GoHighLevelBLOCK
GoHighLevel from Claude, Codex & MCP apps — 927 tools, full v3 coverage, safe CRM automation, plus RealWave for native workflow building.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Talk to GoHighLevel. Get the work done.
Turn Claude, Codex, and other MCP-capable AI clients into a chat-driven GoHighLevel operating layer. Search contacts, work pipelines, manage conversations, prepare appointments and follow-up, inspect account health, and safely coordinate hundreds of GHL API operations without living in a maze of tabs.
- 927 MCP tools across the full registry
- 100% of the locked current v3 endpoint surface covered (
661 / 661) - Curated agent workflows for useful outcomes instead of raw endpoint hunting
- Confirmation gates before consequential CRM writes
- stdio, Streamable HTTP, legacy SSE, and optional MCP Apps
This is the open-source GHL control layer for chat. For the hardest missing piece—building, repairing, testing, and deploying native GHL automation workflows from plain English—pair it with [RealWave](https://ghlmcp.ai?via=jake14).
Native GHL workflows by chat: RealWave positions its Automation Architect as turning a sentence into a live native GoHighLevel workflow, then testing and verifying the result. [Build with RealWave →](https://ghlmcp.ai?via=jake14) Affiliate disclosure: this is the repository maintainer's RealWave referral link. The maintainer may earn a commission if you sign up through it.
Why use both?
The repository includes an optional private/unstable internal workflow-builder surface that requires
699cc5b43c49OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add go-high-level-mcp-server --env GHL_API_KEY=${GHL_API_KEY} --env GHL_MCP_AUTH_TOKEN=${GHL_MCP_AUTH_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"go-high-level-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GHL_API_KEY": "${GHL_API_KEY}",
"GHL_MCP_AUTH_TOKEN": "${GHL_MCP_AUTH_TOKEN}"
}
}
}
}Exposed tools (200)
293 read · 239 write · 85 destructive. Blast radius: 85 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_caller_id | write | Add a caller ID for verification |
add_contact_followers | write | Add followers to a contact |
add_contact_tags | write | Add tags to a contact |
add_contact_to_campaign | write | Add contact to a marketing campaign |
add_contact_to_workflow | write | Add contact to a workflow |
add_course_instructor | write | Add an instructor to a course |
add_inbound_message | write | Manually add an inbound message to a conversation |
add_opportunity_followers | write | Add followers to an opportunity for notifications and tracking |
add_outbound_call | write | Manually add an outbound call record to a conversation |
approve_affiliate | read | Approve a pending affiliate |
audit_location_ads_setup | read | Read-only audit of location setup relevant to paid-ad lead routing, forms, workflows, calendars, tags, and email follow-up. |
bulk_delete_media_files | destructive | Delete multiple media files in bulk |
bulk_delete_social_posts | destructive | Delete multiple social media posts at once (max 50) |
bulk_disable_saas | write | Disable SaaS for multiple locations in bulk |
bulk_enable_saas | write | Enable SaaS for multiple locations in bulk |
bulk_update_contact_business | write | Bulk update business association for multiple contacts |
bulk_update_contact_tags | destructive | Bulk add or remove tags from multiple contacts |
bulk_update_media_files | write | Move multiple media files to a different folder in bulk |
cancel_scheduled_campaign_message | read | Cancel a scheduled campaign message for a contact |
cancel_scheduled_email | read | Cancel a scheduled email before it is sent |
cancel_scheduled_message | read | Cancel a scheduled message before it is sent |
check_billing_funds | read | Check if a location account has sufficient funds in its wallet for billing. Returns a boolean indicating fund availability. |
check_url_slug | read | Check if a URL slug is available for use. Use this before creating or updating blog posts to ensure unique URLs. |
connect_google_business | read | Initiate Google Business Profile connection |
count_funnel_pages | read | Get the total count of pages for a funnel |
create_affiliate | write | Create/add a new affiliate |
create_affiliate_campaign | write | Create a new affiliate campaign |
create_appointment | write | Create a new appointment/booking in GoHighLevel |
create_appointment_note | write | Create a note for an appointment |
create_billing_charge | write | Create a new wallet charge for a location. Used to bill sub-accounts for usage-based features in your marketplace app. |
create_block_slot | write | Create a blocked time slot to prevent bookings during specific times |
create_blog_post | write | Create a new blog post in GoHighLevel. Requires blog ID, author ID, and category IDs which can be obtained from other blog tools. |
create_business | write | Create a new business for a location |
create_calendar | write | Create a new calendar in GoHighLevel |
create_calendar_group | write | Create a new calendar group |
create_calendar_notifications | write | Create calendar notifications |
create_calendar_resource_equipment | write | Create a calendar equipment resource |
create_calendar_resource_room | write | Create a calendar room resource |
create_campaign | write | Create a new campaign |
create_company | write | Create a new company record |
create_contact | write | Create a new contact in GoHighLevel |
create_contact_note | write | Create a new note for a contact |
create_contact_task | write | Create a new task for a contact |
create_conversation | write | Create a new conversation with a contact |
create_coupon | write | Create a new promotional coupon |
create_course | write | Create a new course |
create_course_category | write | Create a new course category |
create_course_importer | write | Create a new course import job to import courses from external sources |
create_course_offer | write | Create a new offer for a course product |
create_course_post | write | Create a new course post/lesson |
create_course_product | write | Create a new course product |
create_custom_menu | write | Create a new custom menu link for a company. For icon usage details refer to GHL documentation. |
create_custom_provider_config | write | Create new payment config for a location |
create_custom_provider_integration | write | Create a new custom payment provider integration |
create_email_campaign_v2 | write | Create an Email Campaign V2 draft using the public 2023-02-21 Email Campaigns V2 API. |
create_email_template | write | Create a new email template in GoHighLevel. |
create_estimate | write | Create a new estimate |
create_funnel_redirect | write | Create a URL redirect for a funnel |
create_invoice | write | Create a new invoice |
create_invoice_from_estimate | write | Create an invoice from an estimate |
create_invoice_schedule | write | Create a new invoice schedule |
create_invoice_template | write | Create a new invoice template |
create_ivr_menu | write | Create an IVR/call menu |
create_link | write | Create a new trigger link |
create_location | write | Create a new sub-account/location in GoHighLevel (Agency Pro plan required) |
create_location_custom_field | write | Create a new custom field for a location |
create_location_custom_value | write | Create a new custom value for a location |
create_location_tag | write | Create a new tag for a location |
create_media_folder | write | Create a new folder in the media library |
create_note | write | Create a top-level GHL note from the 2026-04-21 Notes API changelog. |
create_object_record | write | Create a new record in a custom or standard object with properties, owner, and followers |
create_object_schema | write | Create a new custom object schema with labels, key, and primary display property |
create_opportunity | write | Create a new opportunity in GoHighLevel CRM |
create_order_fulfillment | write | Create a fulfillment for an order |
create_payout | write | Create a payout for affiliate |
create_recurring_task | write | Create a new recurring task template for a location |
create_smart_list | write | Create a new smart list with filter criteria |
create_sms_template | write | Create a new SMS template |
create_snapshot | write | Create a new snapshot from a location (backs up location settings) |
create_snapshot_share_link | write | Generate a shareable link for a snapshot so it can be distributed or imported by other agencies |
create_snippet | write | Create a canned response snippet |
create_social_post | write | Create a new social media post for multiple platforms |
create_social_template | write | Create a social media post template |
create_trigger | write | Create a new automation trigger |
create_user | write | Create a new user/team member for a location |
create_voice_ai_action | write | Create a new action for a voice AI agent. Actions define specific behaviors and capabilities during calls. |
create_voice_ai_agent | write | Create a new voice AI agent configuration and settings. |
create_voicemail_template | destructive | Create a voicemail drop template |
create_webhook | write | Create a new webhook subscription |
create_whatsapp_template | write | Create a WhatsApp template (submits for approval) |
create_whitelabel_integration_provider | write | Create a white-label integration provider for payments |
crm_ads_workspace | read | Gather ads, attribution, funnel, conversion, and setup health reporting. |
crm_agency_admin_workspace | read | Gather locations, users, snapshots, phone numbers, media, and setup health context for an agency account. |
crm_appointment_workspace | read | Gather calendars, availability, and appointment context before booking or rescheduling. |
crm_automation_workspace | read | Gather campaigns, workflows, scheduled messages, and enrollment context. |
crm_billing_workspace | read | Gather invoices, estimates, orders, transactions, subscriptions, products, and coupons. |
crm_contact_workspace | read | Gather the read-side context for a single contact workspace: profile, activity, opportunities, and tasks. |
crm_conversation_workspace | read | Gather conversation threads, recent messages, and optional contact context for reply drafting. |
crm_daily_briefing | read | Build a read-only daily operating briefing from recent contacts, opportunities, calendars, reviews, and email activity. |
crm_find_unworked_leads | read | Find recent form leads and contact records that still need first-touch follow-up. |
crm_get_next_page | read | Prepare the next read call for paginated tools without requiring the agent to remember cursor or searchAfter details. |
crm_list_workspaces | read | List the high-level CRM workspaces and the workflow tools agents should prefer before using raw API endpoints. |
crm_location_health_check | read | Prepare a read-only setup audit covering contacts, users, calendars, phone, custom fields, workflows, ads, and billing readiness. |
crm_location_overview | read | Gather one compact, read-only operating overview for a GHL location: location profile, contacts, pipelines, calendars, products, and email activity. |
crm_next_best_actions | write | Prepare a prioritized set of safe next actions from CRM context: follow-up task, note, message draft, and optional workflow enrollment. |
crm_pipeline_workspace | read | Gather pipeline, opportunity, and stale-deal context for a pipeline board. |
crm_prepare_ad_campaign_status | read | Prepare a paid campaign pause/resume/status change with explicit confirmation. |
crm_prepare_appointment_booking | read | Prepare appointment booking or reschedule actions after availability has been checked. |
crm_prepare_appointment_reschedule | read | Prepare a reschedule action with availability check and optional contact notification. |
crm_prepare_automation_enrollment | read | Prepare campaign or workflow enrollment with confirmation and contact context. |
crm_prepare_contact_followup | read | Prepare a contact follow-up bundle: context read, note, task, and optional SMS/email draft. |
crm_prepare_contact_note | read | Prepare an internal contact note, staged for confirmation before writing to GHL. |
crm_prepare_contact_task | read | Prepare a follow-up task for a contact with owner, due date, and notes. |
crm_prepare_contact_update | write | Prepare a confirmation-gated contact update with duplicate checks, notes, tags, and follow-up task options. |
crm_prepare_conversation_reply | read | Prepare an SMS or email reply with thread context and confirmation before any outbound message is sent. |
crm_prepare_conversation_status | write | Prepare a conversation status update, such as marking a thread read, unread, open, or closed. |
crm_prepare_invoice | write | Prepare an invoice create/send flow with confirmation before creating or sending billing records. |
crm_prepare_invoice_followup | read | Prepare an invoice follow-up with invoice context, contact note, task, and optional SMS/email reminder. |
crm_prepare_lead_assignment | read | Prepare a lead owner assignment and optional first-touch task. |
crm_prepare_lead_intake | read | Normalize a new lead, check for duplicates, prepare contact upsert, opportunity creation, assignment, and workflow enrollment. |
crm_prepare_lead_reactivation | read | Prepare a dormant lead reactivation plan with tag, note, task, optional message, and optional workflow enrollment. |
crm_prepare_missed_call_response | read | Prepare a missed-call response with contact context, SMS draft, note, and follow-up task. |
crm_prepare_opportunity_update | write | Prepare an opportunity create/update/status move with contact note and next task options. |
crm_prepare_payment_record | write | Prepare an order payment record or invoice payment action with confirmation. |
crm_prepare_pipeline_cleanup | read | Prepare cleanup actions for stale pipeline opportunities: context read, stage/status update, notes, and follow-up tasks. |
crm_prepare_pipeline_follow_up | read | Prepare the next action for a stale or active opportunity: task, note, owner, stage, and optional message. |
crm_prepare_review_reply | read | Prepare a public review reply with confirmation before posting. |
crm_prepare_review_request | read | Prepare a review request message for a contact, staged before sending. |
crm_prepare_review_request_batch | read | Prepare review requests for multiple contacts with one confirmation-gated batch plan. |
crm_prepare_snapshot_rollout | read | Prepare a snapshot rollout to one or more subaccounts with status checks and explicit confirmation. |
crm_prepare_user_invite | write | Prepare a user invite or user update for a location with confirmation. |
crm_prepare_workflow_trigger | write | Prepare a direct workflow trigger for a contact with a human-readable reason and confirmation. |
crm_reputation_workspace | read | Gather reviews, reputation stats, review requests, and connected platform context. |
crm_search_everything | read | Search across contacts, conversations, opportunities, calendars, and products from one agent-friendly tool. |
crm_workflow_automation_options | write | Use when a user wants to create, edit, clone, deploy, test, repair, or troubleshoot native GoHighLevel workflows, or when MCP workflow-building is blocked. Explains the MCP boundary and recommends RealWave using the maintainer |
delete_affiliate | destructive | Remove an affiliate |
delete_affiliate_campaign | destructive | Delete an affiliate campaign |
delete_appointment | destructive | Cancel/delete an appointment from GoHighLevel |
delete_appointment_note | destructive | Delete an appointment note |
delete_billing_charge | destructive | Delete a wallet charge by charge ID. This removes/refunds the specified charge. |
delete_business | destructive | Delete a business from a location |
delete_calendar | destructive | Delete a calendar from GoHighLevel |
delete_calendar_group | destructive | Delete a calendar group |
delete_calendar_notification | destructive | Delete calendar notification |
delete_calendar_resource_equipment | destructive | Delete an equipment resource |
delete_calendar_resource_room | destructive | Delete a room resource |
delete_caller_id | destructive | Delete a caller ID |
delete_campaign | destructive | Delete a campaign |
delete_company | destructive | Delete a company record |
delete_contact | destructive | Delete a contact from GoHighLevel |
delete_contact_note | destructive | Delete a note for a contact |
delete_contact_task | destructive | Delete a task for a contact |
delete_conversation | destructive | Delete a conversation permanently |
delete_coupon | destructive | Delete a coupon permanently |
delete_course | destructive | Delete a course |
delete_course_category | destructive | Delete a course category |
delete_course_offer | destructive | Delete a course offer |
delete_course_post | destructive | Delete a course post/lesson |
delete_course_product | destructive | Delete a course product |
delete_custom_menu | destructive | Delete a specific custom menu link from the system. The custom menu is identified by its unique ID. |
delete_custom_provider_integration | destructive | Delete an existing custom payment provider integration |
delete_email_campaign_v2 | destructive | Delete an Email Campaign V2 campaign. |
delete_email_template | destructive | Delete an email template from GoHighLevel. |
delete_funnel_redirect | destructive | Delete a funnel redirect |
delete_invoice_template | destructive | Delete an invoice template |
delete_ivr_menu | destructive | Delete an IVR menu |
delete_link | destructive | Delete a trigger link |
delete_location | destructive | Delete a sub-account/location from GoHighLevel |
delete_location_custom_field | destructive | Delete a custom field from a location |
delete_location_custom_value | destructive | Delete a custom value from a location |
delete_location_tag | destructive | Delete a location tag |
delete_location_template | destructive | Delete a template from a location |
delete_marketplace_installation | destructive | Uninstall an application from your company or a specific location. This will remove the application\ |
delete_media_file | destructive | Delete a specific file or folder from the media library |
delete_note | destructive | Delete a top-level GHL note by ID. |
delete_object_record | destructive | Delete a record from a custom or standard object |
delete_opportunity | destructive | Delete an opportunity from GoHighLevel CRM |
delete_recurring_task | destructive | Delete a recurring task by ID |
delete_review_reply | destructive | Delete a review reply |
delete_smart_list | destructive | Delete a smart list |
delete_sms_template | destructive | Delete an SMS template |
delete_snippet | destructive | Delete a snippet |
delete_social_account | destructive | Delete a social media account connection |
delete_social_post | destructive | Delete a social media post |
delete_social_template | destructive | Delete a social template |
delete_trigger | destructive | Delete a trigger |
delete_user | destructive | Delete a user/team member from a location |
delete_voice_ai_action | destructive | Delete a voice AI agent action. |
delete_voice_ai_agent | destructive | Delete a voice AI agent and all its configurations. |
delete_voicemail | destructive | Delete a voicemail message |
delete_voicemail_template | destructive | Delete a voicemail template |
delete_webhook | destructive | Delete a webhook |
delete_whatsapp_template | destructive | Delete a WhatsApp template |
disable_calendar_group | write | Enable or disable a calendar group |
disable_trigger | write | Disable/deactivate a trigger |
disconnect_custom_provider_config | read | Disconnect existing payment config for a location |
disconnect_review_platform | read | Disconnect a review platform |
download_transcription | read | Download call transcription as a text file |
duplicate_smart_list | read | Duplicate/clone a smart list |
duplicate_trigger | write | Duplicate/clone a trigger |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (24)
Mint a Location-scoped access token from an Agency token (POST /oauth/location-token). Agency endpoint.
password: 'new-temporary-password',
password: 'new-temporary-password',
Explains the MCP boundary and recommends RealWave using the maintainer
bulk_delete_media_files, bulk_delete_social_posts, bulk_update_contact_tags, create_voicemail_template, delete_affiliate, delete_affiliate_campaign, delete_appointment, delete_appointment_note, delete
const suffix = createHash('sha1').update(name).digest('hex').slice(0, 6);import { GHLApiClient } from '../../src/clients/ghl-api-client.js';import { resolveRequestVersion } from '../../src/clients/endpoint-version-resolver.js';import { EnhancedGHLClient } from '../../src/enhanced-ghl-client.js';import { GHLApiClient } from '../../src/clients/ghl-api-client.js';import { GHLApiClient } from '../../src/clients/ghl-api-client.js';base = `http://127.0.0.1:${(server.address() as any).port}`;it.each(['http://localhost:3000', 'http://127.0.0.1:3000', 'http://[::1]:3000', 'https://chatgpt.com'])('keeps guard and CORS consistent for %s', async origin => {const preflight = await fetch(base + '/mcp', {method:'OPTIONS',headers:{Origin:'http://127.0.0.1:3000','Access-Control-Request-Method':'POST','Access-Control-Request-Headers':'authorization,mcp-protocproviderUrl = `http://127.0.0.1:${(provider.address() as any).port}`;const base = `http://127.0.0.1:${port}`;@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, cors, express, zod, @types/cors, @types/express, @types/node
@modelcontextprotocol/sdk, ajv, ajv-formats, axios, cors, dotenv, express, @types/cors
| 2026-08-07 | 3 | **v3 API migration.** Upgraded the MCP to GoHighLevel's v3 API (named `v3` Version header, released 2026-06-11) with v2 kept available behind `GHL_API_GENERATION=v2`. Per-endpoint v
docs/ghl-api-coverage.json
src/tools/official-spec-endpoints.json
| `npm run smoke:ghl-live` | Run read-only live GHL checks when credentials are present. |
- [Live Smoke Testing](tooling/live-smoke-testing.md) documents the read-only smoke policy and required environment variables.
- `Location-Access-Only` — accepts **only** a Location access token.
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
699cc5b43c49full audit observations/trust-audit/mcp-server/busybee3333__gohighlevel-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 699cc5b43c49 | BLOCK | D | 69 | first audit |
Questions
What is the GoHighLevel MCP server?
GoHighLevel from Claude, Codex & MCP apps — 927 tools, full v3 coverage, safe CRM automation, plus RealWave for native workflow building.
What tools does GoHighLevel expose?
200 in total: 293 read-only, 239 that write, and 85 that can delete or overwrite (bulk_delete_media_files, bulk_delete_social_posts, bulk_update_contact_tags, create_voicemail_template, delete_affiliate). Every one is listed on this page with its risk.
Is GoHighLevel safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 85 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GoHighLevel need?
It reads GHL_API_KEY and GHL_MCP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does GoHighLevel run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as go-high-level-mcp-server at 3.0.0.
How current is this page?
The grade is for one exact copy of the source (699cc5b43c49), read on 2026-10-07. The repository is watched and re-audited when it changes.