MCP in MintHCM has been part of the product’s core since version 4.2.0 (August 2025), not a plugin bolted on from outside.
Role-based access control for MCP tools shipped in version 4.3.0; OAuth 2.1 authentication for remote connections followed in version 4.3.3 (September 2026).
Requests travel directly from the AI client to a company’s own MintHCM instance – nothing in between is logged or tracked.
Every write operation (creating, updating or deleting a record) requires user confirmation before it happens.
MintHCM is one of the few open source HR systems listed in the Claude Marketplace (Anthropic, September 2026).
Introduction
MCP in MintHCM is a server built into the system that lets AI assistants like Claude read and update HR data in plain language, without logging into the system, building a report or writing a query. It is not an external add-on or a third-party service – it is part of the same codebase published on GitHub. For a business, that means a question like “how many active recruitments do we have today” gets answered from live data, not from last week’s export.
What is MCP, and why does HR software need it at all?
MCP (Model Context Protocol) is an open standard created by Anthropic that connects an AI assistant to an external system in a unified way – one “socket” instead of a separate integration for every tool. For an HR system, that means the same protocol handles questions about candidates, leave or working time, without a separate API for each function.
Without this standard, every AI integration with an HR system would need its own custom connection, maintained, updated and secured separately. MCP removes that burden, because the AI client and the HR system speak the same language by definition of the protocol, not by agreement between two specific companies.
How Does MCP in MintHCM Actually Work?
The MCP server runs on a company’s own MintHCM instance, under the /mcp/ path – not on shared infrastructure. A request passes through five steps: the AI client connects to that address, authenticates via OAuth 2.1, discovers the available tools, calls a specific tool, and MintHCM checks whether the logged-in user’s role has permission for it before returning a result. For write operations, a sixth step is added: human confirmation.
This architecture matured in stages rather than arriving all at once:
Version
What changed in MCP
4.2.0 (August 2025)
MCP becomes part of the product core
4.3.0
Access to MCP tools becomes controlled by role permissions
4.3.3 (September 2026)
OAuth 2.1 for remote connections; server rules required for the /mcp/ path
Importantly, this isn’t an integration reserved for Claude. MCP is an open standard, so the same server works with any MCP client – VS Code, GitHub Copilot Chat and others, present and future.
MCP in MintHCM isn’t an add-on bolted on from outside – it’s the same code anyone can read on GitHub.
What operations can Claude actually perform through MCP?
Claude can read data without any limits beyond the user’s own permissions: searching records with filters, counting them, summing field values, checking relationships between records, and running existing reports. Write operations – creating, updating or deleting a record, and creating or removing a relationship – always require the user’s confirmation in the conversation before anything changes.
It’s worth noting that MintHCM doesn’t have a dedicated tool for every business action. Scheduling a meeting with a candidate doesn’t use a special “book a meeting” function – Claude simply creates a standard record in the Meetings module, the same mechanism used for any other record. That shows there’s no hidden logic underneath: it’s the same set of CRUD operations already available from the MintHCM interface itself.
How is this different from AI integrations in closed HR systems?
Closed HR systems often offer AI as a service from a single, chosen vendor, sometimes built by a third party wrapping their API rather than by the system’s own maker. MintHCM is released under AGPL-3.0, and the MCP server is publicly available in the same repository as the rest of the system. A company deploying it can check the mcp/README.md documentation itself, instead of relying solely on a vendor’s assurances.
The second difference is independence from the AI model provider. MintHCM doesn’t lock a company into one assistant – the same MCP server works with Claude as well as any other client that follows the standard. A company chooses its AI tool independently of its choice of HR system, rather than buying both bundled from one vendor.
What does this mean for security and data handling?
A request sent by Claude goes directly to a company’s own MintHCM instance – not through any external servers. The server logs only OAuth authentication events (client registration, token issuance, errors), locally, in a log kept on the client’s own instance, without the content of any query and without employee data. None of it leaves the customer’s own infrastructure.
Access isn’t open by default, either. An administrator has to deliberately configure server rules for the /mcp/ path and grant the relevant role permission to use MCP tools – only then does a user account start seeing anything through Claude, and exactly as much as it would see logged into MintHCM directly. This also matters for AI Act transparency obligations (Article 50, in force from 2 August 2026): open source code and local logs give a company something to show an auditor, instead of pointing them to an external vendor’s word.
Frequently Asked Questions
Does MCP in MintHCM only work with Claude?
No. MCP is an open standard from Anthropic, but it supports any client that follows the protocol, including VS Code and GitHub Copilot Chat, not only Claude.
From which MintHCM version do I have access to MCP?
The MCP server has been part of the core since version 4.2.0 (August 2025). Remote connections with OAuth 2.1 authentication require version 4.3.3 or later.
Can Claude change data without my approval?
No. Every write operation – creating, updating or deleting a record – requires user confirmation in the conversation before it happens.
Is the content of my questions to Claude stored anywhere on MintHCM’s side?
No. The MintHCM server logs only OAuth events (registration, token, errors), without query content, locally on the client’s own instance.
Do I need to configure anything before MCP starts working?
Yes. An administrator has to set server rules for the /mcp/ path and grant the relevant role permission to use MCP tools – access isn’t enabled by default for every account.
Does Claude see more data than a regular MintHCM user?
No. Claude operates with the permissions of the account it’s signed in with, seeing exactly the modules and records that user would see inside MintHCM itself.
How is MCP different from the “AI Agent” feature in MintHCM?
These are two independent mechanisms. The AI Agent is a separate chat embedded in the interface with a human-in-the-loop mechanism, while MCP lets any external AI client, including Claude, connect directly to a MintHCM instance.
Summary
MCP in MintHCM changes where a company gets its answers about HR data – instead of clicking through the system, it’s enough to ask. What sets this apart from many competing solutions is where it was built: into the product’s core, under an open license, on the customer’s own infrastructure, not the vendor’s.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.