Atlas / MCP servers / ivo-toby / Contentful Management

Contentful ManagementBLOCK

mcp/ivo-toby/contentful-management

MCP (Model Context Protocol) server for the Contentful Management API

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
67 42r · 18w · 7d
Transport
sse · stdio · streamable-http
License
MIT
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Notice

This is a community driven server! Contentful has released an official server which you can find here

[](https://smithery.ai/server/@ivotoby/contentful-management-mcp-server)

An MCP server implementation that integrates with Contentful's Content Management API, providing comprehensive content management capabilities.

  • Please note \*; if you are not interested in the code, and just want to use this MCP in

Claude Desktop (or any other tool that is able to use MCP servers) you don't have to clone this repo, you can just set it up in Claude desktop, refer to the section "Usage with Claude Desktop" for instructions on how to install it.

Features

  • Content Management: Full CRUD operations for entries and assets
  • Comment Management: Create, retrieve, and manage comments on entries with support for both plain-text and rich-text formats, including threaded conversations
  • Space Management: Create, update, and manage spaces and environments
  • Content Types: Manage content type definitions
  • Localization: Support for multiple locales
  • Publishing: Control content publishing workflow
  • Bulk Operations: Execute bulk publishing, unpublishing, and validation across multiple entries and assets
  • Smart Pagination: List operations return maximum 3 items per request to prevent context window overflow, with built-in pagination support

Pagination

To prevent context window overflow in LLMs, list operatio

Read from source at commit 23aa1abd7336OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add contentful-management-mcp-server --env CONTENTFUL_MANAGEMENT_ACCESS_TOKEN=${CONTENTFUL_MANAGEMENT_ACCESS_TOKEN} --env PRIVATE_KEY=${PRIVATE_KEY} -- npx -y @ivotoby/[email protected]
claude-desktop
{
  "mcpServers": {
    "contentful-management-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@ivotoby/[email protected]"
      ],
      "env": {
        "CONTENTFUL_MANAGEMENT_ACCESS_TOKEN": "${CONTENTFUL_MANAGEMENT_ACCESS_TOKEN}",
        "PRIVATE_KEY": "${PRIVATE_KEY}"
      }
    }
  }
}
03

Exposed tools (67)

42 read · 18 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
TopicreadThe topic for the content
actionIdreadID of the AI Action (if known)
ai-actions-createwriteGuide for creating and configuring AI Actions in Contentful
ai-actions-invokewriteHelp with invoking AI Actions and processing results
ai-actions-overviewreadComprehensive overview of AI Actions in Contentful
ai-actions-variablesreadExplanation of variable types and configuration for AI Actions
api-operation-helpreadGet detailed help for specific Contentful API operations
asset-managementreadGuidance on managing digital assets like images, videos, and documents
bulk-operationsreadGuidance on performing actions on multiple entities simultaneously
bulk_validatereadValidate multiple entries at once
conceptreadContentful concept (Space/Environment/ContentType/Entry/Asset)
content-modeling-guidereadGuide through content modeling decisions and best practices
content-type-operationsreadHelp with defining and managing content types and their fields
create_ai_actionwriteCreate a new AI Action
create_commentwriteCreate a new comment on an entry. The comment will be created with the specified body and status. To create a threaded conversation (reply to an existing comment), provide the parent comment ID. This allows you to work around the 512-character limit by creating threaded replies.
create_content_typewriteCreate a new content type
create_entrywriteCreate a new entry in Contentful. Before executing this function, you need to know the contentTypeId (not the content type NAME) and the fields of that contentType. You can get the fields definition by using the GET_CONTENT_TYPE tool. IMPORTANT: All field values MUST include a locale key (e.g.,
create_environmentwriteCreate a new environment
delete_ai_actiondestructiveDelete an AI Action
delete_assetdestructiveDelete an asset
delete_commentdestructiveDelete a specific comment from an entry.
delete_content_typedestructiveDelete a content type
delete_entrydestructiveDelete an entry
delete_environmentdestructiveDelete an environment
detailsreadAdditional context or requirements
entityreadEntity type (space/environment)
entityTypereadType of entities to process (entries/assets)
entry-managementreadHelp with CRUD operations and publishing workflows for content entries
explain-api-conceptsreadExplain Contentful API concepts and relationships
get_ai_actionreadGet a specific AI Action by ID
get_ai_action_invocationreadGet the result of a previous AI Action invocation
get_assetreadRetrieve an asset
get_commentsreadRetrieve comments for an entry with pagination support. Returns comments with their status and body content.
get_content_typereadGet details of a specific content type
get_entryreadRetrieve an existing entry
get_single_commentreadRetrieve a specific comment by its ID for an entry.
get_spacereadGet details of a space
invoke_ai_actionwriteInvoke an AI Action with variables
list_ai_actionsreadList all AI Actions in a space
list_assetsreadList assets in a space. Returns a maximum of 3 items per request. Use skip parameter to paginate through results.
list_content_typesreadList content types in a space. Returns a maximum of 10 items per request. Use skip parameter to paginate through results.
list_environmentsreadList all environments in a space
list_spacesreadList all available spaces
mcp-tool-usagereadInstructions for using Contentful MCP tools effectively
modelTypereadAI model type (e.g., gpt-4, claude-3-opus)
operationreadOperation you want to perform
publish_ai_actionwritePublish an AI Action
publish_assetwritePublish an asset
publish_content_typewritePublish a content type
publish_entrywritePublish an entry or multiple entries. Accepts either a single entryId (string) or an array of entryIds (up to 100 entries). For a single entry, it uses the standard publish operation. For multiple entries, it automatically uses bulk publishing.
resourceTypereadType of resource (Entry/Asset/ContentType)
search_entriesreadSearch for entries using query parameters. Returns a maximum of 3 items per request. Use skip parameter to paginate through results.
space-environment-managementreadHelp with managing spaces, environments, and deployment workflows
space-identificationreadGuide for identifying the correct Contentful space for operations
taskdestructiveSpecific task (create/read/update/delete/publish/unpublish/bulk)
toolNamereadSpecific tool name (e.g., invoke_ai_action, create_entry)
unpublish_ai_actionreadUnpublish an AI Action
unpublish_assetreadUnpublish an asset
unpublish_entryreadUnpublish an entry or multiple entries. Accepts either a single entryId (string) or an array of entryIds (up to 100 entries). For a single entry, it uses the standard unpublish operation. For multiple entries, it automatically uses bulk unpublishing.
update_ai_actionwriteUpdate an existing AI Action
update_assetwriteUpdate an asset
update_commentwriteUpdate an existing comment on an entry. The handler will merge your updates with the existing comment data.
update_content_typewriteUpdate an existing content type. The handler will merge your field updates with existing content type data, so you only need to provide the fields and properties you want to change.
update_entrywriteUpdate an existing entry. The handler will merge your field updates with the existing entry fields, so you only need to provide the fields and locales you want to change. IMPORTANT: All field values MUST include a locale key (e.g.,
upload_assetwriteUpload a new asset
useCasereadDescription of the content modeling scenario
variableTypereadType of variable (Text, Reference, StandardInput, etc)
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (10)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
src/config/client.ts:30
return ["-----BEGIN RSA PRIVATE KEY-----", ...chunks, "-----END RSA PRIVATE KEY-----"].join(
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
test/integration/client.test.ts:66
"-----BEGIN RSA PRIVATE KEY-----\ntest-private-key\n-----END RSA PRIVATE KEY-----",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_ai_action, delete_asset, delete_comment, delete_content_type, delete_entry, delete_environment, task
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc
.releaserc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/integration/ai-action-handler.test.ts:2
import { aiActionHandlers } from "../../src/handlers/ai-action-handlers"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/integration/ai-action-handler.test.ts:3
import { aiActionsClient } from "../../src/config/ai-actions-client"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/integration/ai-action-handler.test.ts:6
vi.mock("../../src/config/ai-actions-client", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/integration/ai-actions-client.test.ts:4
vi.mock("../../src/config/client", () => {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/integration/ai-actions-client.test.ts:21
import { aiActionsClient } from "../../src/config/ai-actions-client"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@contentful/node-apps-toolkit, @modelcontextprotocol/sdk, contentful-management, cors, dotenv, express, zod, zod-to-json-schema
Why it matters. 37 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 23aa1abd7336full audit observations/trust-audit/mcp-server/ivo-toby__contentful-management.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0723aa1abd7336BLOCKD69first audit
06

Questions

What is the Contentful Management MCP server?

MCP (Model Context Protocol) server for the Contentful Management API

What tools does Contentful Management expose?

67 in total: 42 read-only, 18 that write, and 7 that can delete or overwrite (delete_ai_action, delete_asset, delete_comment, delete_content_type, delete_entry). Every one is listed on this page with its risk.

Is Contentful Management safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Contentful Management need?

It reads CONTENTFUL_MANAGEMENT_ACCESS_TOKEN and PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Contentful Management run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @ivotoby/contentful-management-mcp-server at 1.14.0.

How current is this page?

The grade is for one exact copy of the source (23aa1abd7336), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement