MCP Server Development

MCP server development services

The Model Context Protocol (MCP) is the open standard that lets Claude, ChatGPT, Microsoft Copilot and your own agents call business systems as tools. We design, build, secure and host MCP servers over ERP, CRM, HR and data systems, starting with read-only tools and adding write actions behind approvals.

Want your systems in the hands of AI agents, safely?

Tell us which system and which questions or actions matter most. We’ll check what already exists and scope the tool surface and security model with you.

Please share the workflow and the systems involved—not credentials or customer records. We’ll agree the scope and next steps with you.

NVIDIA Inception

NVIDIA Inception member

Part of NVIDIA’s program for startups building with AI and accelerated computing.

About the program
Pravin BansalSravan Modugula

Bay Area roots. Enterprise experience.

Pravin’s experience includes Google and SmartBear. Sravan previously held leadership roles at JPMorgan Chase and First Republic Bank.

Meet the founders

San Francisco Bay Area, California

9110 Alcosta Blvd Ste H345, San Ramon, CA 94583

US-led delivery, with engineering in India. Supporting US and international organizations.
Prefer email? info@aiondata.io

Tell us where you want to start.

Just your name and email to get started. Your details are handled under our Privacy Policy.

What's included

Custom MCP Servers

Servers built around the questions and actions your team needs, over SAP, NetSuite, Dynamics 365, Salesforce, HubSpot, Shopify, Paycor, TallyPrime, Zendesk and any system with an API.

Official Server Rollouts

Where the vendor ships its own MCP server, we configure it, narrow its scope, connect it to your assistants and add custom tools only for what it does not cover.

Data & Warehouse MCP

Governed, read-only or write-scoped access to Snowflake, Databricks, BigQuery and PostgreSQL, with a semantic layer so agents ask the right question of the right table.

Auth, Scopes & Audit

OAuth and per-user identity, tool-level permissions, rate limits, redaction of personal data, and a complete log of every call an agent makes.

Evaluation & Guardrails

Tool-call test suites, golden datasets and regression checks, so a model update or an API change does not silently break the assistant your team relies on.

Hosting & Operations

Remote MCP servers deployed in your AWS, Azure or GCP account, or hosted by us, with monitoring, versioning and a handover your team can run.

How we work

  1. Check what already exists

    Many vendors now ship an MCP server. We check the official server and hosted options first, and configure them when they cover the job.

  2. Design the tool surface

    Tools built around what people ask, not every API endpoint. Clear names, tight schemas, a read/write split and approvals where money or customers are involved.

  3. Build, secure, evaluate

    Implement the server, wire identity and permissions, and test it against real prompts, failed requests and edge cases before anyone in the business uses it.

  4. Ship and hand over

    Deploy as a remote MCP server, connect it to Claude, ChatGPT or Copilot Studio, and hand over documentation, runbooks and operations.

Ways to engage

Start with the stage you need. Each one ends with something your team can use.

Short discovery

Blueprint

Confirm what the official server and hosted options cover, then design the tools, identity model and hosting for the rest.

  • Tool list with read/write split and risk levels
  • Authentication and permission design
  • Hosting and network plan
  • Written scope and estimate

Typically 2–4 weeks

Single-system server

A focused server over one system with a handful of well-designed tools, including security and evaluation.

  • Read-only tools first, writes behind approvals
  • OAuth or per-user identity
  • Evaluation suite of real prompts
  • Connected to your assistants

Scoped after discovery

Multi-system and agents

Tools that span several systems, such as order status across Shopify, SAP and Zendesk, or agent workflows built on top.

  • Cross-system tools with consistent rules
  • Human approval gates
  • Per-system rate limits and retries
  • End-to-end evaluation

Ongoing

Hosting and support

We run the server in your cloud or ours, update it when vendor APIs change, and keep the evaluation suite passing.

  • Monitoring and alerting
  • Version updates and API change reviews
  • Audit log retention
  • A named support channel

Which AI assistants can use your MCP server

One server can serve several assistants. Each client connects differently, and those differences shape hosting, authentication and network access.

Which AI assistants can use your MCP server
ClientWhere it connectsTransportAuthenticationWhat to know
Claude (claude.ai, Claude Desktop, Cowork)Custom connector; on Team and Enterprise an Owner adds the URLStreamable HTTP (legacy HTTP+SSE still accepted)OAuth 2.0, a static header credential (beta) or noneCalls come from Anthropic’s cloud, so private servers must allowlist its IP ranges.
Claude Codeclaude mcp add, or a shared .mcp.json in the repositorystdio for local servers, Streamable HTTP for remote; SSE deprecatedOAuth 2.0 through /mcp, or headers and environment variablesAdmins can fix, allow or deny servers with managed MCP settings.
ChatGPT (developer mode and plugins)Developer mode, then ChatGPT Plugins; admins enable plugins by roleStreamable HTTP on a public HTTPS endpoint, or Secure MCP TunnelOAuth 2.1 (DCR, CIMD or a predefined client), or none for public dataOn Enterprise and Edu, an admin must grant developer-mode access.
OpenAI API (Responses API)An "mcp" tool with server_url, or tunnel_id for a private serverStreamable HTTP or HTTP/SSEOAuth access token in the authorization parameterAsks for approval before sharing data by default; allowed_tools trims the tool list.
Microsoft Copilot StudioMCP onboarding wizard on the agent’s Tools page, or a Power Apps custom connectorStreamable HTTP only; SSE unsupported since August 2025None, API key (header or query) or OAuth 2.0Servers can also be registered and approved through Agent 365.
Custom agents (official MCP SDKs)Your own code, using the TypeScript, Python, C#, Go, Rust or another official SDKstdio or Streamable HTTPOAuth 2.1-based authorization for HTTP (optional in the spec); stdio uses local credentialsYou own the client, so approvals, logging and tool limits are yours to build.

Checked against each vendor’s documentation in September 2026. Client features change often; we confirm them for your plan during discovery.

Official MCP server or a custom build?

Start with the vendor’s server when it covers your edition and your questions. Build where it stops.

Official MCP server or a custom build?
SituationOfficial serverCustom server
Read-only questions in the vendor’s cloud editionUsually enough; configure scope and accessAdds little
The system runs on-premisesOften not supported (Business Central’s server, for example, is online only)Runs inside your network under your identity rules
Agents need to write, with checksVaries; several start read-onlyValidation, approval steps and an audit record on every write
One request spans several systemsOne system per serverOne tool can combine systems with consistent rules
The vendor has no serverNot available (Paycor and ADP, for example)A governed server designed for the job
Business rules matterGeneric create, read and update toolsEncodes posting periods, tax rules or payroll logic

The MCP server status page lists the dated, vendor-verified status of each system we integrate.

Practical use cases

ERP in the chat window

“What is the open balance for Acme and when did they last pay?” answered from SAP or NetSuite in seconds: read-only, logged and permissioned per user.

Finance questions answered without a ticketERP integrations

CRM actions from the assistant

Create leads, update deal stages and draft follow-ups in Salesforce or HubSpot from Claude, with approval prompts for anything irreversible.

Sales admin time reclaimedCRM integrations

Analytics agents over your warehouse

Our Lexicon platform already speaks MCP; we extend the same governed natural-language access to your own data stack.

Governed questions over your dataLexicon

What an MCP server actually gives you

Every system your company runs, the ERP, the CRM, the ticketing tool, the warehouse, is a source of answers and a place where work happens. Today a person bridges them: reading a screen in one, typing into another. An MCP server describes the useful parts of a system as tools an AI assistant can call, so “check whether this customer is on credit hold and, if not, release the order” becomes a request rather than a procedure.

The protocol itself is simple; the value is in the design. Which tools to expose, how to name and constrain them, whose identity a call runs under, what must be logged and where a human has to approve: these are the decisions that separate a demo from something your finance team is allowed to use. That is the work we do.

Official servers changed the build-or-buy question

Over the past year many vendors released their own MCP servers, including NetSuite, Dynamics 365 Business Central, HubSpot and QuickBooks. Others have none: Paycor and ADP, for example. SAP publishes sample code for Business One rather than a supported product, and TallyPrime’s first official tools target data retrieval in Claude Desktop.

So we check what exists first. Where an official server fits, we configure and govern it. We build only what is missing: on-premises access, write actions with approvals, tools that span several systems, and the business rules generic tools cannot apply.

Systems we build MCP servers for

ERP and accounting: SAP Business One, S/4HANA and ByDesign, NetSuite, Dynamics 365 Business Central and Finance & Operations, Acumatica, Odoo, TallyPrime, QuickBooks, Xero. CRM and support: Salesforce, HubSpot, Zoho, Dynamics 365 Sales, Zendesk, Freshdesk. HR and payroll: Workday, BambooHR, ADP, Paycor. Commerce: Shopify, Adobe Commerce, BigCommerce, Amazon. Data: Snowflake, Databricks, BigQuery, PostgreSQL. And internal APIs, legacy databases and document stores nobody has an SDK for.

Why enterprises choose AIONDATA

We have shipped MCP in production: Lexicon and our agent products are MCP-native

Deep integration expertise: the same team builds ERP, CRM and eCommerce integrations, so your MCP server sits on solid data flows

Security first: identity propagation, scoped tools, audit logs and controls for personal data designed in

Model-agnostic: works with Claude, ChatGPT, Copilot Studio and custom agents through any MCP client

ISO 9001:2015 and CMMI Level 3 certified delivery processes

You own the code and can host it anywhere

Frequently asked questions

What is MCP (Model Context Protocol)?

MCP is an open standard, originally published by Anthropic and now supported by the major AI assistants and agent frameworks, that defines how an AI model discovers and calls external tools and resources. An MCP server is the component that exposes a system, such as your ERP, CRM or database, through that standard.

Our vendor already has an MCP server. Do we need a custom one?

Often not at first. If the official server covers your edition and the questions your team asks, we configure and govern it. A custom server earns its place when you run on-premises, need write actions with approvals, want one tool to span several systems, or depend on business rules the generic tools do not apply.

Is it safe to let an AI agent write to our ERP or CRM?

It is safe when the server enforces it. We scope tools to the minimum needed, run calls under the identity of the person making the request, add confirmation steps for irreversible actions and log every call. Many clients start read-only and add write tools once the team trusts the assistant.

Which AI assistants and models does it work with?

Any MCP-compatible client: Claude (web, desktop and Claude Code), ChatGPT, Microsoft Copilot Studio, the OpenAI API and custom agents built on hosted or open-weight models. The server is model-agnostic; the table above shows how each client connects.

Remote or local MCP server?

Remote servers run over HTTPS and suit shared use in Claude, ChatGPT and Copilot Studio. Local servers run on a user’s machine and suit developer tools such as Claude Code. Claude’s custom connectors are called from Anthropic’s infrastructure, so a remote server behind your firewall needs a planned network path.

Can our existing REST API become an MCP server without a rebuild?

Usually yes. An MCP server can wrap existing endpoints, but we still design tools around tasks rather than exposing every endpoint, because agents choose tools more reliably when there are fewer, clearer ones with tight inputs.

What happens when the vendor changes its API?

We pin API versions where the vendor allows it, version the server and run the evaluation suite on every change. With hosting and support, we review vendor release notes and update the server before a deprecation reaches you.

How long does it take to build an MCP server?

A focused server over one system with a handful of well-designed tools typically takes two to four weeks including security and evaluation. Multi-system servers or agent workflows on top take longer; we scope and quote after a short discovery.

Can you host the MCP server for us?

Yes: as a remote MCP server on our infrastructure under an SLA, or deployed into your AWS, Azure or GCP account. You own the code either way.

We already have integrations between these systems. Do we need MCP too?

They solve different problems. Integrations move data between systems automatically; MCP lets people and agents ask questions and take actions across those systems on demand. Existing integrations are a strong foundation, and we often build the MCP server on top of them.

Want your systems in the hands of AI agents, safely?

The enquiry form is at the top of this page. Tell us the workflow and the systems involved.

Go to the enquiry form