Tools
Best MCP servers for product managers, chosen by the job you need done
Choose an MCP server by the product job it does and by whether it offers a read-only path, not by how often it appears in a roundup. Five categories cover almost every product manager use case: delivery trackers, product analytics, engineering signal, documents and design. The official MCP Registry, live in preview since 8 September 2025, is the durable place to check what exists.
What makes an MCP server worth connecting?
Four tests, in this order, and a server that fails the first one rarely survives the others.
It is published by whoever owns the data. A tracker server from the tracker vendor authenticates against your real account and inherits your real permissions. A third-party wrapper needs a credential you hand it, which is a different and larger decision.
It has a read-only path. Linear publishes both a read-write endpoint and a separate read-only one, and notes that requesting only the read scope keeps the underlying token away from write APIs. GitHub's official server has a read-only flag, and its documentation is explicit that read-only takes priority even when a write tool is requested by name. Supabase exposes read-only as a URL parameter that runs every query as a read-only Postgres user. Where that path does not exist, you are choosing between full access and no access.
It can be scoped narrower than your own account. Supabase supports pinning a connection to one project so the assistant cannot reach data in your other projects. Sentry's endpoint accepts organisation and project scoping in the URL. Scope is the difference between a connection you can explain and one you cannot.
And it answers a question you already ask by hand every week. This is the test most lists skip, and it is the one that predicts whether a connection survives a month.
Which server maps to which product job?
| Product job | Server | Read-only path |
|---|---|---|
| Read and triage delivery work | Linear, Atlassian Remote MCP | Linear: yes, separate endpoint and scope |
| Query product usage and errors | PostHog | Not documented as a separate endpoint |
| Query your own application database | Supabase | Yes, URL parameter |
| Read code, issues and pull requests | GitHub | Yes, flag that skips write tools |
| Search and triage production errors | Sentry | Scoped by organisation or project |
| Read and update specs and docs | Notion | Limited to content you can already access |
| Pull design context into a build | Figma | Client must be in Figma's own catalog |
Delivery: where most product managers start
Linear's server sits at mcp.linear.app/mcp and is read-write by default, with tools for finding, creating and updating issues, projects and comments. It authenticates with OAuth 2.1 and dynamic client registration, or with a bearer token or API key. The detail worth copying into your own notes is the read-only endpoint: it exists, it is one URL away, and pointing at it is the cheapest safety decision in this whole category.
Atlassian's Remote MCP Server sits at mcp.atlassian.com/v2/mcp and reaches across Jira, Jira Service Management, Confluence and Bitbucket, summarising and searching them and creating or updating work items and pages in natural language. Its documentation is candid about the permission model: clients act on connected products with your existing permissions. That is reassuring if you are an individual contributor and much less reassuring if you are an administrator, because the connection inherits administrative reach without announcing it.
Product data: the category with the sharpest edges
PostHog runs a hosted server at mcp.posthog.com/mcp that its documentation describes as letting an agent use PostHog through plain text questions. It covers error triage with stack traces, analytics queries including HogQL, and feature flag and experiment management, and it reads and writes across those products. Feature flag management sitting behind the same connection as analytics questions is exactly the kind of capability pairing worth noticing before you connect, not after.
Supabase publishes the most useful documentation in this category, because it leads with the risk rather than the feature list. Its guidance opens by stating that connecting a language model to your projects carries security risks, recommends read-only mode for unattended work, and advises connecting to a production project only when the task genuinely requires production evidence. The threat it names is prompt injection through content already sitting in your database, which is the failure mode people connecting an analytics server almost never have on their list.
Engineering signal, docs and design
GitHub's official server offers toolsets spanning issues, pull requests, repositories, actions, code security and more, with a default set covering context, repos, issues, pull requests and users, and both a GitHub-hosted remote option and a local one. For a product manager the value is rarely the code. It is reading what shipped, what is stuck, and what a pull request description actually claims.
Sentry's server at mcp.sentry.dev/mcp connects an assistant to error search, performance analysis, issue triage and its documentation, using OAuth for every connection. Notion's hosted server lets a client search, read, create and update content you can already access, after an OAuth authorisation. Figma's official server supplies design context to agents generating code, and restricts connections to clients listed in its own catalog, which is a deliberate narrowing rather than an oversight.
What should make you say no?
A server with no read-only path, wrapping a system where a wrong write is expensive, connected for a task you have not yet written down in a sentence. Any one of those is survivable. All three together is how a connection becomes an incident.
Two softer no's are worth naming. A server that duplicates something a scheduled job already does deterministically is usually a downgrade, because you have swapped a predictable pipeline for a probabilistic one. And a server connected only because it appeared on a list, including this one, has no owner and no success condition, which means nobody will notice when it starts failing quietly.
How to keep this list current without maintaining a list
The set of servers will be different in three months. The official MCP Registry exists precisely because the ecosystem outgrew hand-maintained catalogs; it launched in preview on 8 September 2025 as an open catalog and API, with sub-registries so an organisation can publish an internal approved set on top of it. Check the registry for existence, the vendor's own page for behaviour, and your own weekly question for whether it is worth connecting at all.
For the protocol underneath these choices, start with MCP for product managers, and for connecting one server to one scoped task, building an AI assistant with MCP is the practical walkthrough.
Turn a connection list into a system
Choosing servers is a design problem: what the system may see, what it may do, and when a person approves. Builders Camp's AI Agents bootcamp runs 2 weeks with 3 live sessions and 9 microlessons on exactly that, covering tool use and integrations, human-in-the-loop approvals and evaluation. Building with Claude Code names MCP and tool integrations in its own syllabus and runs 1 week with 2 live sessions. If the goal is fewer manual steps rather than a smarter assistant, Automate Workflows with AI is the closer fit, at 1 week with 2 live sessions and 8 microlessons.
One last filter that costs nothing: connect a server, then ask it the question you used to answer by hand, and compare. If the manual answer was better, the connection was not the problem you had. For the analytics version of that test, pulling data without SQL in Claude Code shows what the comparison looks like in practice.
Bootcamps referred in this Guide
Frequently asked questions
How do I know a server is the real one and not a copy?
Start from the vendor's own documentation rather than a directory listing or a blog roundup. Linear, Atlassian, PostHog, Supabase, GitHub, Sentry, Notion and Figma all document their servers on their own domains, including the exact endpoint. A server that only exists in a third-party list, wrapping a product whose vendor has not published one, is a different trust decision.
Which server should a product manager connect first?
The one attached to a question you already ask every week by hand. For most product managers that is the tracker or the analytics product, because those are the two places where the weekly answer is currently assembled manually. Connecting a second server before the first one has paid for itself is how connection lists grow without anything getting faster.
Does every server offer a read-only mode?
No, and this is a useful filter. Linear publishes a read-only endpoint at mcp.linear.app/mcp/readonly and a read-only OAuth scope. GitHub's server has a read-only flag that skips write tools even when they are requested. Supabase has a read-only URL parameter that runs queries as a read-only Postgres user. Where no read-only path exists, the connection is a bigger decision.
What is the official MCP Registry, and should I use it?
It is an open catalog and API for publicly available MCP servers, launched in preview on 8 September 2025, intended as a single source of truth for discovery. Use it to find out whether a server exists for a tool you use. Use the vendor's own page to decide whether to trust it.
Can I connect a server for a tool that has no official one?
Technically yes, since anyone can publish a server. Practically, a community server for a product whose vendor has not shipped one runs with whatever credential you hand it, and the specification treats a local server as code executing with your client's privileges. Treat it as installing software from an unknown publisher, because that is what it is.
How many servers is too many?
The limit is not a number, it is review capacity. If nobody can say what each connected server is allowed to do without opening a config file, the list is already too long. Tool lists also consume the model's own context before any work starts, so more connections can make answers worse, not just riskier.
Do these servers work outside Claude?
Most do. MCP is supported across a range of clients, including Claude, ChatGPT, Visual Studio Code and Cursor, which is the point of a protocol. The exception is worth noting: Figma states that only clients listed in its own MCP catalog can connect to its server.
Sources
- Linear: Model Context Protocol
- Atlassian: Getting started with the Atlassian Remote MCP Server
- PostHog: Model Context Protocol
- Supabase: Model context protocol (MCP)
- GitHub: github/github-mcp-server
- Sentry: Sentry MCP Server
- Notion: Notion MCP
- Figma: Figma MCP Server
- Model Context Protocol blog: The official MCP Registry

Andre Albuquerque
CEO of Builders Camp, SuperOperator, and other companies. Building products.
CEO of Builders Camp, SuperOperator, and other companies. Building products.
LinkedInMore guides by Andre Albuquerque
Guilherme Salgueiro
Builder and AI systems practitioner. Guilherme helps developers, PMs, and founders move beyond prompting into structured AI system design -- building with Claude Code, agents, and automation pipelines to ship products faster and more reliably.
Builder and AI systems practitioner. Guilherme helps developers, PMs, and founders move beyond prompting into structured AI system design — building with Claude Code, agents, and automation pipelines to ship products faster and more reliably.
LinkedInMore guides by Guilherme SalgueiroLast updated 2026-09-18
Researched from Builders Camp's bootcamp, track and masterclass material and the sources listed on this page, drafted with AI, and fact-checked against every source cited.
Related guides
MCP for product managers, and what the protocol actually changes
MCP is an open standard, announced by Anthropic on 25 November 2024, for connecting an AI application to external...

Andre Albuquerque & Guilherme SalgueiroHow to Build an AI Assistant with MCP
Building an AI assistant with MCP means adding one or more MCP servers to an AI tool like Claude Code, scoping each...

Andre Albuquerque & Guilherme SalgueiroBest AI Tools for Product Managers in 2026
The best AI tools for product managers in 2026 are not one tool but four categories: a reasoning and writing assistant...
Andre AlbuquerqueHow to pull product data without SQL using Claude Code
Profile the dataset before you query it: column types, distinct values in every small column, null counts, and the date...

Andre Albuquerque & Guilherme Salgueiro

