Skip to content

Guide

In-product connectors versus MCP servers

A packaged connector is installed and governed inside the AI product. An MCP server is a standards-based service that an assistant calls as a tool, and may be run by a vendor, a third party, or your own team. The difference matters most for governance.

Written and researched by Christian Stewart, Founder and Editor

At a glance

Choose an in-product connector when you want the AI vendor to own distribution, review and admin controls; choose an MCP server when you need access to a system the vendor does not package, and you accept responsibility for hosting and auditing it. The protocol is the same idea in both cases — the difference is who governs the tool, and that is a procurement decision more than a technical one.

Packaged connector
Installed, reviewed and revoked inside the AI product
MCP server
Standards-based service the assistant calls as a tool
Who governs it
Vendor for connectors; you or a third party for MCP
Main risk difference
Registry or package review varies by platform; custom MCP servers still require your own vetting

Both approaches end in the same place — an assistant reaching a system it does not own — but they get there differently, and the differences show up in procurement and governance rather than in the chat window. If the underlying vocabulary is still unfamiliar, the AI connector basics guide covers it first.

Where a platform offers a directory or package listing, some review may happen before a server is listed, but the depth of that review differs by platform and does not extend to a server you register yourself. Before you connect a specific server, work through how to evaluate an MCP server before connecting it, which covers publisher provenance, tool authority, token handling, approvals, logging and revocation.

Neither model is universal. ChatGPT apps and custom connections and Claude remote connectors and desktop extensions are governed by different admin surfaces, and a built-in connector is not necessarily an MCP implementation. An MCP server also does not port unchanged between clients: each platform decides what it will register, what transport it accepts, and which tools it will surface.

Packaged connectors compared with MCP servers
DimensionPackaged connectorMCP server
Who operates itThe AI platform vendorThe tool vendor, a third party, or you
Where it is enabledIn the assistant's settingsBy registering a server endpoint
Typical governanceVendor admin controlsYour own deployment and access controls
PortabilitySpecific to that platformAny client implementing the protocol
CustomisationFixed feature setYou define the tools exposed

Choosing between them

  • Prefer a packaged connector when the capability you need already exists and centralised administration is an advantage.
  • Prefer an MCP server when you need tools that no gallery offers, or when the data must not leave infrastructure you control.
  • Treat a self-hosted server as production software: it needs an owner, monitoring, and a patching plan.

Whichever model you pick, the review is the same one: a security and permission review of the authorising account and its scopes.

Connector Scout records the connection type

Every connection record stores its connection type, so a first-party connector is never presented as equivalent to a third-party automation or a self-hosted MCP server.

How this looks in real records

Questions

Sources