Technical Article

How to Connect Claude to the Official Upwork MCP Server

Setting up the official Upwork connector in Claude, and the permission choices that keep proposals and Connects under your control.

Share this article

To connect Claude to Upwork, add Upwork’s official MCP server as a connector in Claude, sign in through Upwork’s own OAuth screen, and decide which tools Claude may run without asking. That takes minutes. The part that deserves more thought is what the connection is allowed to do: reading jobs and preparing drafts can be routine, while anything that sends a proposal, spends Connects or messages a client should require your approval every time. This guide covers the setup, the permission model and the habits that keep an account safe.

What the official Upwork MCP server is

The Model Context Protocol is an open standard for connecting AI applications to outside systems: a server exposes tools and data, and a client such as Claude calls them inside a conversation. Upwork announced its own MCP server in August 2026, available to every client and freelancer at no additional cost, and usable from Claude, ChatGPT, Cursor and other MCP-compatible products.

For a freelancer or agency, the point is that job discovery, drafting and proposal work can happen through an interface Upwork built and hosts, rather than through scraping or browser automation. It is one component in a larger pipeline; the full Upwork automation playbook shows where it sits between alert intake and human review.

Before you connect

  • Use your own Upwork account, or for an agency the account whose activity the connection should represent. Do not share a password with any tool.
  • Decide what the connection is for. Discovery and drafting need far less trust than submission.
  • Check your Claude plan and workspace policy. Remote MCP connectors are available across Claude plans, and on Team and Enterprise an owner may need to enable them.
  • Read Upwork’s current guidance on bots and automation, so your use stays within what the platform expects.

Connecting Claude, step by step

Menu labels change between releases, so treat these as the shape of the process rather than exact clicks, and follow Upwork’s own setup instructions where they differ.

  1. Open Claude’s connector settingsAdd Upwork from the directory, or as a custom connector using the server address Upwork publishes.
  2. Authorize with UpworkSign in on Upwork’s own OAuth screen; Claude never sees your password.
  3. Review the tool listSee which tools read data and which change anything.
  4. Set approvalsKeep every changing tool on “ask each time”.
  5. Test with a read-only requestAsk for matching jobs and confirm the results look right.
Connecting Claude to the official Upwork MCP server.

Permissions: the decision that matters

Claude asks before it runs a tool unless you tell it otherwise. Anthropic’s guidance is to choose “allow always” only for a server and tool you trust to run unsupervised. For Upwork that suggests a clear split.

  • Reasonable to allow: searching jobs, reading job and client details, reading your own proposals and messages.
  • Ask every time: creating or editing drafts, so you see what is being written.
  • Always ask, never allow-always: submitting proposals, sending messages, accepting offers, submitting work or anything that spends Connects or money.

The aim is not to make Claude less useful. It is to keep every irreversible action tied to a moment where you looked at it. That is the same principle behind human approval in agent workflows, applied to one connector.

OAuth, tokens and what Claude can see

Authorization runs through OAuth: you sign in on Upwork, approve access, and Claude receives a token that lets it call the server on your behalf. The MCP specification builds on OAuth 2.1 for this, which is why the connection never needs your password.

Treat the connection as an account credential. Remove it when you stop using it, reconnect after any suspicion of compromise, and do not copy tokens into other tools, prompts or workflow nodes. If you also run an automated pipeline, give it its own authorization and its own narrow purpose rather than reusing a personal session.

Useful requests once connected

  • Find jobs posted in the last day that match my skills in multi-tenant SaaS, and list budget, client history and Connect cost for each.
  • Read this job and tell me what the client is actually asking for, what is unclear, and whether it fits my documented work.
  • Draft a proposal for this job using only the case studies I paste below. Do not add contact details or links.
  • Summarize my open proposals and which ones have been viewed.

Each of these reads or prepares. None of them sends anything, which is the right default for a conversational session.

Prompt injection and untrusted job text

Job descriptions are written by strangers, and some will contain text aimed at AI assistants. When Claude reads a job through the connector, that text enters the conversation. The defense is the permission model above: if every changing action requires your confirmation, instructions hidden in a job description cannot send a proposal or message on their own.

Be cautious about connecting several write-capable tools in one session. A job description that can influence a model that can also send email or post elsewhere widens the blast radius. Keep Upwork sessions focused, and read every confirmation prompt rather than approving by reflex.

From a chat session to a controlled pipeline

A conversational connection is good for exploring jobs and drafting by hand. Once volume grows, the same official access can sit inside a pipeline: alerts arrive through an inbox and n8n, the server supplies current job data, rules and scoring narrow the list, and drafts wait for review. The n8n job-alert workflow covers the intake side.

Designing that kind of pipeline, with approval gates, evidence rules and budget limits built in, is the work behind my AI agent development service.

Share this article

References

  1. Upwork: Upwork Talent Is Now Everywhere AI Works (MCP server announcement)
  2. Claude Help Center: Get started with custom connectors using remote MCP
  3. Model Context Protocol: Introduction
  4. Model Context Protocol: Authorization specification

Evidence and further reading

All insights →
InsightA Safe Upwork Automation Playbook: From Job Alerts to Better ProposalsWhere automation helps on Upwork, where a human decision has to stay, and the architecture that keeps the line between them.

Facing a similar problem?

AI Feasibility & Architecture Assessment

For teams planning an AI feature, an agent or a private model who need evidence before committing budget.

Request an assessment

Let's build what's next

Have a complex system that needs to be built right?

Whether you are starting from an idea, replacing an existing platform, or scaling a system, let's talk.

Better Technology.
Brighter Possibilities.