Managed MCP services for MSP customers
Resell secure MCP access to your customers.
Give each managed customer a separate MCP workspace for its staff and SaaS apps. You control the service model; customer users get only the tools approved for their company.
What does reselling MCP mean for an MSP?
Reselling MCP means packaging secure access to a customer's SaaS applications as a managed service. The MSP administers a separate customer workspace, connects approved apps, grants specific MCP tools, and helps the customer's staff use those tools from compatible AI clients.
This is different from using MCP only inside the MSP. The service is designed for the people at the customer: finance, operations, sales, support, IT, or other teams that want an AI client to work with the business apps they already use. For the MSP's own PSA, RMM, security, and documentation workflows, see MCP for MSPs.
How does a managed MCP service work?
| Participant | What they control | What stays separated |
|---|---|---|
| MSP | Customer onboarding, connected services, tool grants, risk policy, and service packaging | Each customer is managed through its own workspace |
| Customer administrator | Authorized staff and the customer's own access requirements | Customer users and identity remain scoped to that customer |
| Customer staff | The prompts and requests they send through a compatible AI client | Each person receives only tools allowed by workspace, group, and user policy |
| Stackyapper | MCP routing, credential protection, policy checks, confirmation, and operational audit | Provider credentials are not sent to the AI client |
How are customer SaaS apps and users isolated?
Every managed customer can have its own workspace. Users, SaaS connections, tool grants, MCP sessions, and audit records resolve inside that workspace, so one customer does not inherit another customer's access.
Stackyapper checks the signed-in identity, selected workspace, service connection, tool grant, action risk, and confirmation policy again when a tool runs. The official MCP authorization guidance likewise recommends authorization when servers access user-specific data, administrative actions, audit history, or enterprise systems. See the Model Context Protocol authorization guide and Stackyapper's MCP access control model.
What can customer staff do with MCP?
The exact actions depend on the App and its current state, the customer's provider authorization, and the tools the MSP grants. The App directory separates Available Apps from Beta Apps that are still being worked on. A managed customer MCP service can support patterns such as:
- Ask an approved AI client to find records across permitted business systems.
- Build customer-specific summaries, reports, or client-supported artifacts from approved results.
- Use read tools first, then keep write or destructive actions separately permissioned.
- Give different departments access to different apps and tools without sharing provider credentials.
- Remove a user or tool grant without rebuilding every customer integration.
How to onboard a customer to managed MCP access
- Create the customer workspace. Add one managed customer workspace so its users, SaaS connections, permissions, sessions, and audit records stay separate.
- Connect the customer’s SaaS apps. Authorize supported business applications inside that customer workspace. Provider credentials stay with Stackyapper and are not sent to the AI client.
- Grant only the approved MCP tools. Choose which tools the workspace, groups, and individual users can access. Apply confirmation policy to higher-impact actions.
- Onboard customer staff. Invite authorized staff and connect a compatible MCP client such as Claude, ChatGPT, Codex, or Microsoft Copilot Studio using the maintained setup instructions.
- Operate and review the service. Review activity by customer workspace and update users, connections, and tool grants as the customer’s requirements change.
Use the maintained MCP client setup guide for current client requirements. Microsoft partners can also follow the Microsoft Copilot Studio MCP setup guide.
How can an MSP package and price MCP?
Stackyapper bills each managed customer workspace to the account that manages it. The managing business decides whether to include it in a managed-service bundle, pass it through as a line item, or absorb it, subject to its Stackyapper agreement and its own customer contract.
Your number of active customer workspaces determines one per-workspace rate, applied to all of them for that billing period.
| Active customer workspaces | Price per workspace |
|---|---|
| 1–4 | $149 |
| 5–19 | $139.80 |
| 20–49 | $134 |
| 50+ | $132 |
Example: Five active customer workspaces cost $699 per month, plus the managing account's Standard ($99) or Business ($199) plan. There is no customer-workspace minimum or maximum.
Every managed customer workspace includes unlimited customer users; separate apps, connections, permissions, sessions, and audit scope; managed SAML and SCIM; automated identity lifecycle; and a custom access domain.
Prices are USD and billed month to month. See current Stackyapper pricing and the machine-readable pricing file. Provider subscriptions and provider API charges are not included.
What is the MSP responsible for?
- Confirming the applicable agreement permits its planned resale or managed-service model.
- Choosing the correct customer workspace before connecting an app or granting a tool.
- Obtaining customer authorization for provider connections and workplace monitoring.
- Designing least-privilege access for each customer role and reviewing higher-impact actions.
- Supporting the AI client and workflow the MSP chooses to include in its service.
Stackyapper is the access and policy layer, not the AI assistant and not a substitute for the MSP's customer agreement. Review the trust center, terms, and MCP security checklist for MSPs before launch.
Managed customer MCP questions
Can an MSP resell MCP access to customers?
Stackyapper can support an MSP resale model under the applicable Stackyapper agreement. The managing account pays for each managed customer workspace, including customer identity, then decides whether to include that cost in a managed service, pass it through, or absorb it.
Does each MSP customer get a separate MCP workspace?
Yes. Each managed customer can have an isolated workspace with its own users, SaaS connections, tool grants, MCP sessions, and audit records. It does not inherit access from the MSP’s internal workspace or another customer.
Can customer staff use their SaaS apps from Claude, ChatGPT, or Copilot?
Authorized customer staff can use approved tools from their customer workspace through a compatible remote MCP client. Client support varies, and the SaaS app, provider authorization, workspace policy, and user grant still determine what each person can use.
Is managed customer MCP access white-labeled?
Every managed customer workspace includes customer-specific managed SAML and SCIM plus a custom access domain. Stackyapper does not claim that every product surface is fully white-labeled.
Does Stackyapper replace the customer’s AI assistant?
No. Stackyapper is the MCP access and governance layer. The MSP and customer choose the compatible AI client, while Stackyapper controls service connections, tool access, confirmation, and audit within the selected workspace.