Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Query corporate card spend from your AI assistant: tools stage Ramp data, execute_query runs SQL.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Ramp MCP server connects Claude, ChatGPT or any MCP-compatible agent to a company's corporate card and spend management account. Load tools stage transactions, cards, limits and users into a queryable database, and SQL runs across it. The same connector also approves requests, edits accounting coding and mints single-use card credentials.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
execute_query accepts SQL over whatever was loaded, so the effective read surface is any question about the staged copy — much larger than 17 tool names implies, and bounded only by what someone chose to load.https://mcp.ramp.com/mcp, and the listed documentation URL renders a JavaScript shell with no matching machine-readable guide.readOnlyHint or destructiveHint values were observed for any of the seventeen. Every capability statement here is Ramp's own.No. The permissions label is accurate and this connector acts on Ramp. Ramp documents approving or rejecting transactions, reimbursements and purchase orders, editing memos and accounting codes, locking and unlocking cards, posting comments, and generating single-use Agent Card credentials. Every write lands in the Ramp Audit Log. Bill approvals are the documented exception and are not yet available.
Yes. Ramp's open-source server documents an ETL pipeline plus an ephemeral in-memory SQLite database, and describes execute_query as running arbitrary SQL against it. The load tools populate tables first, so the model composes SQL over whatever was staged rather than calling one fixed endpoint per question. Results are capped at 100 rows per query.
Ramp does not say. Its hosted documentation calls it only a queryable workspace or queryable database and never states where it runs, how long tables persist, or whether they are encrypted at rest. The open-source self-hosted server documents an in-memory SQLite database, but that is a different deployment, so treat hosted staging as undocumented.
Yes, through Agent Cards. Ramp documents generating a single-use PAN and CVV at purchase time, scoped to one merchant and capped at the requested amount, expiring after the first authorization or twelve hours. Card issuance is policy-controlled per business and blocked for fourteen merchant category codes including gambling, securities brokers and pharmacies.
It inherits the signed-in user's Ramp role. Ramp states the assistant sees only data and actions that user could already perform, so employees see their own spend while admins see company-wide data. Most company-wide load tools need admin or business-owner permission. Admins can further restrict access by role, department or user.
Ask your Ramp admin to check your role. Ramp documents this exact symptom as meaning the account lacks admin or business-owner permissions, which most company-wide transaction, bill, reimbursement and spend tools require. Access is also separately restrictable under Company, Integrations, Ramp MCP, Manage Access. Reconnecting alone will not add tools your role cannot reach.
Too many data tables are loaded into the queryable database at once. Ramp's documented fix is asking the assistant to clear unused tables, then retrying; persistent errors resolve within minutes as running operations finish. Ramp does not publish the actual table ceiling, so there is no documented number to plan a large spend export against.
/llms-guides/ramp-mcp.txt; the directory's documentation URL docs.ramp.com/developer-api/v1/guides/ramp-mcp-remote returns a JavaScript shell with no matching guide file) · retrieved 2026-08-19/llms-guides/build-for-ai-agents.txt) · retrieved 2026-08-19/llms-guides/agent-cards.txt; source of the single-use PAN/CVV terms and the blocked merchant category code table) · retrieved 2026-08-19/llms-guides/mcp.txt; states Ramp ships three MCP servers) · retrieved 2026-08-19ramp_mcp open-source server README — https://github.com/ramp-public/ramp_mcp (fetched 2026-08-19; documents the ETL pipeline plus ephemeral in-memory SQLite database and arbitrary SQL via execute_query, for the self-hosted deployment) · retrieved 2026-08-19docs.ramp.com/robots.txt allows the whole site with an empty Disallow, and carries no Content-Signal directives (fetched 2026-08-19). docs.ramp.com/llms.txt publishes an explicit machine-readable index and instructs agents to read the /llms-guides/ text files rather than the rendered HTML (fetched 2026-08-19) · retrieved 2026-08-19resource; the path-insert form returns 404) · retrieved 2026-08-19https://api.ramp.com/developer/v1/token/pkce) · retrieved 2026-08-19{"detail":"No access token provided"} with www-authenticate: Bearer resource_metadata="https://ramp-mcp-remote.ramp.com/.well-known/oauth-protected-resource/mcp". No authentication was attempted and no tool was called · retrieved 2026-08-19Connect Ramp once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.