glif-mcp-serverSAFE
Glif's hosted MCP server, plugin and skills for creating images, video and audio. Works with Claude, ChatGPT, Codex, Cursor and more.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Glif is a creative agent. Describe what you want to make, and it picks the models and does the work across images, video and audio. It also transcribes, renders HTML, searches the web, runs code and chains multi-step media jobs.
- Endpoint:
https://glif.app/api/mcp(Streamable HTTP, JSON-RPC 2.0) - Auth: OAuth 2.1 sign-in with your Glif account. Plain HTTP clients can send a
glif_v1_...API key from glif.app/settings/api-tokens as a bearer token. - Install page with one-click buttons: https://glif.app/mcp
- Docs for agents: https://glif.app/llms.txt
This repo holds three things:
- A plugin for Claude, Codex, ChatGPT, Cursor, VS Code, Copilot and Gemini CLI. It connects the hosted server and bundles public skills.
- Public Agent Skills in
skills/. - Registry metadata for the hosted server (
server.json). The server itself runs on glif.app and is not open source.
[!NOTE] Looking for the old locally run stdio server (npm @glifxyz/glif-mcp-server)? It's deprecated. The code is parked on the `legacy-local-server` branch.Install the plugin
The plugin adds the Glif server plus the skills below. Your client opens a browser sign-in the first time it connects.
Claude Code
claude plugin marketplace add glifxyz/glif-mcp-server claude plugin install glif@glif
In a session, /plugin marketplace add glifxyz/glif-mcp-server then /plugin install glif@glif does the same. Run /mcp to sign in.
Claude (web and desktop)
Customize → Plugins → Add marketplace, then enter glifxyz/glif-mcp-server. To add only the server, go to Settings → Connectors → Add custom connector and paste https://glif.app/api/mcp.
Codex
codex plug
67a039fe1458OBSERVED · 2026-10-07Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
streamable-http
- **Auth:** OAuth 2.1 sign-in with your Glif account. Plain HTTP clients can send a `glif_v1_...` API key from [glif.app/settings/api-tokens](https://glif.app/settings/api-tokens) as a bearer token.
| 12 | [ChatGPT and Codex directory](https://developers.openai.com/plugins/deploy/submission) | ChatGPT and Codex users | Upload a ZIP at platform.openai.com/plugins. Needs a verified org, the `/.well
- If the client cannot complete OAuth, the user needs a free account at https://glif.app first. Clients without OAuth can send a `glif_v1_...` API key from https://glif.app/settings/api-tokens as `Aut
Gates applied: no_behavioural_pass.
67a039fe1458full audit observations/trust-audit/mcp-server/glifxyz__glif-mcp-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 67a039fe1458 | SAFE | B | 89 | first audit |
Questions
What is the glif-mcp-server MCP server?
Glif's hosted MCP server, plugin and skills for creating images, video and audio. Works with Claude, ChatGPT, Codex, Cursor and more.
Is glif-mcp-server safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does glif-mcp-server need?
No credential environment variables were found in its source, so it appears to need none.
How does glif-mcp-server run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (67a039fe1458), read on 2026-10-07. The repository is watched and re-audited when it changes.