On this page5 sections
How to choose an MCP provider: the short answer
Choose an MCP provider by what you can verify on its site before you connect an account: where it stores your credentials, how much of each API it exposes, whether tool calls are metered, how it separates accounts, which AI clients it supports, and what it logs. Nine questions cover it.
What an MCP provider does
An MCP provider runs MCP servers so you do not have to. You authorize a tool such as Shopify or HubSpot once, and the provider gives your AI client a URL to call. You will also see the terms hosted MCP server, managed MCP and MCP gateway. They overlap, and the questions below apply to all three.
If the protocol is new to you, read what MCP is first. If you only need one tool on one account, the vendor's own server may be enough. The best MCP servers lists those.
The 9 questions
1. Where are my credentials stored, and how do I cut a client off?
The provider holds the keys to your store, ad accounts or books. Two things should be written down somewhere public: how those credentials are encrypted, and that the AI client never receives them. The MCP security guidance forbids token passthrough, which means a server must not accept or forward a token that was not issued for it.
Then look for the off switch. Stripe's dashboard, for example, lists each MCP client's OAuth session with a control to end it. Ask any provider where its equivalent is.
Walk away if the setup guide tells you to paste a provider API key into the AI client's config file.
2. Do I get the full API or a curated tool set?
Some servers ship a short list of tools for the common tasks. That works until you need the endpoint they left out.
Look for a public tool list per integration, readable before you pay. Then look for a way to reach the rest of the API without loading thousands of tool definitions into the model's context. Stripe does it with two generic tools, stripe_api_read and stripe_api_write. Others use a search tool. MCP token limits explains why this matters.
"We support HubSpot" with no tool list behind it is not an answer.
3. Is pricing metered per call or flat?
You cannot predict how many tool calls a conversation will make. One question can trigger several. So check whether calls are the billing unit, and if they are, whether the rate is public.
Two examples of metering you can model. Zapier counts two tasks for each successful MCP tool call. Smithery's paid plan includes a $10 monthly credit, then charges $0.10 per 1,000 RPCs. Flat plans priced on connections, seats or workspaces are easier still to forecast.
The thing to avoid is a "fair use" limit or a credit with no stated conversion into calls.
4. Can I connect more than one account per tool?
Agencies, multi-brand retailers and anyone with a staging store need this. Some integrations assume one account. Shopify's official AI integrations connect one store at a time, and switching disconnects the current store and starts a new authorization.
Look for separate workspaces or environments, each with its own connections and usage data. Multiple accounts, one MCP and MCP for agencies go deeper.
5. Which AI clients does it support?
Your team may use Claude, ChatGPT and Cursor in the same week. A provider should offer a standard remote endpoint: Streamable HTTP with OAuth sign-in. Check its client list against the clients you actually use, and ask about the older SSE transport if one of yours still needs it.
A provider that needs a local process on every laptop is a different kind of product. See remote vs local MCP servers.
6. Can I make access read-only, and can a human approve writes?
These are two separate controls.
Read-only means the write and delete tools are not exposed at all, per person or per connection. Telling the model not to write is only a prompt. It does not stop a tool call.
Approval means a risky write waits for a person. Stripe's server requires confirmation for refunds and outbound payments. Other providers leave approval to the AI client. Claude shows a tool approval request unless you chose "Allow always" for that tool. Know which layer you are relying on.
7. What gets logged, and for how long?
When something changes in a client's account, you need to see which tool ran, when, who triggered it and from which AI client. Check the retention period on the plan you would buy, because it can differ by tier.
Ask whether the logs hold payloads. Providers differ on this. Glama's hosting page says its gateway logs every JSON-RPC call with full payloads. PopMCP stores metadata only. Full payloads help an audit and put your customers' data in the provider's logs. Metadata keeps that data out, and you lose the record of exactly what the model read.
8. What compliance paperwork exists?
A larger client's security team will ask before you connect their accounts. Look for a published DPA, a subprocessor list, a stated data location, SSO, and an audit report such as SOC 2 if your buyers require one.
Ask for the report itself. A badge on a homepage proves little, and a claim you cannot read should count as absent.
9. What happens when the provider's API changes?
APIs under an MCP server move. Shopify removed the catalog and cart tools from its Storefront MCP endpoint in favour of a newer protocol. Stripe's MCP server stops accepting some API key types on 31 October 2026.
A provider should own those upgrades, keep tool names stable and warn you before removing a tool. The evidence is a public changelog. HubSpot announced its MCP server's general availability in its developer changelog, and Stripe put a dated notice in its MCP docs.
A community server with one maintainer and no release this year gives you none of that.
How PopMCP answers the 9 questions
We run PopMCP, so here are our own answers. Five of the nine have a weak spot, and each is marked.
| # | Question | PopMCP's answer |
|---|---|---|
| 1 | Credentials | Stored in PopMCP, encrypted at rest with AES-256-GCM, never passed to the AI client. The client signs in with OAuth, and you tick which connectors it can reach. Weak spot: no screen lists or removes a single AI client's grant. You cut access by removing the member, disconnecting the connector, or running consent again with fewer connectors ticked. |
| 2 | Tool depth | A curated set loads by default. The full provider catalog stays reachable on every plan through three helper tools per provider, for example hubspot_search_tools, hubspot_describe_tool and hubspot_raw_operation. HubSpot has 1,000+ operations, Klaviyo 308, QuickBooks 133, Shopify 70. Tool lists are public on each server page. |
| 3 | Pricing | Flat plans priced on workspaces, connections and members, from $0 to $199 a month, with Enterprise from $600. Tool calls are never metered, billed or capped. |
| 4 | Multi-account | Workspaces per client or brand, starting at 3 on Starter. One connection per provider per workspace, so two Shopify stores need two workspaces. Free has one workspace. |
| 5 | AI clients | Any client that supports remote Streamable HTTP MCP with OAuth sign-in, including Claude, ChatGPT custom connectors, Cursor, Codex, Windsurf, Zed and Cline. The older SSE transport is not supported, and neither are Client ID Metadata Documents. |
| 6 | Read-only and approval | Free is read-only for everyone. On Starter and Studio, every teammate other than the owner is read-only. On Scale and Enterprise the owner sets read-only or full access per teammate and connection. Weak spots: the owner cannot make their own connection read-only, and there is no approval mode. A write runs when the model calls it. |
| 7 | Logs | Usage analytics by connection, teammate and tool, with outcome and response time. Metadata only: provider response contents are not stored in that telemetry. History is 7 days on Free, 90 on Starter, 180 on Studio and 1 year on Scale. Weak spot: there is no audit log screen. An audit trail is recorded and comes with the owner's account data export. |
| 8 | Compliance | A published DPA and subprocessor list, with data hosted in the United States. Weak spots: no SOC 2 report. Sign-in is Google or a one-time email code, and SSO is on request for Enterprise only. |
| 9 | API changes | PopMCP maintains each integration as provider APIs change. Weak spot: it publishes no connector changelog and no deprecation policy, so there is no written notice period before a tool is renamed or removed. |
If a missing SOC 2 report, self-serve SSO or an approval step rules us out, that is a fair call. You can compare other hosted options on our Composio, Zapier MCP and MintMCP pages. The plan details behind rows 3 to 7 are on the pricing page and in the FAQ.
Frequently asked questions
What is an MCP provider?
A service that hosts MCP servers for other products. You authorize your accounts with the provider, and your AI client calls the provider's URL. You do not deploy or maintain the servers yourself.
Is a hosted MCP server safe?
It depends on the provider, which is what the nine questions are for. At a minimum, credentials should be encrypted and kept away from the AI client, sign-in should use OAuth, and you should know how to cut a client's access before you need to.
What is the difference between an MCP gateway and an MCP server?
An MCP server exposes tools for one system. A gateway sits in front of several servers and adds shared sign-in, access control and logging. Some products are both. PopMCP builds the servers and serves them all from one endpoint.
Should I use the official MCP server from each vendor?
For one tool on one account, often yes. It is free of a middleman, and some vendors add controls of their own, such as Stripe's confirmation step on refunds. A provider starts to pay off when you run several tools, several accounts of the same tool, or a team that needs one access model.
How much does a managed MCP provider cost?
It depends on the billing unit. Zapier draws two tasks per successful MCP tool call from your plan's task allowance. Smithery charges $0.10 per 1,000 RPCs once a $10 monthly credit is used. PopMCP has a free plan and flat paid plans from $39 a month with unmetered tool calls.
Do I need SOC 2 from an MCP provider?
Only if your company or your clients require it. If they do, ask for the report and read its scope and dates. PopMCP does not claim SOC 2.
Sources
11 references, checked 5 October 2026
- MCP security best practices (token passthrough, local server risks)modelcontextprotocol.io
- Zapier MCP usage and billing (two tasks per successful tool call)docs.zapier.com
- Smithery pricing ($10 credit, $0.10 per 1K RPCs)smithery.ai
- Stripe MCP docs (OAuth sessions, generic API tools, confirmation step, 31 October 2026 notice)docs.stripe.com
- Shopify, authorizing AI tool access (one store at a time)help.shopify.com
- Shopify, migrate from Storefront MCPshopify.dev
- HubSpot changelog, remote MCP server generally availabledevelopers.hubspot.com
- Claude custom connectors (tool approval requests)support.claude.com
- Glama MCP hosting (gateway logging)glama.ai
- PopMCP pricing (plans, limits, read-only rules, usage history)popmcp.com/pricing/
- PopMCP FAQ (credential storage, sign-in, telemetry, DPA)popmcp.com/faq/