Docs / Integrations

New Vintage MCP

Connect Claude or ChatGPT to your winery’s data and ask questions in plain language. Orders, customers, club members, campaign results: your AI app gets the answers straight from New Vintage, so you don’t have to export a thing.

Once you’re connected, skip the CSV exports and just ask:

Behind the scenes, your AI app checks which data your account can use, reads how it’s structured and writes the query for you. You stay in control the whole time: it can only use the tools you allow.

Before you connect

A quick checklist before you start.

Pro plan

You’ll need an active Pro subscription (Lifetime Pro counts). Free accounts and expired trials can’t use the MCP tools.

Connected data

Connect at least one integration, such as Commerce7, Klaviyo, Mailchimp or RedChirp, and let it sync. The MCP reads the data you’ve synced into New Vintage, never those services directly.

Sign-in

Just your usual New Vintage login. You sign in through your browser, so there’s no token to copy or paste.

Connect New Vintage

New Vintage is listed in both the Claude connector directory and the ChatGPT plugin directory. Choose your app with the switcher to see its steps. Everything else on this page applies to both.

Claude
Claude

Claude connector directory · Settings → Connectors

Available

ChatGPT
ChatGPT

Available

Microsoft Copilot
Microsoft Copilot

Not in a directory yet

Coming soon

Show steps for

Claude

ChatGPT

Microsoft Copilot

Copilot

Microsoft Copilot

Soon

Soon

Set up in Claude

1

In Claude, open Settings → Connectors.

2

Find New Vintage in the Claude directory and select Connect.

3

Sign in to New Vintage in the window that opens.

4

Review what Claude is asking for, then select Allow access.

5

Back in Claude, turn the connector on for your chat, and start asking.

That’s it. There’s no API key to create, store or rotate.

Disconnecting

You can disconnect whenever you like, from your AI app or from New Vintage.

In Claude

Settings → Connectors → New Vintage → Disconnect.

In New Vintage

Settings → Connected apps → Revoke.

Available tools

Last updated: October 5, 2026

The connector has five tools, and all of them are read-only. We add new ones over time and keep this list up to date.

Discover Tenant Data Sources

The starting point. It shows which integrations are connected, what data you can query, which tools are on and how to read the results.

List Tenant SQL Sources

Lists the approved data your account can query right now.

Describe Tenant SQL Sources

Describes how each data source is structured (columns, tenant key, time columns and joins) so your AI app can write the right query without guessing.

Safe Tenant SQL

Runs a single validated, read-only SELECT on your approved data and returns the rows.

Get More Tools

Lets New Vintage know when you ask for something the current tools can’t do yet. It doesn’t read or change any data.

Security and data handling

Written for IT and security reviewers: exactly how the connection works and how your data stays protected.

Connection

Endpoint

https://mcp.newvintage.ai/mcp — HTTPS only.

Protocol

Model Context Protocol over streamable HTTP.

Browser origins

Browser requests are only accepted from https://claude.ai, https://claude.com and the New Vintage app. ChatGPT connects server to server, so it doesn’t need a browser origin.

Authentication

Sign-in uses OAuth 2.0 with dynamic client registration and PKCE (S256), brokered by WorkOS AuthKit, so your organization’s identity provider and SSO settings still apply. There are no static, shared or long-lived API keys.

•

Access tokens expire after 60 minutes.

•

Refresh tokens are issued per user, tracked as a family and rotated on every use. If a spent token is ever replayed, the whole family is revoked, with a 10-second grace period for genuine retries.

•

The registration and authorization endpoints are rate-limited, both per IP address and overall.

•

RFC 7009 token revocation is available at /oauth/revoke.

•

Tokens are bound to a single environment, so a token from one won’t work in another.

Authorization

Every tool call re-checks four things on each request:

1

The access token is valid and was issued for this environment.

2

The session has the mcp:read scope. A session with no scope record is treated as read-only; write or admin access is never assumed.

3

You’re an active member of the tenant being queried. The tenant comes from your OAuth session, never from the AI. A tenantId argument can only choose between tenants you can already access.

4

The tenant has a paid Pro plan.

Query safety

Safe Tenant SQL is the only tool that runs a query, and several independent layers keep it in check:

Statement type

Only a single SELECT or WITH statement gets through. Data changes, schema changes, multiple statements and unsafe functions are rejected before anything runs.

Object allowlist

Every query is parsed, and each object it touches is checked against your tenant’s approved catalog. Sensitive and internal objects are off-limits.

Mandatory tenant scoping

Every query must include the quoted ‘__TENANT_ID__’ placeholder, which the server swaps for the tenant from your session. The AI never sees or supplies a raw tenant ID.

Validated equals executed

The statement that runs is exactly the one that passed validation, and it’s audited so nothing can be swapped in between.

Database-level isolation

Queries run under a least-privilege Postgres role, agent_sql_executor (NOLOGIN, NOBYPASSRLS), so row-level security keeps results inside your tenant. Even if validation were somehow bypassed, the database still wouldn’t return another tenant’s rows.

Result sampling

Large results come back as a preview rather than in full. The response is flagged with resultMode, resultWindow and a notice telling your AI app that the rows are examples only, and that totals, rankings, percentages and exports need a narrower or aggregate query. That way, it won’t confidently report a number from a partial sample.

What is logged

We record product analytics on MCP usage: which tool ran, whether it worked (and why not, if it didn’t), which data objects it used, row counts and the result mode.

Every event is scrubbed before it’s saved. Email addresses and raw SQL are removed, and the intent text is cleaned and flagged if anything was taken out. Query results are never written to analytics.

Data flow

The MCP only reads from the New Vintage database, which holds the data you’ve already synced. It never calls or writes to Commerce7, Klaviyo, Mailchimp or any other service during a query. Results go to your AI app to answer your question; see “Where your results go” in the setup steps for your app’s data terms.

Limits and known behavior

Pro only

Free accounts get a clear ‘requires a Pro account’ error instead of partial results.

Synced data only

The connector works with whatever your last integration sync brought in. Discovery shows each integration’s last sync time and status, so you always know how fresh the data is.

Read-only by design

Your AI app can’t place orders, edit customers, send campaigns or change settings through this connector.

One query per call

Each call runs one query, so bigger questions get answered in a few steps. Queries time out after 15 seconds by default.

Previews are not exports

For a complete export, use the export tools in New Vintage rather than asking your AI app to page through results.

Troubleshooting

Requires a Pro account

The winery account doesn’t have an active Pro plan. Check billing in your New Vintage settings.

A sign-in loop, or the connector never asks you to sign in

Remove the connector and add it again. Sign-in only starts when you add or reconnect it, not from inside an existing chat.

Access denied: this token lacks the mcp:read scope

Your session started before a permission change. Disconnect and reconnect to approve the updated access.

Your AI app reports a number that looks wrong

The answer may come from a sampled preview. Ask your AI app to run it again as an aggregate query (COUNT, SUM or GROUP BY) instead of counting the returned rows.

No data sources listed

None of your integrations have finished syncing yet. Connect one in New Vintage and give it time to sync.

Support and policies

Need a hand? Here’s where to find help, technical references and our policies.

AI intelligence for wineries
of all sizes.

RESOURCES

Help Center (Coming soon)

© 2026 New Vintage Labs · Napa, California

AI intelligence for wineries
of all sizes.

RESOURCES

Help Center (Coming soon)

© 2026 New Vintage Labs · Napa, California

AI intelligence for wineries
of all sizes.

RESOURCES

Help Center (Coming soon)

© 2026 New Vintage Labs · Napa, California