6sense
Ask an AI agent about 6sense account insights, buying signals and keyword trends.
Read rotas, staff records and leave balances, and draft, assign, approve and publish shifts.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Planday MCP server connects a Planday workspace — workforce scheduling for shift-based businesses, owned by Xero — to Claude, ChatGPT and any MCP-compatible agent. Anthropic's directory lists 12 tools that read rotas, staff, departments, leave balances and working-time rules, and that draft, assign, publish and approve shifts. Sign-in is OAuth through your normal Planday login.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
readOnlyHint or destructiveHint is published here. Every read/write label on this page is our classification.scopes_supported of openid and offline_access. Nothing at consent separates reading a rota from publishing one, or reading a leave balance from approving a swap. The only boundary between the routine write and the consequential one is the client-side Tool permissions screen — a Claude control, not a Planday grant. Revoke it and the boundary is gone.shift:delete, salaries:read, payrates:read and impersonate. We checked attribution three ways: the identical 79-scope list is served by id.planday.com, id.prod-global.planday.cloud and id.prod-westeurope.planday.cloud alike, so it is Planday's whole API vocabulary rather than a signal about this connector. It is not evidence of a hidden tool surface — but it does show the account you sign in with holds privileges far beyond what these 12 tools use.public-mcp-server.prod-global.planday.cloud serves a byte-identical landing page, an equivalent RFC 9728 descriptor, and the same 401 challenge. Anthropic's directory lists only the West Europe host. We found no Planday documentation explaining which workspaces belong to which region, or how to choose.x-ratelimit-* headers. We found no statement that the MCP server shares them.Yes. Four of the twelve tools change state: create_draft_shift, assign_shift, publish_draft_shifts and approve_shift_swap. Publishing makes a draft visible to staff, assigning moves a shift onto a named person, and approving a swap rewrites two employees' rotas at once. The other eight only read. Planday states nothing is deleted.
Yes, as far as your own Planday login reaches. list_employees returns staff records, and Planday's HR API defines an employee as carrying national identity number, bank account, birth date, home address, phone numbers and email. If an Administrator connects, that reach includes payroll data, because Administrators can view and edit payroll information.
Not by itself, but a publish can trigger one. Planday documents that publishing shifts offers Message or SMS notification, and that open-shift notifications are sent automatically and cannot be disabled by admins. Whether publish_draft_shifts sets those flags is not documented. SMS is charged and Planday states it cannot be fully disabled platform-wide.
Twelve, according to Anthropic's directory on 2026-08-23. Planday publishes no tool list of its own — its Claude help article describes capabilities in prose and shows the tool permission screen only as a screenshot. The endpoint returned 401 to an anonymous handshake, so we could not read names, schemas or safety annotations from the server.
Two, and neither limits anything. The server's own RFC 9728 descriptor declares scopes_supported of openid and offline_access, which are identity and refresh-token claims. Planday's identity service advertises 79 granular scopes such as shift:delete and salaries:read, but those belong to its platform API, not to this connector's grant.
No tool among the twelve carries a delete verb, and Planday's help article states plainly that Claude will not delete anything. Planday's own platform API does expose shift deletion under a shift:delete scope, so the capability exists in the product — the connector simply does not list a tool for it, and its grant does not request that scope.
No tool names a timesheet or a payroll export. The twelve tools cover scheduling, employees, absence and working-time rules only. Note that approve_shift_swap approves a swap request, not a timesheet. Planday's platform API keeps payroll behind a separate payroll:read scope that this connector's grant does not request.
A Planday Pro subscription, your workspace address and a Planday login. Planday's help article lists the Pro plan as the subscription requirement and any access level as sufficient. The sign-in asks for your workspace URL, such as yourcompany.planday.com. Whatever that account can see and change in Planday, the connector can too.
The connector endpoint is hosted in West Europe, and its hostname says so. Sign-in is brokered by a separate global identity host, id.prod-global.planday.cloud. An identical server also answers at a prod-global hostname, which Anthropic's directory does not list. Planday's help centre points data-residency questions to its Data Processing Agreement rather than answering them.
help.planday.com/robots.txt permits it; the same article in Markdown at the .md suffix carried 864 words against 949 in the HTML. · retrieved 2026-08-23llms.txt (retrieved 2026-08-23). 1,376 lines across five languages; the Claude connector article is not indexed in it. llms-full.txt returned 404. · retrieved 2026-08-23initialize to the endpoint returned HTTP 401 with a www-authenticate Bearer challenge naming its resource metadata; RFC 9728 descriptor at https://public-mcp-server.prod-westeurope.planday.cloud/.well-known/oauth-protected-resource; authorization-server metadata at https://id.prod-global.planday.cloud/.well-known/openid-configuration (2026-08-23). Control probes for the oauth-authorization-server path returned 404 on the resource host, so the descriptor is genuine rather than a catch-all. · retrieved 2026-08-23Connect Planday once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.