Docs / Integrations
New Vintage MCP
Connect Claude or ChatGPT to your winery’s data and ask questions in plain language. Orders, customers, club members, campaign results: your AI app gets the answers straight from New Vintage, so you don’t have to export a thing.
Once you’re connected, skip the CSV exports and just ask:
Behind the scenes, your AI app checks which data your account can use, reads how it’s structured and writes the query for you. You stay in control the whole time: it can only use the tools you allow.
Before you connect
A quick checklist before you start.
Pro plan
You’ll need an active Pro subscription (Lifetime Pro counts). Free accounts and expired trials can’t use the MCP tools.
Connected data
Connect at least one integration, such as Commerce7, Klaviyo, Mailchimp or RedChirp, and let it sync. The MCP reads the data you’ve synced into New Vintage, never those services directly.
Sign-in
Just your usual New Vintage login. You sign in through your browser, so there’s no token to copy or paste.
Connect New Vintage
New Vintage is listed in both the Claude connector directory and the ChatGPT plugin directory. Choose your app with the switcher to see its steps. Everything else on this page applies to both.
Available
Available
Coming soon
Show steps for
Claude
ChatGPT
Set up in Claude
1
In Claude, open Settings → Connectors.
2
Find New Vintage in the Claude directory and select Connect.
3
Sign in to New Vintage in the window that opens.
4
Review what Claude is asking for, then select Allow access.
5
Back in Claude, turn the connector on for your chat, and start asking.
That’s it. There’s no API key to create, store or rotate.
Disconnecting
You can disconnect whenever you like, from your AI app or from New Vintage.
In Claude
Settings → Connectors → New Vintage → Disconnect.
In New Vintage
Settings → Connected apps → Revoke.
Available tools
Last updated: October 5, 2026
The connector has five tools, and all of them are read-only. We add new ones over time and keep this list up to date.
Discover Tenant Data Sources
The starting point. It shows which integrations are connected, what data you can query, which tools are on and how to read the results.
List Tenant SQL Sources
Lists the approved data your account can query right now.
Describe Tenant SQL Sources
Describes how each data source is structured (columns, tenant key, time columns and joins) so your AI app can write the right query without guessing.
Safe Tenant SQL
Runs a single validated, read-only SELECT on your approved data and returns the rows.
Get More Tools
Lets New Vintage know when you ask for something the current tools can’t do yet. It doesn’t read or change any data.
Security and data handling
Written for IT and security reviewers: exactly how the connection works and how your data stays protected.
Connection
Endpoint
https://mcp.newvintage.ai/mcp — HTTPS only.
Protocol
Model Context Protocol over streamable HTTP.
Browser origins
Browser requests are only accepted from https://claude.ai, https://claude.com and the New Vintage app. ChatGPT connects server to server, so it doesn’t need a browser origin.
Authentication
Sign-in uses OAuth 2.0 with dynamic client registration and PKCE (S256), brokered by WorkOS AuthKit, so your organization’s identity provider and SSO settings still apply. There are no static, shared or long-lived API keys.
•
Access tokens expire after 60 minutes.
•
Refresh tokens are issued per user, tracked as a family and rotated on every use. If a spent token is ever replayed, the whole family is revoked, with a 10-second grace period for genuine retries.
•
The registration and authorization endpoints are rate-limited, both per IP address and overall.
•
RFC 7009 token revocation is available at /oauth/revoke.
•
Tokens are bound to a single environment, so a token from one won’t work in another.
Authorization
Every tool call re-checks four things on each request:
1
The access token is valid and was issued for this environment.
2
The session has the mcp:read scope. A session with no scope record is treated as read-only; write or admin access is never assumed.
3
You’re an active member of the tenant being queried. The tenant comes from your OAuth session, never from the AI. A tenantId argument can only choose between tenants you can already access.
4
The tenant has a paid Pro plan.
Query safety
Safe Tenant SQL is the only tool that runs a query, and several independent layers keep it in check:
Statement type
Only a single SELECT or WITH statement gets through. Data changes, schema changes, multiple statements and unsafe functions are rejected before anything runs.
Object allowlist
Every query is parsed, and each object it touches is checked against your tenant’s approved catalog. Sensitive and internal objects are off-limits.
Mandatory tenant scoping
Every query must include the quoted ‘__TENANT_ID__’ placeholder, which the server swaps for the tenant from your session. The AI never sees or supplies a raw tenant ID.
Validated equals executed
The statement that runs is exactly the one that passed validation, and it’s audited so nothing can be swapped in between.
Database-level isolation
Queries run under a least-privilege Postgres role, agent_sql_executor (NOLOGIN, NOBYPASSRLS), so row-level security keeps results inside your tenant. Even if validation were somehow bypassed, the database still wouldn’t return another tenant’s rows.
Result sampling
Large results come back as a preview rather than in full. The response is flagged with resultMode, resultWindow and a notice telling your AI app that the rows are examples only, and that totals, rankings, percentages and exports need a narrower or aggregate query. That way, it won’t confidently report a number from a partial sample.
What is logged
We record product analytics on MCP usage: which tool ran, whether it worked (and why not, if it didn’t), which data objects it used, row counts and the result mode.
Every event is scrubbed before it’s saved. Email addresses and raw SQL are removed, and the intent text is cleaned and flagged if anything was taken out. Query results are never written to analytics.
Data flow
The MCP only reads from the New Vintage database, which holds the data you’ve already synced. It never calls or writes to Commerce7, Klaviyo, Mailchimp or any other service during a query. Results go to your AI app to answer your question; see “Where your results go” in the setup steps for your app’s data terms.
Limits and known behavior
Pro only
Free accounts get a clear ‘requires a Pro account’ error instead of partial results.
Synced data only
The connector works with whatever your last integration sync brought in. Discovery shows each integration’s last sync time and status, so you always know how fresh the data is.
Read-only by design
Your AI app can’t place orders, edit customers, send campaigns or change settings through this connector.
One query per call
Each call runs one query, so bigger questions get answered in a few steps. Queries time out after 15 seconds by default.
Previews are not exports
For a complete export, use the export tools in New Vintage rather than asking your AI app to page through results.
Troubleshooting
Requires a Pro account
The winery account doesn’t have an active Pro plan. Check billing in your New Vintage settings.
A sign-in loop, or the connector never asks you to sign in
Remove the connector and add it again. Sign-in only starts when you add or reconnect it, not from inside an existing chat.
Access denied: this token lacks the mcp:read scope
Your session started before a permission change. Disconnect and reconnect to approve the updated access.
Your AI app reports a number that looks wrong
The answer may come from a sampled preview. Ask your AI app to run it again as an aggregate query (COUNT, SUM or GROUP BY) instead of counting the returned rows.
No data sources listed
None of your integrations have finished syncing yet. Connect one in New Vintage and give it time to sync.
Support and policies
Need a hand? Here’s where to find help, technical references and our policies.
Website
Documentation
Privacy policy
Terms of service