Pi (inside Planhat) connects out to an external application | An external AI (e.g. Claude or ChatGPT) connects in to Planhat |
Who is the MCP host? | Pi | The external AI application |
Who is the MCP server? | The external application (e.g. Slack, Google Drive) | Planhat |
Where is it configured? | The "MCP Plugins" Tool | OAuth Clients, in the "Settings" Tool |
Typical question | "Pi, what did the customer say in Slack this week?" | "Claude, list the Companies where I am the Owner" |
Where the data is used | In Planhat OS Sessions | In the external AI tool |
Both can be used at the same time. This article only covers MCP Plugins. For Planhat's MCP server, see our OAuth Clients overview and the connection guides for Claude and ChatGPT.
Connection types: Central v. Individual
When you create an MCP Plugin, you choose how Planhat should authenticate with the external application. This is the most important decision in the setup, because it determines whose data Pi can see and how the activity appears on the external application's side.
| Central | Individual |
How it authenticates | One shared authorization (token) is used for every User in the tenant | Each User authorizes their own account after the Admin has set up the Plugin |
What Pi can access | Whatever the single connected account can access - the same for every User | Only what that specific User can access in the external application |
How it appears in the external app | Every call looks like it came from the same account. The external app cannot tell which Planhat User triggered it | Each call is made as the individual User, so the external app's own permissions and audit trail apply per person |
Setup effort | Admin connects once; Users have nothing to do | Admin sets up the Plugin; each User clicks "Connect" and authorizes (about 30 seconds) |
Best suited to | Shared, non-personal sources that everyone should see identically - e.g. a shared knowledge base or a company-wide document library | Any application that holds personal or user-specific data - e.g. Slack (direct messages, private channels), Google Drive (personal files), email |
📌 Important to note
Use "Individual" for Slack and Google Drive.
With a "Central" connection to Slack, every User in your tenant would be able to retrieve content the connected account can see - including that person's direct messages and private channels. With an Individual connection, each User only ever sees what they can already see in Slack themselves. The same logic applies to Google Drive and personal files.
A Central connection can be acceptable when you only need read-only retrieval from a source with no personal data, and you are comfortable that Planhat's own audit logs (rather than the external app's) are what tell you which User made a given request.
How access and permissions are layered
Multiple layers combine to determine what Pi can actually do through an MCP Plugin. It is useful to understand them, because "Pi can't find the file" is usually explained by one of these layers rather than by the Plugin itself.
The permissions granted in the external application. For OAuth Plugins, these are the scopes the OAuth app was granted (e.g. which Slack scopes the Slack app has); for Plugins using an API token or username/password, they are the permissions of that token or account. These are the maximum capabilities the connection can ever have
The User's own access in the external application. With an Individual connection, Pi can only reach channels, files and folders the User can open themselves
The tools enabled on the Plugin. Each MCP Plugin template comes with a set of tools (e.g. search messages, read channel history, list files, read a file, create a file). The Admin sees the full set on the configuration
The User's own tool selection. After connecting, each User can turn individual tools on or off for their own connection - for example, allowing read tools but not write tools
Pi's judgement in the Session. Pi only calls a tool when the User's request calls for it, and it will ask for clarification when a request is ambiguous (e.g. which of two similarly named Companies you mean)
Now you are familiar with the background context of MCP Plugins, next in this article we'll go through how you - as a Planhat Admin - set up MCP Plugins in Planhat.
Prerequisites for setting up MCP Plugins
You are a Planhat Admin with the "Admin Access" workflow permission in your Role, which is required to add new MCP Plugins within the MCP Plugins Tool
Your Planhat tenant has Planhat OS and Pi enabled
For the external application, someone in your organization (you or a colleague) must be able to create an OAuth app (which may be called an "app", "OAuth client" or "integration") and give you its Client ID and Client Secret. Specifically, you will need:
Slack: an account that is allowed to create a new Slack app for your workspace at
api.slack.com/apps. In many workspaces, installing a new app requires approval from a Slack workspace admin, so plan for that stepGoogle Drive: access to a Google Cloud project in your organization where you can create an OAuth 2.0 Client ID (and, where required, configure the OAuth consent screen). Your Google Workspace admin may need to allow the app for your domain
Custom MCP connection: the MCP server URL (from the application's or your own server's documentation) and the credentials it expects - an OAuth app, an API token, or a username and password
If your organization runs a security review for new integrations, start it early. The main questions reviewers ask are covered in the "Security and data considerations" section below
🚀 Tip
Before you begin setting up MCP Plugins, decide which use cases you want to launch with. In practice, the two that most teams start with are (1) retrieving recent customer updates from Slack channels and (2) finding and summarizing account plans or QBR documents in Google Drive. Knowing your use case also tells you which connection type you need (see above) and what to test with Pi in Stage 4.
Next, we'll go through the actual setup steps.
Stage 1: in Planhat, start creating the MCP Plugin
In Planhat, open the Tools menu (by clicking "More" in your sidebar) and click "MCP Plugins" (under "System Configuration")
Click the image to view it enlarged
📌 Note: at time of writing, there is a feature flag controlling access to this, so if you don't see the MCP Plugins option, please speak with Planhat staff
Click "New connection" (in the top right)
Choose a template from the MCP Plugins library for the application you want to connect - e.g. Slack, Google Drive or GitHub. Templates pre-fill the MCP server details, the required scopes and the available tools, so you only need to supply credentials. If the application you want to connect is not in the library, choose "Custom connection" instead - see "Setting up a custom MCP connection" below
Click the image to view it enlarged
Choose the "Connection type": "Individual" or "Central" (see "Key concepts" above for how to decide). For Slack and Google Drive, choose Individual
Planhat shows a "Callback URL" (also called a redirect URL). Copy it - you will need to paste it into the external application in Stage 2
📌 Important to note
Keep this Planhat tab open. You will come back to it in Stage 2 to paste the Client ID and Client Secret you get from the external application.
Setting up a custom MCP connection
If the application you want to connect to is not in the Plugin library - e.g. your own internal MCP server - you can add it as a custom MCP connection. The flow is similar compared to a template, except that you supply the server details yourself:
In the Plugin library, choose "Custom connection" (in the top left)
Choose the connection type (Individual or Central)
Enter the "Server URL" (under "Authentication"). This is not provided by Planhat - find it in the external application's MCP documentation (or your own server's configuration) and copy it in exactly
Choose the authentication method the server expects. Three are supported: OAuth, API token, and username/password
Continue with the next steps to obtain the credentials from the external application and paste them into Planhat. For OAuth, Planhat shows the Callback URL to register with the server; for API token or username/password, you paste the credentials directly
🚀 Tip
OAuth is the recommended authentication method - it is what the MCP protocol specifies for authorization, and it gives the strongest security: Users authorize on the server's own consent screen, Planhat never stores their password, and access can be revoked at any time. Use API token or username/password only where the MCP server does not support OAuth.
Stage 2: in the external application, create the OAuth app (or credentials), and copy the Client ID and Client Secret into Planhat
The steps in this stage start outside of Planhat, in the external application's developer or admin console. For OAuth Plugins (most templates), the main principles are the same for every application: create an OAuth app, register Planhat's Callback URL as an allowed redirect URL, and copy the Client ID and Client Secret and paste them into Planhat. For a Plugin that uses an API token or username/password, the equivalent to this stage is simply generating the token or service credentials in the external application.
Below, we will walk through Slack, as the most common example.
Example: Slack
Go to api.slack.com/apps and click "Create an App"
Choose "Blank app" and click "Continue"
Enter an app name (e.g. "Planhat MCP"), select your Slack workspace from the dropdown menu, and then click "Create"
"OAuth & Permissions" should be automatically selected in the left-hand menu (or if it hasn't been, you should navigate to it). Under "Redirect URLs", click "Add New Redirect URL", paste the "Callback URL" you copied from Planhat in Stage 1, click "Add", and then click "Save URLs"
In the left-hand menu, open "Basic Information". Under "App Credentials", copy the "Client ID" and paste it into the relevant field in Planhat, and then copy the Client Secret from Slack (click "Show" to reveal it first) and copy that into the relevant field in Planhat too
Back in Slack, select "Agents" in the left-hand menu, and then enable the toggle switch for "Slack Model Context Protocol (MCP) Server"
Stage 3: test and save the connection; confirm scopes/tools
In the MCP Plugin configuration form in Planhat, click "Connect" to test the setup with your account
Click through the authentication screens as applicable - e.g. continuing with our Slack example, you will see something similar to the screenshot below, where you click "Allow" to confirm and continue
You will see the connection confirmation (with tools stated) in the form in Planhat
For the Central connection type only, you will also see an "Access Granted" section as point 4 in the form, where you can select Roles, Teams and/or Users to have access - but you can also add these later on, after creating the MCP Plugin. We show this later in this article
Click "Create"
You will see the details of the MCP Plugin in Planhat, showing it's connected:
Click the image to view it enlarged
Back in Slack, in "OAuth & Permissions" in the left-hand menu, scroll down to "User Token Scopes" and you can review the scopes that have been added, and select/deselect scopes if desired - or most likely, you will just leave the defaults "as is". If you do make any changes here, they will update the MCP Plugin in Planhat
In Planhat, you can click on your own individual connection in the MCP Plugin (as shown in the green box in the first screenshot below) to open up the tools applied for you (as shown in the second screenshot below) - generally you can leave these as the defaults, but you have the option to disable/enable here if desired
Click the image to view it enlarged
Stage 4: try out the connection with Pi
Start a new Session with Pi and try a request that uses the MCP Plugin you have just set up - for example:
"Search Slack for the latest messages about Acme and summarize them"
"List the files in my Google Drive related to Acme"
"Open the Acme account plan in Google Drive and tell me the agreed next steps"
Check that the results only include content you personally have access to in the external application, and that the tool calls appear in the MCP Plugin's "Tool Calls" audit log (see "Audit logs" below)
Click the image to view it enlarged
🚀 Tip
If Pi asks you a clarifying question - for example which of two Companies with similar names you mean - that is expected behavior. Pi checks with you before calling a tool when your request is ambiguous.
Stage 5: roll out to your Users
With an Individual connection, each User will need to connect their own account once - see our separate guide for Users.
The screenshot below is an example of what another User who is an Admin (has the "Admin Access" workflow permission) would see; general non-Admin Users will only see their own connection here.
Click the image to view it enlarged
With a Central connection, Users have nothing to connect - instead, you grant access as part of the MCP Plugin, to the Users or Roles who should be able to use it, and then they will see it as available in their MCP Plugins view. Either you can grant access as part of the original MCP Plugin setup form as we discussed earlier, or you can "Add access" to an existing MCP Plugin, as shown in the example screenshot below.
The next step for you as an Admin - whether your MCP Plugin is an Individual or Central connection - is to communicate to your Users, i.e. your colleagues in your Planhat tenant.
Tell Users what the MCP Plugin is for. Frame it as "bring Slack and Google Drive context into Planhat through Pi" or similar. It is retrieval (and, where enabled, writing) from within Planhat; it is not a way to chat with Pi from inside Slack, for example
Send the connection User instructions. The User-facing article Planhat OS - Using MCP Plugins with Pi (for Users) contains the quick connect flow. Many teams record a short click-through video or add the steps to their onboarding course
Make the data findable. Pi can only retrieve what it can identify. If your customer Slack channels follow a naming convention (e.g. #customer-acme), tell Users to reference the customer by name. Even better, store the external identifier on the Company record - for example a custom field "Slack Channel ID" synced from your CRM - so a User can simply say "Slack updates for Acme" and Pi can look up the channel from the Company
Encode the process in a Skill. If the routine is always the same (e.g. "pull the latest Slack updates for a customer, summarize, and save as a note on the Company"), create a Skill so every User runs it the same way
Managing MCP Plugins
Viewing connection status
The MCP Plugins Tool lists every Plugin configured in your tenant. As an Admin (with the "Admin Access" workflow permission in your Role), you can see each Plugin's connection type, whether it is enabled, and (for Individual connections) your own connection status. General Users see only the Plugins available to them and their own connection status.
Editing, disabling and deleting a Plugin
To edit a Plugin, click on it in the row to open up its details panel on the right-hand side. To modify the tools available in your own connection, click on your name in the "Connections" list in this panel
Click the image to view it enlarged
To disable a Plugin to stop Pi from using it without deleting the configuration, click on the "Enabled" toggle switch for that Plugin in the list. When you disable, Users keep their authorizations, and the Plugin can be re-enabled later. This is the safe option if you are unsure, or if the external application is under review
You can delete a Plugin to remove it entirely - click the ellipsis symbol (3 dots) at the end of the Plugin row in the list, and select "Delete". If you delete, all User authorizations for that Plugin are revoked. Planhat asks you to confirm, and this cannot be undone
Click the image to view it enlarged
Rotating credentials
If a Client Secret is compromised or your security policy requires periodic rotation, you can generate a new secret in the external application (Slack: Basic Information → App Credentials → "Regenerate"; Google: Credentials → the OAuth client → "Reset secret"), and then paste the new secret into the MCP Plugin configuration in Planhat and save. Depending on the application, existing User authorizations may continue to work or may need to be re-authorized - check with a test User after rotating.
Audit logs - "Tool Calls"
Every tool call made through an MCP Plugin is recorded by Planhat: which User triggered it, which tools were called, and when. This lets you answer "who retrieved what, and when" without asking the external application - which matters most for Central connections, where the external application only sees one shared account.
Click the image to view it enlarged
Appendix: security and data considerations
These are the points your security or IT team are most likely to ask about.
OAuth first, with alternatives where needed. MCP Plugins support three authentication methods: OAuth, API token, and username/password. Most pre-configured Plugins use OAuth, which is the recommended method under the MCP specifications and offers the strongest security: Users authorize on the external application's own consent screen, Planhat never handles their password, and access can be revoked at any time
Your access, nothing more. With Individual connections, Pi cannot reach anything the User could not open themselves. Scopes are limited to what the Plugin needs, and Users can further restrict which tools Pi may use
Tool-level control. Users can switch individual tools on or off - for example, allow reading but not writing
Audit trail. Planhat records every tool call, including who made it and when. For Individual connections, the external application's own audit trail also attributes activity to the correct person
Central connections carry more responsibility. One account, one identity, for everyone granted access. Reserve Central for shared, non-personal sources, use a dedicated service account, and prefer read-only scopes
Secrets. Client Secrets, API tokens and passwords are stored encrypted in Planhat and are not displayed after saving
Further reading
Planhat OAuth Clients - overview (for the reverse direction: external AI tools connecting to Planhat)




































