Planday MCP server icon

Planday

by Planday

HIPAA CompliantSOC2 ReadyISO 27001 Ready
Productivity12 tools

Read rotas, staff records and leave balances from a Planday workspace, and draft, assign, approve and publish shifts from an AI agent. Anthropic lists 12 tools; Planday publishes no tool list. OAuth sign-in, no application scopes.

Verified connector

Listed by Anthropic as a partner connector in its Connectors Directory.

Connection checked by Agentman on .

Anthropic states this reflects the level of review a connector received, not a security audit.

Connect Planday via MCP

https://public-mcp-server.prod-westeurope.planday.cloud/mcp

Works in any MCP-compatible client. In Agentman Studio it is one click — no config file to edit.

Planday Tools & Capabilities (12)

Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.

Limits

  • Planday publishes no tool list for this server. The 12 names come from Anthropic's directory. We checked both directions: no name appears in Planday's documentation, and Planday's help article names no tool. This is the "no vendor enumeration" case — there is no second list to diff, so we cannot report a clean listing, only that nothing exists to check it with. That is weaker than "no undisclosed tools were found", and the difference matters.
  • We could not read tool schemas or safety annotations. The endpoint returned 401, so no parameter-level detail, readOnlyHint or destructiveHint is published here. Every read/write label on this page is our classification.
  • Only one route to a second enumeration exists, and it is a screenshot. Planday's help article shows the Tool permissions screen — the one place a real tool list would be visible — as an image. We did not transcribe names from it, so we treat it as no enumeration rather than as a partial one.
  • The OAuth grant draws no line inside the surface. The RFC 9728 descriptor declares scopes_supported of openid and offline_access. Nothing at consent separates reading a rota from publishing one, or reading a leave balance from approving a swap. The only boundary between the routine write and the consequential one is the client-side Tool permissions screen — a Claude control, not a Planday grant. Revoke it and the boundary is gone.
  • The 79-scope list belongs to Planday's platform, not to this connector. Planday's identity service advertises granular scopes including shift:delete, salaries:read, payrates:read and impersonate. We checked attribution three ways: the identical 79-scope list is served by id.planday.com, id.prod-global.planday.cloud and id.prod-westeurope.planday.cloud alike, so it is Planday's whole API vocabulary rather than a signal about this connector. It is not evidence of a hidden tool surface — but it does show the account you sign in with holds privileges far beyond what these 12 tools use.
  • Two consented categories match no tool name. The consent screen requests time and cost, and contract rules. No tool in the listing names either. Whether tools read them, or the grant is simply broader than the tools, is not documented.
  • A second regional endpoint exists and is not listed. public-mcp-server.prod-global.planday.cloud serves a byte-identical landing page, an equivalent RFC 9728 descriptor, and the same 401 challenge. Anthropic's directory lists only the West Europe host. We found no Planday documentation explaining which workspaces belong to which region, or how to choose.
  • Data residency is not documented for this connector. Planday's data-security article defers every residency question — where data is stored, whether it leaves the EEA, which sub-processors are used — to its Data Processing Agreement and legal pages rather than answering it. The endpoint's hostname is the only regional statement we found.
  • Long lists are truncated. Planday's troubleshooting table states that long lists are cut short and advises narrowing to one department or a shorter date range. An agent summarising "everyone scheduled next month" may be summarising a partial set without saying so.
  • Rate limits are documented for the platform API, not for MCP. Planday publishes per-second and per-minute quotas per client and per portal — the example response shows 20 and 750 per portal, 100 and 2,000 per client — returned as HTTP 429 with x-ratelimit-* headers. We found no statement that the MCP server shares them.
  • Planday Pro is required. Lower subscription tiers are not eligible.
  • Whether a publish notifies staff is unresolved. Planday documents the Message/SMS choice in the product UI, but not whether the MCP tool exposes, sets or suppresses it. Treat it as unknown.

Frequently asked questions

Yes. Four of the twelve tools change state: create_draft_shift, assign_shift, publish_draft_shifts and approve_shift_swap. Publishing makes a draft visible to staff, assigning moves a shift onto a named person, and approving a swap rewrites two employees' rotas at once. The other eight only read. Planday states nothing is deleted.

Yes, as far as your own Planday login reaches. list_employees returns staff records, and Planday's HR API defines an employee as carrying national identity number, bank account, birth date, home address, phone numbers and email. If an Administrator connects, that reach includes payroll data, because Administrators can view and edit payroll information.

Not by itself, but a publish can trigger one. Planday documents that publishing shifts offers Message or SMS notification, and that open-shift notifications are sent automatically and cannot be disabled by admins. Whether publish_draft_shifts sets those flags is not documented. SMS is charged and Planday states it cannot be fully disabled platform-wide.

Twelve, according to Anthropic's directory on 2026-08-23. Planday publishes no tool list of its own — its Claude help article describes capabilities in prose and shows the tool permission screen only as a screenshot. The endpoint returned 401 to an anonymous handshake, so we could not read names, schemas or safety annotations from the server.

Two, and neither limits anything. The server's own RFC 9728 descriptor declares scopes_supported of openid and offline_access, which are identity and refresh-token claims. Planday's identity service advertises 79 granular scopes such as shift:delete and salaries:read, but those belong to its platform API, not to this connector's grant.

No tool among the twelve carries a delete verb, and Planday's help article states plainly that Claude will not delete anything. Planday's own platform API does expose shift deletion under a shift:delete scope, so the capability exists in the product — the connector simply does not list a tool for it, and its grant does not request that scope.

No tool names a timesheet or a payroll export. The twelve tools cover scheduling, employees, absence and working-time rules only. Note that approve_shift_swap approves a swap request, not a timesheet. Planday's platform API keeps payroll behind a separate payroll:read scope that this connector's grant does not request.

A Planday Pro subscription, your workspace address and a Planday login. Planday's help article lists the Pro plan as the subscription requirement and any access level as sufficient. The sign-in asks for your workspace URL, such as yourcompany.planday.com. Whatever that account can see and change in Planday, the connector can too.

The connector endpoint is hosted in West Europe, and its hostname says so. Sign-in is brokered by a separate global identity host, id.prod-global.planday.cloud. An identical server also answers at a prod-global hostname, which Anthropic's directory does not list. Planday's help centre points data-residency questions to its Data Processing Agreement rather than answering them.

Sources

Use in Agentman

Connect once and your agents call these tools on their own — on a schedule, in a workflow, with nobody at the keyboard.

Open in Agentman Studio

Server Info

Category
Productivity
Developer
Planday
Tools
12
Domain
public-mcp-server.prod-westeurope.planday.cloud

Using Claude Desktop or another MCP client? Setup docs — the connection URL above works anywhere.