You can add a custom connector to Claude without paying for a plan. Anthropic allows one on the Free plan, and the dialog that creates it asks for little more than a name and a server URL. The part that trips people up comes right after: how does Claude prove who it is to your server? The answer depends on whether the server speaks OAuth, expects a bearer token in the Authorization header, or wants a static API secret in a custom header. Below you get the exact menu names, the field labels, a decision table for each sign-in method, and the failure modes people hit in practice. Every product detail follows Claude's own connector documentation as it reads in October 2026.
💡 Short answer: Free plan users can add one custom connector. Pick OAuth when each person signs in as themselves. Pick No sign-in plus Request headers when the server wants a bearer token or a fixed API secret, and remember that Request headers is still a beta feature.
What a Custom Connector Is
Remote MCP in plain terms
A connector is a bridge between Claude and another service. Claude speaks the Model Context Protocol (MCP), an open standard that lets a server publish tools, which are actions Claude can call, and resources, which are data Claude can read. When the server lives on the internet and answers over HTTPS, it is a remote MCP server. The URL you give Claude is the address where that server accepts MCP requests, for example https://mcp.example.com/mcp.
Once connected, Claude can read data from the app behind the server, create or change records, and take actions on your behalf. That reach is exactly why the authentication choice deserves a few minutes of attention.
Custom versus directory connectors
The Connectors Directory lists services that already ship a ready-made connector. Some are verified by Anthropic and others come from the community. A custom connector is anything you add yourself by URL, and Claude treats it as a connection to an unverified service.
- Directory connector: one click, maintained by the vendor, either verified or community-built.
- Custom connector: any remote MCP server you have a URL for, with the authentication settings chosen by you.
If the service you want is already in the directory, connect it from there. Take the custom route when you built the server yourself, when your company runs one internally, or when a vendor publishes an MCP URL without a directory listing.
Does the Free Plan Work?
One connector on Free
It does. Custom connectors by URL work on Free, Pro, Max, Team and Enterprise. The Free plan comes with a single custom connector, and that limit applies to the account you are signed in with. One slot is enough for a real trial: connect your own server, run a few read-only requests, and decide whether the setup deserves a paid plan or a second server.

💡 Spend the slot wisely. Changing a connector's sign-in settings later means removing it and adding it again, so decide between OAuth and request headers before you click Add.
| Plan | Who adds the connector | Limit |
|---|
| Free | You, in your own account | One custom connector |
| Pro and Max | You, in your own account | No cap mentioned in the docs |
| Team | An Owner, for the organization | Members connect with their own accounts |
| Enterprise | An Owner, or a member whose custom role manages the organization's libraries | Members connect with their own accounts |
Team and Enterprise setup
On Team and Enterprise, an Owner opens Organization settings > Connectors, selects Add, then Custom. If Claude asks for the connector type, choose Web. The Owner enters the URL, optionally adds an OAuth client ID and secret, and clicks Add. Members then open Customize > Connectors, find the entry with the Custom label, and click Connect to sign in with their own account. A member without a qualifying role cannot add a custom connector, so send the URL to an Owner instead.
Add One in Five Steps
Steps on Free, Pro and Max
- Open Customize > Connectors.
- Click Add custom connector.
- Enter the remote MCP server URL.
- Optionally enter OAuth credentials.
- Click Add.

The layout of the dialog varies by organization. Some people see a name, a URL and an expandable settings area on one screen, with the OAuth client ID and secret tucked inside it. Others get a two-step flow that asks them to choose the authentication settings explicitly. Both routes finish in the same place: a connector in your list with a Custom label.
After saving, open a fresh chat and test with something harmless. Ask Claude to list the tools the connector offers, then run one read-only request. If that works, you can trust the plumbing before you let Claude write anything. Prefer the terminal? The same server can be added to Claude Code from the command line, as the MCP in Claude Code quickstart shows.
What each field means
| Field | What to enter |
|---|
| Name | A label you will recognize in the connector list |
| MCP server URL | The HTTPS address where the server accepts MCP requests |
| Authentication | Sign in now, Sign in when needed, or No sign-in |
| OAuth client | Claude's published identity, automatic registration, or your own client ID |
| Request headers | Fixed credentials sent on every request (beta) |
| Transport | Leave the default unless the server's own docs say otherwise |
A URL that ends in /sse selects the older SSE transport. Everything else uses the default. Changing the transport setting without a reason from the server's documentation is a reliable way to break a working setup.
Once the connector exists, you can switch it on or off per conversation: click the + button in the chat, choose Connectors, and toggle it.
OAuth, Bearer Token or API Secret
Three situations, three setups. Start with the table, then read the section that matches your server.
| The server expects | Choose in Claude | Who holds the credential |
|---|
| OAuth sign-in per person | Sign in now or Sign in when needed | Each user, through the server's sign-in page |
| A bearer token | No sign-in plus a request header named authorization | One shared token, stored by Claude |
| A static API secret | No sign-in plus the header name the server expects | One shared secret, stored by Claude |
| Nothing (public server) | No sign-in | Nobody |
OAuth: each person signs in
OAuth is the right choice when every person should act as themselves. The Authentication setting has two OAuth modes. Sign in now sends each user through the server's OAuth flow before they use the connector. Sign in when needed lets Claude connect without credentials and prompt for sign-in only when the server asks for it.

The OAuth client setting decides how Claude introduces itself to the server's authorization server:
- Use Claude's published identity: the recommended option. The server reads Claude's client details from a Client ID Metadata Document that Anthropic hosts. You configure nothing, but the server must support this method.
- Register automatically: Claude registers an OAuth client with the server as users connect, using Dynamic Client Registration. It works with most servers and adds client registrations over time.
- Use your own OAuth client: enter a client ID you registered with the server. Leave the secret blank unless your authorization server requires one.
Read the permission scopes on the consent screen before you approve. A connector that asks for write access to everything deserves a second look.
Bearer token in request headers
A bearer token is a credential where whoever bears it gets in. Servers expect it in one place: Authorization: Bearer <token>. For a long time the custom connector dialog had no field for it, and developers asked for one in public reports such as issue #112 on Anthropic's claude-ai-mcp repository, filed in March 2026. The answer today is the Request headers section of the dialog, which is in beta and available to a limited set of organizations. If you do not see it, your organization does not have access yet.

The detail that causes most failures: Claude sends the header value exactly as you type it. It never adds a scheme or prefix.
| You enter | Claude sends |
|---|
Bearer your-token | Authorization: Bearer your-token |
your-token | Authorization: your-token |
Most servers reject the second form. If the server's docs show Authorization: Bearer YOUR_TOKEN, type Bearer , a space, and then the token. Basic authentication works the same way: type Basic followed by the base64-encoded credentials.
💡 OAuth blocks the Authorization header. On a connection that uses OAuth you cannot set Authorization as a request header, because OAuth already uses it. A bearer token needs No sign-in.
Developers who work with PicassoIA's own developer API will recognize the pattern. It lives at https://api.picassoia.com/v1, and every call carries a bearer credential that begins with pia_sk_. Same header, same Bearer prefix, same rule: whoever holds the string gets in, so it never belongs in a screenshot.
Static API secret as a header
Some servers skip bearer tokens and want a plain secret in a header of their own. The documented route is simple: choose No sign-in, then add the secret under Request headers. Claude stores it as the connector's credential.

Here is how the Request headers section behaves:
- Header name: pick one from the list, which offers standard authentication and routing names such as
authorization and x-auth-token, or choose Custom header to type another.
- Approval: Anthropic reviews and approves each custom header name before Claude sends it to a third-party server. An unapproved name is rejected with an error when you save. To request approval, contact Claude support.
- Required or optional: a required header with no stored value makes the connection fail. An optional header with no value is left out of the request.
- Limit: up to four headers per connector.
- Storage: Claude keeps each value securely and does not show it again after you save.
This setup suits a shared credential, such as an internal tool or a service account. If each person needs their own identity, go back to OAuth. You can also combine the two: request headers can ride along with OAuth, including OAuth with your own pre-registered client, to verify where a request came from or to satisfy a gateway that wants its own routing header.
Network and Security Checks
Public internet and IP ranges
Your MCP server must be reachable over the public internet from Anthropic's IP ranges. If a firewall sits in front of it, allowlist Anthropic's published addresses. A server inside a private network is out of reach for a plain connector, and Anthropic points those cases to MCP tunnels.

A quick pre-flight list for server owners:
- The URL starts with
https:// and points at the exact path that accepts MCP requests.
- The server answers from the public internet, not only from your office network or VPN.
- Anthropic's IP ranges are allowed through any firewall or gateway.
- The credential you plan to type works when you test it from a plain HTTP client first.
Review tools before approving
A remote MCP server gives Claude tools that can read, create, modify or delete data. Treat the first connection like hiring a contractor:
- Connect only to servers from trusted organizations.
- Review the requested permission scopes during sign-in.
- Watch for prompt injection. Claude has built-in protections, but they are not a license to relax.
- Read tool approval requests carefully, and click Always allow only for servers you trust.
- Turn off connectors you are not using, from the + menu in the chat.
- Block tools you never need: go to Customize > Connectors, select the connector, and set the tool's permission to Blocked.

If a server behaves like a malicious one, report it to Anthropic's Bug Bounty Program.
Fixing Connection Errors
Common errors and fixes
| Symptom | Likely cause | Fix |
|---|
| Save fails with a header error | The custom header name is not approved | Pick a name from the list, or ask Claude support to approve yours |
| 401 right after connecting | The header value lacks the Bearer prefix | Remove the connector and add it again with Bearer plus the token |
| Connection fails with no sign-in prompt | A required header has no stored value | Re-add the connector and fill the value, or mark the header optional |
| Server never answers | A firewall blocks Anthropic's IP ranges, or the server is private | Allowlist the ranges, or use MCP tunnels |
| Protocol errors on a working server | Wrong transport setting | Follow the server's docs; a URL ending in /sse selects the older transport |
| No Request headers section | The beta is not enabled for your organization | Use OAuth, or ask whoever manages your Claude account |

Settings you cannot edit later
From Customize > Connectors (Owners use Organization settings > Connectors), you can edit a connector's name or URL, or remove it. You cannot change authentication settings after adding it, which includes OAuth credentials and request headers alike. To change them, remove the connector and add it again with the new details. On Team and Enterprise, members then need to reconnect.
That rule also shapes how you rotate a token. When a bearer token expires or leaks, rotate it at the source, remove the connector, and add it again with the new value.
How to Use Sonnet 5 on PicassoIA
Why a second Claude helps
While you set up connectors, a separate chat is useful for the writing around the work: decoding a server error, drafting a README that lists your tools, or turning your server's auth docs into the exact header value to type. Picasso IA hosts several Claude models in its Large Language Models category, so you can keep that chat open next to your Claude settings.
The steps in Picasso IA
- Open Claude Sonnet 5 in the Large Language Models collection.
- Write the prompt. Paste the error text, the server docs excerpt, or your header table, with every real credential replaced by
<TOKEN>.
- Add an optional System Prompt so the instructions carry through the whole conversation, for example: "You review MCP server setups. Never ask me to paste a live secret."
- Attach an image if a screenshot says it faster than text. Blur or crop any secret first.
- Choose the effort level, from low to max. Low skips extended reasoning for the fastest reply. Go higher when you chase a tricky OAuth failure.
- Set a maximum response length, or leave the default, and generate.
- Reply in the same thread to refine the answer or hand Claude the next step.

💡 Never paste a live credential into any chat. Swap it for a placeholder first. The model page lists 3 credits per generation and says you can test Claude Sonnet 5 without a paid plan.
Make Your Own Images on Picasso IA
Docs, launch posts and tutorials about your MCP server all need pictures, and stock photos rarely match what you built. Picasso IA turns a sentence into a photorealistic image in seconds. Start with PicassoIA Image for quick scenes, try Flux 2 Pro when composition matters, or compare with Seedream 5 Lite. The platform also handles image editing, super resolution and video generation, so one account handles the whole asset pipeline.
Describe the subject, then add the light, the lens and the setting. A prompt like "A developer reviewing a printed permissions list at a clean desk, soft window light from the left, 50mm lens, shallow depth of field" gives you a usable header image on the first try. Open Picasso IA, run your first prompt, and see how far one sentence can take you.