The Model Context Protocol is now a standard feature announcement: your software gets an MCP server, your AI assistant can finally reach your data. We checked 425 business-software vendors to see who actually ships one — and then asked a duller question nobody seems to answer. What does it cost, and which plan do you have to be on?
Read the grey bar first. For 42 of the 74 servers, we could not find a single sentence — on the product page, in the docs, in the announcement, or on the pricing page — that says which plan includes the MCP server or what it costs. Not “free”, not “Enterprise only”, not “contact sales”. Nothing.
That silence is easy to misread as good news. The reasonable assumption is that the server comes with whatever you already pay for, and for many vendors that is probably true. But it is an assumption, and the 32 vendors who do spell it out show why it is not a safe one: 9 of them put the MCP server behind a specific higher tier. Miro requires Enterprise. Freshservice restricts it to Enterprise, in a beta, by request through your account manager. Tenable requires a Tenable One licence. Similarweb requires a subscription with API access. If you budgeted on the assumption that MCP came free with your seat, those four are the shape of the surprise.
Every row links to the vendor’s own page — the page we read to make the call. Ordered by how restrictive the requirement is, silent vendors last.
| Vendor | Access | What their own documentation says you need |
|---|---|---|
| Bitscale (Beta (limited access)) | not limited to read-only in the docs | ● A specific higher tier only |
| Circle | not limited to read-only in the docs | ● A specific higher tier only |
| Freshservice (EAP beta) | not limited to read-only in the docs | ● A specific higher tier only |
| Miro | not limited to read-only in the docs | ● A specific higher tier only |
| Seamless.ai | not limited to read-only in the docs | ● A specific higher tier only |
| Serpstat | not limited to read-only in the docs | ● A specific higher tier only |
| Similarweb | not limited to read-only in the docs | ● A specific higher tier only |
| Tenable | not limited to read-only in the docs | ● A specific higher tier only |
| Woodpecker | not limited to read-only in the docs | ● A specific higher tier only |
| ActiveCampaign | not limited to read-only in the docs | ● Any paid plan |
| Amplitude | not limited to read-only in the docs | ● Any paid plan |
| Apollo | not limited to read-only in the docs | ● Any paid plan |
| Castmagic | not limited to read-only in the docs | ● Any paid plan |
| Databox (Under active development) | not limited to read-only in the docs | ● Any paid plan |
| Descript | not limited to read-only in the docs | ● Any paid plan |
| Frase | not limited to read-only in the docs | ● Any paid plan |
| Gorgias (Beta) | not limited to read-only in the docs | ● Any paid plan |
| Shippo | not limited to read-only in the docs | ● Any paid plan |
| Wati | not limited to read-only in the docs | ● Any paid plan |
| Beehiiv | not limited to read-only in the docs | ● Works on every plan, including free |
| Bright Data | not limited to read-only in the docs | ● Works on every plan, including free |
| ClickUp (Public beta) | not limited to read-only in the docs | ● Works on every plan, including free |
| ElevenLabs | not limited to read-only in the docs | ● Works on every plan, including free |
| Gamma | not limited to read-only in the docs | ● Works on every plan, including free |
| HubSpot | not limited to read-only in the docs | ● Works on every plan, including free |
| Jotform AI Agents | not limited to read-only in the docs | ● Works on every plan, including free |
| MeetGeek | not limited to read-only in the docs | ● Works on every plan, including free |
| monday.com | not limited to read-only in the docs | ● Works on every plan, including free |
| Plesk (Very early beta) | not limited to read-only in the docs | ● Works on every plan, including free |
| Replit (Beta) | not limited to read-only in the docs | ● Works on every plan, including free |
| Wistia | not limited to read-only in the docs | ● Works on every plan, including free |
| Zendrop | not limited to read-only in the docs | ● Works on every plan, including free |
| 1Password (Beta) | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| accessiBe | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Amplemarket | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| BidX (Beta (invite only)) | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Brevo | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Bybit | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Clay | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Close | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Clutch | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| CrowdStrike | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Customer.io | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Deel | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Dify | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Digit | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Envoy | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Fireflies.ai | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Freshworks | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Gixo | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Gusto | read-only | ● Not stated anywhere in their own docs |
| HiBob (Beta) | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Hostinger | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Hubstaff | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Keeper Security | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| lemlist | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Navan | read-only | ● Not stated anywhere in their own docs |
| Pylon | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| QuickBooks UK | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Reply.io | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| respond.io | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Rippling | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| RocketReach | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Runpod | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| ServiceM8 | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Softr | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| StoreSEO | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Storylane | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Sunsama | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Survicate | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Todoist | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Webflow | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Wrike (v2 in beta) | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
| Xero (Live (remote server in beta)) | not limited to read-only in the docs | ● Not stated anywhere in their own docs |
Names in amber carry an availability status other than “Live” on the vendor’s own page — beta, early access or invite-only. That is 12 of 74: 1Password, BidX, Bitscale, ClickUp, Databox, Freshservice, Gorgias, HiBob, Plesk, Replit, Wrike, Xero. Read-only is a separate column: 2 server(s) are documented as read-only (Gusto, Navan), and a read-only server can be fully live. Where the docs do not say, the column reads “not limited to read-only in the docs” — that is what we found, not a guarantee of write access.
An MCP server is not a minor integration. It is the seam through which an AI assistant reads and, increasingly, writes your CRM records, your payroll data, your support queue. Deciding whether to switch it on is a security review, a procurement question and a budget line. All three of those need to know what plan it lands on.
There is also a pattern here worth naming. Announcing an MCP server is a positioning move: it says the vendor is ready for the agent era. Pricing it is a commercial commitment, and commitments constrain you later — particularly if you suspect that agent traffic will cost you real money and you would like to keep the option of charging for it. Announcing without pricing gets the positioning at none of the cost. 42 of 74 is what that looks like when you count it.
We are not accusing anyone of hiding a fee. Most of these servers are probably included, and several vendors told the world so in one clear sentence — monday.com and Wistia both did it in their FAQ, in about fifteen words. It took the rest of the field no more effort to stay quiet.
This is not a random sample of the software industry. These 425 vendors are the ones in our own partner database: business software skewed towards SMB and mid-market, weighted to sales, marketing, support, HR and infrastructure tools. A survey of enterprise platforms, or of developer tooling, would produce a different number. Treat 17.4% as the adoption rate in this corpus, not in SaaS at large.
“Not stated” means not stated, not unavailable. We read the vendor’s own pages. If the requirement is written down somewhere we did not reach — inside a logged-in help centre, in a sales deck, in an email to customers — we would not have seen it, and the vendor is welcome to point us at it. We will correct the row and say so.
Partial statements are coded as silent. Webflow’s MCP reference names a paid add-on, but only for one analytics capability inside the server, not for access to the server itself. Todoist’s guide notes that Claude Code needs a paid Claude plan — a fact about Anthropic’s pricing, not Todoist’s. Neither tells you what you need from that vendor, so both count as “not stated”. Reasonable people could code those two the other way.
Documentation moves. The sweep ran on 2026-08-17. Our partner database has grown to 374 vendors since; the 351 we found nothing for were checked on that date and not after. A server launched last week is not in this count.
Starting set: the 425 vendors in our affiliate and partner database as of 2026-08-17. For each one we looked for a first-party MCP server through three machine signals: the official MCP registry (namespaces are reverse-DNS and DNS-verified, so a hit is strong first-party evidence), the vendor’s sitemap including docs., developer., help. and support. subdomains, and their /llms.txt and /llms-full.txt.
Every hit was then read by hand on the vendor’s own domain, because the signals produce false positives that matter:
docs.<vendor>/mcp is, at several vendors, the Mintlify documentation-search server that every customer of that docs platform gets for free — read-only, over their own docs. The product server is usually at mcp.<vendor> and often returns 401. Recognisable by tool names like search_* and query_docs_filesystem_*.The plan field records what the vendor writes, quoted where possible, and “not stated” where the pages say nothing. We did not estimate, infer from a comparable product, or ask sales. Earlier rounds of this scan used guessed URL patterns (/mcp, docs.x/mcp) and missed 21 servers that the registry-plus-sitemap sweep found, including Xero, CrowdStrike, monday.com, Amplitude and Webflow — which is a caution about any adoption figure built from URL guessing, including our own earlier ones.
Underlying data: 74 entries, each with a source URL on the vendor’s own domain, across 73 distinct domains. Our own MCP server, which we run over this corpus, is documented at /mcp/; what MCP is and how it works is explained at /ai/model-context-protocol/.
AIBuilder Marketplace, “65 SaaS vendors ship MCP. 38 won't say which plan you need.”, Report 03, 2026-09-15. Free to quote and reproduce with attribution (CC BY 4.0). The full table as structured data, or the list of 42 silent vendors on its own, is available on request — we would rather you republished it than re-scraped it.