Pipedrive MCP Server

39 tools. 19 can modify or destroy data without limits.

6 destructive tools with no built-in limits. Policy required.

Last updated:

19 can modify or destroy data
20 read-only
39 tools total

Community server · catalogue entry verified 12/06/2026

How to control Pipedrive MCP Server ↓

What Pipedrive MCP Server exposes to your agents

Read (20) Write / Execute (13) Destructive / Financial (6)
Critical Risk

The most dangerous Pipedrive MCP Server tools

19 of Pipedrive MCP Server's 39 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control Pipedrive MCP Server

PolicyLayer is an MCP gateway — it sits between your AI agents and Pipedrive MCP Server, and nothing reaches the server without passing your rules. These are the rules we recommend:

Deny destructive operations
{
  "delete-activity": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "convert-lead-to-deal": {
    "limits": [
      {
        "counter": "convert-lead-to-deal_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "find-person": {
    "limits": [
      {
        "counter": "find-person_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register Pipedrive MCP Server — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON PIPEDRIVE →

Free to start. No card required.

All 39 Pipedrive MCP Server tools

READ 20 tools
Read find-person ⭐ PRIMARY TOOL for finding persons - USE THIS BY DEFAULT. Reliable fuzzy matching across name, email, phone, a Read get-deal Get a specific deal by ID including custom fields Read get-deal-notes Get detailed notes and custom booking details for a specific deal Read get-deals Get deals from Pipedrive with flexible filtering options including search by title, date range, owner, stage, Read get-organization Get a specific organization by ID including custom fields Read get-organizations Get all organizations from Pipedrive with optional filtering by name Read get-person Get a specific person by ID including custom fields Read get-person-notes Get all notes attached to a specific person Read get-persons Get all persons from Pipedrive with optional filtering by name, email, organization, or phone Read get-persons-by-organization Get all persons belonging to a specific organization Read get-pipeline Get a specific pipeline by ID Read get-pipelines Get all pipelines from Pipedrive Read get-stages Get all stages from Pipedrive Read get-users Get all users/owners from Pipedrive to identify owner IDs for filtering deals Read search-all Search across all item types using Pipedrive Read search-deals Search deals by term Read search-leads Search leads by term Read search-organizations Search organizations using Pipedrive Read search-persons ⚠️ FALLBACK TOOL - Use Read search-persons-by-notes Search for persons who have attached notes containing a specific keyword. This searches the content of notes l

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about Pipedrive MCP Server

Can an AI agent delete data through the Pipedrive MCP Server MCP server? +

Yes. The Pipedrive MCP Server server exposes 6 destructive tools including delete-activity, delete-deal, delete-lead. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through Pipedrive MCP Server? +

The Pipedrive MCP Server server has 13 write tools including convert-lead-to-deal, create-activity, create-deal. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach Pipedrive MCP Server.

How many tools does the Pipedrive MCP Server MCP server expose? +

39 tools across 3 categories: Destructive, Read, Write. 20 are read-only. 19 can modify, create, or delete data.

How do I enforce a policy on Pipedrive MCP Server? +

Register the Pipedrive MCP Server MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every Pipedrive MCP Server tool call.

Deterministic rules across all 39 Pipedrive MCP Server tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

39 Pipedrive MCP Server tools catalogued and risk-classified — across an index of 43,000+ MCP servers.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.