Atlas / MCP servers / delorenj / Ticketmaster

TicketmasterSAFE

mcp/delorenj/ticketmaster

A Ticketmaster MCP server that provides query capabilites from the Discovery API

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/mcp-server-ticketmaster)

A Model Context Protocol server that provides tools for discovering events, venues, and attractions through the Ticketmaster Discovery API.

Features

  • Search for events, venues, and attractions with flexible filtering:
  • Keyword search
  • Date range for events
  • Location (city, state, country)
  • Venue-specific searches
  • Attraction-specific searches
  • Event classifications/categories
  • Output formats:
  • Structured JSON data for programmatic use
  • Human-readable text for direct consumption
  • Comprehensive data including:
  • Names and IDs
  • Dates and times (for events)
  • Price ranges (for events)
  • URLs
  • Images
  • Locations and addresses (for venues)
  • Classifications (for attractions)

Installation

Installing via Smithery

To install mcp-server-ticketmaster for Claude Desktop automatically via Smithery:

npx -y @smithery/cli install mcp-server-ticketmaster --client claude

Manual Installation

npx -y install @delorenj/mcp-server-ticketmaster

Configuration

The server requires a Ticketmaster API key. You can get one by:

  1. Going to https://developer.ticketmaster.com/
  2. Creating an account or signing in
  3. Going to "My Apps" in your account
  4. Creating a new app to get your API key

Set your API key in your MCP settings file:

{
"mcpServers": {
"ticketmaster": {
"command": "npx",
"args": ["-y", "@delorenj/mcp-server-ticketmaster"],
"env": {
"TICKETMASTER_API_KEY": "your-api-key-here"
}
}
}
}

Usage

The server provides a tool called `search_ticketmast

Read from source at commit 7f6ef997a62cOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server-ticketmaster --env TICKETMASTER_API_KEY=${TICKETMASTER_API_KEY} -- npx -y @delorenj/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server-ticketmaster": {
      "command": "npx",
      "args": [
        "-y",
        "@delorenj/[email protected]"
      ],
      "env": {
        "TICKETMASTER_API_KEY": "${TICKETMASTER_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
search_ticketmasterreadSearch for events, venues, or attractions on Ticketmaster
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (1)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@playwright/test, axios, dotenv, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 7f6ef997a62cfull audit observations/trust-audit/mcp-server/delorenj__ticketmaster.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-097f6ef997a62cSAFEB89first audit
06

Questions

What is the Ticketmaster MCP server?

A Ticketmaster MCP server that provides query capabilites from the Discovery API

What tools does Ticketmaster expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Ticketmaster safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Ticketmaster need?

It reads TICKETMASTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Ticketmaster run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @delorenj/mcp-server-ticketmaster at 0.2.5.

How current is this page?

The grade is for one exact copy of the source (7f6ef997a62c), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement