Loading article…
Loading article…
Last updated on Aug 25, 2026
The Maxio Model Context Protocol (MCP) integration controls what an approved AI client, such as ChatGPT or Claude, can reach in your Maxio data. Connector configuration, assigned roles, enabled tools, API credential permissions, logging, and governance controls together decide what reaches an AI client and what does not.
The integration is not enabled by default, and an administrator cannot switch it on unaided. Both a set of account-level prerequisites and explicit configuration have to be in place first.
Three conditions are outside an administrator's control and have to hold before Maxio MCP appears under Integrations:
Once those conditions hold, an administrator completes the setup:
To configure the connector, see the Configure the Maxio MCP Connector help article.
If the integration is disabled, users cannot reach Maxio through ChatGPT, Claude, or another MCP-compatible client using the Maxio MCP connector.
Administrators can also disable the integration, restrict access to approved users or teams, limit the connector to read-only access, and control which tools or workflows are exposed through MCP.
An AI client only receives information from Maxio when an authorized user submits a request through an enabled MCP connector. Each request carries the identity of the person who made it.
The AI client does not independently browse, monitor, or continuously scan Maxio data. Access occurs when a user asks a question or initiates an approved workflow that uses an enabled MCP tool.
Depending on your configuration, MCP tools may be able to access selected Maxio data, such as:
The exact data available depends on the connector role, enabled MCP tools, API credential permissions, and the user's request.
Potentially, yes.
Because Maxio manages billing, subscription, revenue, and customer information, data accessed through MCP may include customer or commercial information, such as:
The amount of information exposed through MCP depends on which Maxio modules are connected, which tools are enabled, which reports are available, and what permissions are assigned to the connector.
Maxio recommends enabling only the tools and access required for approved business use cases.
Potentially, depending on your Maxio configuration and the data stored in your account.
The MCP integration may access billing-related information such as invoices, payments, subscriptions, and reporting data. Some customers may store regulated or sensitive business information within those records.
The MCP integration is not intended to collect payment card or bank account information through an AI client. Current subscription creation workflows support remittance-style payment collection only. Credit card and bank account collection flows are intentionally restricted within MCP workflows.
Customers should evaluate their own data classification policies before enabling MCP access.
The Maxio MCP server does not support field-level masking or exclusion of sensitive data. The MCP layer returns data much as an API does, exposing whatever the enabled tools surface, so your control is at the tool level: disable an MCP tool, such as a customer or subscription tool, to keep the data it reaches out of scope.
Within that constraint, administrators limit exposure by configuring the integration using least-privilege principles.
Recommended controls include:
For more guidance, see the MCP Best Practices Guide help article.
The integration can be configured as either read-only or read/write, depending on the assigned role and enabled tools.
The Analyst role is designed for read-only reporting, analysis, auditing, and customer support workflows.
The Bookkeeper role includes Analyst access and adds selected create capabilities, such as creating customers, subscriptions, products, components, coupons, product families, and sales orders where supported.
Most customers should begin with read-only access unless there is a clear business need for write access.
For the full list of available tools by role, see the Maxio MCP Supported Tools help article.
The MCP integration uses a dedicated connector permission model configured by the customer administrator.
Access is governed through:
The effective access available through an AI client is constrained by both the permissions assigned to the Maxio API credentials and the tools enabled for the MCP connector.
The Maxio MCP integration is implemented through the Maxio MCP server.
At a high level:
The integration does not provide unrestricted database access.
Data is generally accessed on demand through Maxio APIs.
The AI client does not connect directly to the Maxio database. The MCP integration retrieves information needed to fulfill a specific user request. The standard MCP workflow is not designed to create a broad replicated copy or searchable index of your Maxio environment.
Limited operational data may be temporarily stored for platform functionality, auditing, and troubleshooting.
Examples may include:
Maxio applies encryption and operational security controls to sensitive stored integration data.
Purging a Maxio Site also purges the data held for that Site on the MCP server, so removing a Site does not leave its data behind on the MCP side.
The core integration flow may involve:
Supporting infrastructure services may also be used for authentication, monitoring, logging, and secure storage.
Customers should review the terms, data handling practices, and retention policies for their selected AI client.
Yes. The platform includes logging and audit capabilities that may capture:
These controls support customer auditing, troubleshooting, and governance requirements.
Yes.
Maxio recommends treating AI-generated outputs as advisory. Human review should remain part of workflows involving:
MCP can help retrieve data, summarize information, and support analysis, but it should not replace human accountability or required business approvals.
Before enabling MCP in production, Maxio recommends defining internal AI usage policies.
Appropriate use cases may include:
Restricted or prohibited use cases may include:
For examples of appropriate prompts and tool usage patterns, see the Example Prompts for Maxio MCP Tools help article.
Maxio does not use customer data accessed through MCP to train AI models.
Data handling and retention for third-party AI clients are governed by the customer's subscription plan, workspace configuration, and contractual terms with that provider. Customers should review the published privacy and data handling documentation for their selected AI client.
For an introduction to what MCP is and which clients it supports, see the Understand the Maxio Model Context Protocol (MCP) help article.
Still need help?
Reach out and our support team will take it from here.