What Can the Notion MCP Server Do (and Not Do)?
A plain guide to what Notion’s hosted MCP server lets an AI assistant do in your workspace: the jobs its tools cover, whose access it uses, what admins control, the limits that shape how it edits, and the things it does not do at all.
7 min read
Notion MCP, the server Notion hosts at mcp.notion.com, lets an AI assistant search your workspace, read pages and databases, create and edit pages, query databases, build databases and views, move and duplicate pages, comment, and upload files. On plans with Notion AI it can also search connected apps such as Slack and Google Drive, read your meeting notes and start Notion’s own Custom Agents. It works as you: after an OAuth sign-in it can reach every page you can reach in the workspace you picked, and nothing more. Just as useful to know is what it leaves out. Notion’s published tool list has no tool for deleting a page and none for changing who a page is shared with.
This piece is about capability, not setup. To connect it, see Notion MCP with Claude Code, which also covers rate limits, or Notion MCP with ChatGPT. Tool names below come from Notion’s supported-tools page (opens in a new tab). That page changes as Notion adds tools, so the list your own client shows after sign-in is the final word.
What it can do, grouped by job
- Find.
notion-searchruns keyword searches with filters for location, creator, date and title, returning up to 50 results.notion-ai-searchtakes a plain question and, where Notion AI is on, also searches connected sources. Either can look up a workspace member by name or email. - Read.
notion-fetchreads a page, database, data source or saved view by URL or ID.notion-query-data-sourcesreads rows, runs a saved view or answers a SQL query.notion-get-commentsreads a page’s discussions, resolved ones included. - Write.
notion-create-pagesmakes pages, optionally from a database template, or as a private draft when you have not said where it belongs.notion-update-pagechanges properties and content.notion-create-commentcomments on a page or a block, or replies. - Restructure.
notion-move-pages,notion-duplicate-pageandnotion-create-folderrearrange things.notion-create-databaseandnotion-update-data-sourcecreate databases and change their properties.notion-create-viewandnotion-update-viewbuild table, board, calendar, timeline, chart, form and other views. - Files.
notion-create-file-uploadaccepts files up to 20 MiB, and attachment tools add text or a file from a URL to a page. - Notion’s own AI features. There are tools for Notion Skills (reusable instructions kept as pages), for querying your meeting notes, and for starting and messaging Notion Custom Agents.
One more tool is worth knowing by name: notion-get-tool-access. It reports what the connected workspace’s plan allows, tool by tool and option by option. Since June 2026 Notion shows an assistant the tools your plan does not include as well, so it can tell you an upgrade is needed instead of trying something that cannot work.
Whose access it uses
Yours. Notion’s developer documentation (opens in a new tab) says that once you authorise a client, it can use Notion MCP to read and update content you can access. Notion’s Help Center puts it more bluntly: MCP tools act with your full Notion permissions and can access everything you can access. Four things follow from that:
- Anything you can open, it can open, including your private pages. Anything you cannot open stays out of reach, and database queries return only the rows and properties you can read.
- Your edit rights are its edit rights. If you can edit the company handbook, so can the assistant.
- It works in one workspace at a time: the one you chose during sign-in. To use another, you connect again.
- It has no narrower role of its own. There is no setting inside Notion MCP that gives the assistant less access than you have.
That last point is a real difference from Notion’s ordinary API. There, an internal connection operates as a separate bot user and can reach only the pages someone has shared with it through Add connections. Notion MCP does not work that way. The older open-source notion-mcp-server, which does take a token, is no longer actively maintained (opens in a new tab), and Notion recommends the hosted server for most people.
What admins control
- Workspace owners see and manage MCP connections under Settings, Connections.
- On Enterprise, admins can restrict which AI apps members may connect to an approved list, under Settings, Connections, Permissions, and block anything not on it.
- A Disconnect All Users button removes every external AI tool and MCP client connected through Notion MCP, and people then sign in again. Notion says you cannot yet disconnect everyone from one specific app.
- Organisation owners can list and revoke members’ MCP connections through Notion’s Admin API.
- Per-user detail is limited. Notion’s Help Center (opens in a new tab) says detailed visibility into which users are using each tool is not yet available.
Limits that shape how it works
- Edits are search and replace.
notion-update-pagechanges content by matching exact text on the page. If any match fails, the whole update is refused and the page is left as it was. That is a good safety property, and it means the assistant has to read a page before it can change it. - Big pages can come back in parts. When some of a page cannot be loaded,
notion-fetchmarks the result as truncated and returns the IDs of the missing sections to fetch separately. - SQL answers are lossy. Notion warns that SQL output can leave out mentions, link targets and formatting, and says to read a property in rows mode or with
notion-fetchbefore changing it. - Very large or heavily formatted content can fail to create in one call, and the whole call fails with it. Splitting the content into several calls or child pages is Notion’s advice.
- Several features depend on your plan: connected-app search needs Notion AI, some search filters need Business or Enterprise, SQL queries are metered outside Business and Enterprise with Notion AI, and meeting notes and Custom Agents need Business or higher with Notion AI.
- Sign-in is interactive. The hosted server requires the OAuth flow; Notion says (opens in a new tab) non-interactive authorisation is being worked on.
What it does not do
- Delete. The published tool list has no tool for deleting or trashing a page or a database. If something needs removing, you do it in Notion.
- Change sharing. There is no tool to share a page, change its permissions or invite someone. Access stays where you set it.
- Run the workspace. Members and teamspaces can be read, not managed, and there are no tools for workspace settings or billing.
- Open connected-app results. Results from Slack, Google Drive and the rest come back from AI search, but Notion says they cannot be read with
notion-fetch. - Keep its own name. Because it signs in as you, what it changes is changed with your account. If you want to tell its edits from yours later, that has to come from a habit, such as a comment line, not from Notion MCP.
A sensible way to start
- Pick a small, low-stakes teamspace or page tree and ask for reads only: search, summarise, list what is out of date.
- Keep your client’s approval prompt on for every create and update, and read what it proposes before you approve. Notion’s security guidance (opens in a new tab) asks for exactly this.
- Treat page content as untrusted. Notion warns that text in a page can be written to redirect an assistant, and that a client can pass what it reads to other tools in the same session.
- When a request fails oddly, ask the assistant to call
notion-get-tool-accessfirst. Plan limits explain a lot of surprises.
Where a task board fits
Notion MCP hands an assistant your access to a whole workspace, which suits documents and databases. If the part you want an assistant on is the list of work, fenbs gives it a narrower seat: it connects over MCP with a browser sign-in, holds your role on one board narrowed by the scopes you tick (read, write, comment), and every change it makes is recorded under its own name. A task can link to the Notion page it came from. See fenbs vs Notion for where each fits.
Related
Set it up: Notion MCP with Claude Code or Notion MCP with ChatGPT. The same question for other trackers: what the Jira MCP server can do and what the Linear MCP server does. What can go wrong with any connection: MCP security risks.