An invoice arrives by e-mail and you ask your AI assistant to pull the amount and the due date out of it. The answer you get is that through the MCP connector the assistant can see the attachment’s name and its size, but not what is inside it. You would have to save the file to disk yourself, which defeats the point of automating anything.

Fortunately, MCP is not the only road an AI takes into a service. Today we’ll walk through the others and show you how to ask Claude to take one of them.

The limit is often in the channel, not in the service

“I don’t have a tool for that” means the operation isn’t offered by the channel – the kind of connection the AI assistant happens to be using to reach the service. The Gmail MCP connector is a good example, because Anthropic spells the limit out: the connector gives access to information about an attachment, not to its contents. Gmail does have a separate API, and in it a method that returns exactly those contents.

So start by asking where that limit actually sits:

You couldn't carry out this operation through MCP. Check the service's documentation for whether it offers the operation at all – in its API, in a command line tool or in a data export. Tell me what you found, and don't change anything yet.

The answer settles whether it’s worth looking further. When a service doesn’t offer something to anyone, no other route turns that around.

A connector from the directory, an MCP server added by address and a server running on your own computer are three different ways of plugging in a service, and each gives you a different set of tools. What sets them apart is covered in the tip on connectors and MCP.

A service API cuts out the middleman

MCP usually works off an API, but as a middleman it narrows the list down to the handful of operations most people need. Claude Code can write a request to an API and run it, so you ask for that connection in conversation, without writing a line of code yourself.

API stands for application programming interface. Where you click buttons on the service’s website, a program reaches for the API: the same service exposed as a list of commands that can be called from outside.

So why didn’t we connect Gmail through its API in the first place? Simplicity and safety. A connector takes a few clicks in the settings on claude.ai. An API connection needs special keys, and getting hold of them usually takes more work.

An API gives you a wider range of operations, and some of them can break things when used carelessly. It will let you delete every message in a mailbox with a single call, without asking for confirmation.

So use an API thoughtfully, but don’t be afraid of it. We take this route ourselves every day. In our experience, an e-mail with a graphic signature doesn’t survive the Gmail connector – the image simply vanishes from the body – so our messages with a signature are put together by a script that talks straight to the Gmail API. Same mailbox, different route, different result.

This service has a public API. Prepare a request that fetches the contents of the attachment from the latest message from this sender. First tell me what credential you need and where to get it, and don't run anything until I approve it.

A service’s command line keeps the keys to itself

Some services ship their own command line program, a CLI. GitHub has one, so do Stripe and Cloudflare.

CLI stands for command line interface. It’s a program with no windows or buttons: you work with it by typing commands in a terminal – which is exactly how Claude Code uses it.

You log in to a CLI once, on your own computer, and from then on Claude Code calls it like any other command. The Claude Code documentation suggests this route itself: when there’s no built-in tool for the command you need, ask the AI to run it.

Check whether this service has an official command line tool. If it does, tell me how to log in to it and then stop – I'll do the login myself.

The advantage of a CLI is that no key ever travels into your files: the credential stays where the service’s own program put it, usually in the system keychain. The one catch is that not every service offers such a tool. Google has a CLI, but not for personal accounts – its gcloud tool handles Google cloud resources only.

A file on disk needs no credentials at all

Plenty of services let you export your data to a file, and a report, a price list or a record of payments can also be saved from the browser by hand. The AI reads a file like that straight from disk, with no login. It’s the simplest route, and it gets passed over precisely because it looks too ordinary.

Claude Code opens text files, images and PDFs without any add-ons, and reads spreadsheets and Word documents with a skill that Anthropic includes with your account. If it still runs into a format it can’t open, ask it to convert the file into one it can read:

There's a file with a bank statement in this folder. Read it, and if you can't open that format, convert the file into a format you can read.

The same goes for public addresses. A blog’s RSS feed, an open file with a price list, a page with no login – Claude Code fetches all of it with no setup at all, because public data needs no credentials from anyone.

The browser is what’s left when no other route leads there

The hardest case is the one left over: a service with no MCP server, no API, no CLI and no way to export the data. Then the route is the same window you work in yourself – the Claude extension for Chrome. The AI reads the page and clicks on it, because your session with that service is already open. The extension works on every paid plan; it isn’t available on the free account.

At a login screen and at a CAPTCHA the work stops – the AI hands that step back to you. The more serious problem lies elsewhere: an open page can carry hidden instructions that try to steer the assistant in your place. Anthropic reports that, against its own set of known attack techniques, the success rate of such attempts falls below 0.08 percent, and notes itself that this is not zero – so when working in the browser, watch what the AI is doing, especially in a payments panel.

What the extension can do in a browser and how to switch it on is covered in the news about Claude clicking in your browser.

What these routes ask of you

Each one has its price, and you’re better off knowing it early than late.

RouteCredentialWhat to watch for
Service APIkey or OAuththe key sits in a file on disk
Command lineone loginthe tool may not exist
Exported filenonedata as of the export day
Browseryour own logina page can steer the AI

An API key is a password: don’t send it in conversation, and ask the AI to write itself a rule that refuses to read the file the key sits in. Services also count requests, and some of the thresholds are low – Airtable accepts five requests per second per base, and OpenWeather’s One Call API allows a thousand a day before it starts charging. For a one-off job that’s beside the point; for a script running in a loop it isn’t. Some APIs also charge by usage, so if you need hundreds of requests, ask about pricing first.

More on what leaves your files for the model provider, and how to keep an assistant out of chosen folders, is in the tip on client data and AI.

In short

The order to search in comes from the Claude Code documentation itself: the MCP server first, then a command in the terminal, meaning an API or a CLI, then working in the browser, with screen control last. Slot an exported file into that order wherever you happen to have one – the higher up that order you reach, the less there is to set up and the fewer of your credentials sit outside the service.

What matters most, though, is the one sentence worth having ready whenever the AI reports a missing tool:

I understand you can't do this through MCP. Check what other routes there are for it – the service's API, its command line tool, an export to a file or working in the browser – and tell me which of them will need my help.

Sometimes the answer is “none”, and that is a result too: you then know the problem sits with the service, not with the channel you reach it through.