Letting an AI assistant near your merch budget sounds risky until you see where the controls sit. Here's how Sunday MCP handles sign-in, approvals and shipments, plus the general MCP security habits worth adopting for any connector.
Part of our complete guide to Sunday MCP: manage your merch from Claude, ChatGPT or Gemini.
MCP security for a business team comes down to three questions: who the agent signs in as, what it can do without asking, and where a person has to say yes. In Sunday MCP, the agent signs in with your own Sunday account through OAuth, cannot place orders, and needs a human to approve every quote and confirm every shipment.
The first question finance asks about AI agents is a fair one: can it spend money? For Sunday MCP the answer is no. It can prepare almost everything, and a person still commits every euro. This article explains how that works, and covers the security habits worth applying to every MCP connector you add.
What's actually risky about giving an AI agent access to spend?
Three things, in rising order of cost. The agent reads data it shouldn't. The agent misunderstands a request and prepares the wrong thing. The agent commits money or ships goods based on that misunderstanding.
The first is an access problem, solved by how the connector signs in. The second will happen, the same way a colleague occasionally misreads an email. The third is the one that hurts, and it's the one a well-designed connector should make impossible without a person in the loop. Merch makes this concrete. A wrong reorder of 500 hoodies is a production run, not a refundable click.
How does MCP authorization work?
MCP is the open standard that lets assistants like Claude, ChatGPT and Gemini talk to other software. If that's new, our plain-English guide to MCP servers covers the basics. For authorization, most remote MCP servers use OAuth: you're sent to the vendor's own login page, you sign in, and the assistant receives permission to act through your account. You never paste a password into the chat.
Sunday MCP works this way. You add Sunday as a custom connector using the URL you receive when access is granted, then sign in with your own Sunday account. The assistant works through that login, so it sees what your Sunday account can see. There's no shared key floating around a team channel. The setup guide walks through the steps.
Access to Sunday MCP itself is on request, and included on every Sunday plan. Sunday rolled it out internally first, and is now opening it to partners and agencies and to teams with large merch programs.
Why is quote-then-approve the core spend control?
Because it moves the commitment out of the conversation. In Sunday MCP, an agent can suggest products, calculate prices, build a budget split and generate a quote. It can show you the quote or send it. What it cannot do is turn that quote into an order. A person approves it personally, through a link.
You, in ChatGPT · Illustrative example: Reorder 300 T-shirts like last time and ship them to the Lisbon office.
Sunday MCP: I've prepared a quote for 300 T-shirts matching your last order. I can't place the order myself. Once someone approves the quote through this link, I'll plan the shipment to Lisbon for you to confirm.
That design means the agent can be fast and occasionally wrong without anything expensive happening. You review a document, not a receipt.
What still needs a human in Sunday MCP?
| Action | What the agent does | What a person does |
|---|---|---|
| Product and kit ideas | Suggests products and pre-made kits that fit your audience | Chooses |
| Prices and budgets | Calculates prices, proposes a budget split, builds a shareable wish list | Decides the budget |
| Quotes and reorders | Generates the quote and shows or sends it | Approves it through a link |
| Orders | Cannot place them | Approving the quote is the order step |
| Designs | Requests designs on selected products | Signs off against brand guidelines |
| Shipments | Plans them | Confirms them |
| Stock and reporting | Answers data questions, requests reports | Reads them |
Merch involves designs, approvals and brand guidelines. Sunday's position is to automate as much of the preparation as possible and keep a person confirming that the brand is respected and the spend is right.

A real Sunday mailer going through a letterbox. Before a parcel like this ships through Sunday MCP, a person has approved the quote and confirmed the shipment.
How should you handle budgets with an agent?
Assembling budgets is one of the best jobs to give an assistant. Say you have 20,000 euros and a target audience: one prompt can search the catalog, weigh what's popular and propose a split. That's a suggestion, not a spend.
The hard limit in Sunday MCP is the approval. No money is committed until a person approves a quote, so your budget control is whoever holds that approval. A few habits help:
- State the budget in the prompt, so suggestions and quotes come back inside it.
- Keep the approver the same person who approves merch spend today.
- Check each quote against the budget before approving, the way you would a supplier quote.
- Share the wish list with colleagues before anyone asks for a quote, so the discussion happens early.
Other vendors place the limit elsewhere. Goody's gifting MCP, for example, launched in June 2026 with daily budget limits alongside a review of each gift. We compare the approaches in Sunday MCP vs Goody and Sendoso.
An agent that prepares, and a person who decides
Quotes, stock checks and reorders from Claude, ChatGPT or Gemini. Nothing is ordered until your team approves it.
Request Sunday MCP accessIncluded on every Sunday plan · Works with Claude, ChatGPT and Gemini · You approve every order
MCP security best practices for non-technical teams
These apply to every connector you add to Claude, ChatGPT or Gemini, whether it's Sunday, a CRM or a payments tool.
- Use official servers. Connect with the URL the vendor gives you, not one copied from a forum. Our roundup of the best MCP servers for marketing, HR and ops sticks to official ones.
- Sign in as yourself. Prefer OAuth with your own account over shared logins or pasted API keys.
- Start read-only. Spend the first week asking questions before you ask for actions.
- Keep a human on money and shipping. Check what each connector can do without a confirmation step before you rely on it.
- Watch what else is in the conversation. Mixing an inbox, the web and a spending tool in one chat is where injection risk lives.
- Remove what you don't use. Disconnect connectors after a pilot or when someone changes roles.
- Write it down. A short internal policy beats a long one nobody reads.
What about prompt injection?
Prompt injection is when text the assistant reads, in an email, a web page or a shared document, contains instructions aimed at the AI rather than at you. It's a known risk for every AI tool that both reads outside content and takes actions.
You reduce it by keeping untrusted content and spending tools in separate conversations where you can, and by choosing connectors where actions need confirmation. With Sunday MCP, the worst a manipulated agent can do on the spending side is prepare a quote. That quote still lands in front of a person who has to approve it.
What should a simple internal policy say?
Half a page is enough. Who may connect Sunday MCP. Who approves quotes, and up to what amount without a second approver. Which other connectors may share a conversation with it. Who confirms shipments. When to review the setup.
If your company already routes merch through procurement, SSO or an HR system, our post on swag store integrations covers how those fit around Sunday. For the finance and procurement view of AI agents, including accountability and audit questions, read the agentic commerce FAQ for procurement and finance. And if you're not on Sunday yet, you can create a free account first.








