You can connect Square to Claude using the Model Context Protocol (MCP), and once it’s connected, Claude can look up an order, check your catalog, or pull a customer’s record without you opening the Square dashboard to find it. This guide covers what Square’s MCP server does, both ways to connect it — directly or through a gateway — and one thing worth knowing before you try: Square’s OAuth isn’t currently open to every client that asks.
What the Square MCP server actually does
Square publishes a remote MCP server at mcp.squareup.com/mcp. It exposes your account’s payments, orders, catalog, and customers as tools Claude can call directly, so prompts like these work against your real Square data:
- “What orders came in yesterday afternoon?”
- “Look up the customer record tied to this email.”
- “Is the new seasonal item in the catalog yet, and at what price?”
- “Find the payment for order #4821 and tell me its status.”
Claude acts through the same permissions your Square account already has — it isn’t a separate export, it’s your account looking things up, and in some cases creating or changing them, on your behalf. That makes it the third payments server in gate’s catalog alongside Stripe and PayPal — but its OAuth story is different from both of those, which is the part worth reading before you connect it.
The catch: Square’s OAuth isn’t open to every client yet
Stripe and PayPal’s remote servers both let a new AI client register itself and walk through a one-click OAuth consent screen with no extra step. Square’s MCP endpoint is one of a handful in the catalog where that isn’t the case today: the vendor’s OAuth currently only admits clients Square has allow-listed in advance, rather than opening registration to any client that shows up. In practice, that can mean a connection attempt from a new or less-common client fails at the authorization step, even though the server itself is real and documented.
This is the same gap covered in MCP OAuth scopes explained: a server supporting OAuth in principle isn’t the same claim as every client being able to walk through it today. If you hit an “unauthorized client” error connecting Square, that’s the most likely reason — not a mistake in your setup. See the unauthorized client error explained for the general pattern and workarounds. Whether a given client can connect changes as vendors expand their allow-list over time, so it’s worth checking again later if it doesn’t work on your first attempt.
Option 1: Connect Square to Claude directly
If the client you’re using is one Square currently admits, the setup is:
- Open Claude’s connector or MCP settings.
- Add a remote server pointing at Square’s MCP endpoint.
- Sign in with your Square account when prompted — standard OAuth, so Claude never sees your Square password, and you can revoke access from Square’s own account settings at any time.
That’s enough if Claude is the only AI client you use with Square. The tradeoff shows up once you add a second client — ChatGPT for a quick lookup, Cursor for pulling order data into a reporting task — or a second person on the team: each one needs its own attempt at the same OAuth step, with the same chance of hitting the allow-list wall independently.
Option 2: Connect it once, through a gateway
If you’re already juggling more than one MCP server or more than one AI client, wiring each pair directly gets old fast — that’s the connection sprawl covered in what an MCP gateway is. The idea is to connect Square (and everything else) to one gateway URL, then point every AI client at that single URL instead of reconfiguring each one and re-running the OAuth step per client.
With gate specifically, connecting Square looks like this: add gate’s gateway URL to Claude once, then pick Square from the Square server page in the directory and sign in the same way you would directly. gate’s catalog tracks each server’s currently verified connectivity — including cases like this one, where a vendor’s OAuth is still allow-listed — so you know what to expect before you start, instead of finding out mid-flow. See the full list of servers on the MCP servers page.
Why the connection method matters for a payments account
Like any payments account, Square holds transaction history, customer contact details, and your actual catalog and pricing — not just records to look up. A few things worth checking before or right after you connect:
- Is it the official endpoint? Connect Square’s documented server (
mcp.squareup.com), not a third-party mirror claiming to proxy it. - Read, or read and write? A tool that can look up an order is a different risk than one that can edit your catalog or issue a refund. Check the actual tool list rather than assuming it’s read-only — gate’s free MCP security scanner lists every tool a server exposes, with no signup required.
- Test before you trust it with live data. Square, like several payment platforms, offers developer sandbox tooling separate from a live account; checking Square’s own developer docs for how that applies to the MCP server specifically is worth doing before you point Claude at a real business account.
- Who else on the team can reach it? If more than one person connects Square to their own AI client, a shared, revocable setup beats everyone holding their own grant — the same access-control question covered in MCP access control for teams.
Troubleshooting the connection
- “Unauthorized client” or the OAuth screen never appears. Most likely the allow-list issue above — the client you’re using may not be one Square currently admits for this endpoint.
- Claude can’t find an order or customer you know exists. Square’s tools respect your account’s own permissions and the specific location or business you’re signed into; data in a different Square location won’t show up any more than it would in the Square dashboard itself.
- Tools disappear after a Square update. Remote servers can change their tool list without warning. If you’re connected through a gateway, that kind of change is exactly what drift detection is meant to catch — see how MCP rug pulls work for why a one-time review isn’t enough.
The bottom line
Connecting Square to Claude with MCP is a normal OAuth flow when the client you’re using is one Square currently allows — direct if it’s your only client, or once through a gateway if you want the same access shared and governed across every AI client on the team. If the connection fails at the authorization step, that’s worth reading as “not allow-listed yet” rather than a broken setup. Either way, know which tools only read your data and which can change your catalog or touch a live transaction — that distinction matters more here than it does for most tools in this series.