MiroSAFE
Miro integration for Model Context Protocol
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://archestra.ai/mcp-catalog/k-jarzyna__mcp-miro) [](https://smithery.ai/server/@k-jarzyna/mcp-miro)
Model Context Protocol (MCP) server integrating with the Miro platform. It enables AI assistants (like Claude) to access Miro boards and manage their content through a standardized interface.
Requirements
- Node.js v16 or newer installed
- Miro account with API token
Generate Miro Access Token
- Go to the Miro Developer Portal
- Create a new app or use an existing one
- Make sure to create token with permission selected below
- Generate OAuth token by selecting
Install app and get OAuth token
Connecting with Claude Desktop
- Install Claude Desktop
- Open or create the configuration file:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
- Update it to include this server:
{
"mcpServers":{
"miro":{
"command":"npx",
"args":[
"-y",
"@k-jarzyna/mcp-miro"
],
"env":{
"MIRO_ACCESS_TOKEN":"your_miro_access_token"
}
}
}
}- Restart Claude Desktop
Available Tools and Resources
Tools
5d20db981b17OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-miro --env MIRO_ACCESS_TOKEN=${MIRO_ACCESS_TOKEN} -- npx -y @k-jarzyna/[email protected]{
"mcpServers": {
"mcp-miro": {
"command": "npx",
"args": [
"-y",
"@k-jarzyna/[email protected]"
],
"env": {
"MIRO_ACCESS_TOKEN": "${MIRO_ACCESS_TOKEN}"
}
}
}
}Exposed tools (97)
43 read · 37 write · 17 destructive. Blast radius: 17 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add-project-member | write | Adds a member to a project (Enterprise only) |
attach-tag | read | Attach a tag to an item on a Miro board |
copy-board | write | Create a copy of an existing Miro board with optional new settings |
create-app-card-item | write | Create a new app card item on a Miro board |
create-board | write | Create a new Miro board with specified name and sharing policies |
create-board-export-job | write | Creates an export job for one or more boards (Enterprise only) |
create-card-item | write | Create a new card item on a Miro board |
create-connector | write | Create a new connector between items on a Miro board |
create-document-item | write | Create a new document item on a Miro board |
create-embed-item | write | Create a new embed item on a Miro board |
create-frame | write | Create a new frame on a Miro board |
create-group | write | Create a new group on a Miro board |
create-image-item-using-file | write | Create a new image item on a Miro board using file from device or from chat |
create-image-item-using-url | write | Create a new image item on a Miro board using a URL |
create-items-in-bulk | write | Create multiple items on a Miro board in a single operation |
create-items-in-bulk-using-file | write | Create multiple items on a Miro board in a single operation using a JSON file from device |
create-mindmap-node | write | Create a new mind map node on a Miro board |
create-shape-item | write | Create a new shape item on a Miro board |
create-sticky-note-item | write | Create a new sticky note item on a Miro board |
create-tag | write | Create a new tag on a Miro board |
create-text-item | write | Create a new text item on a Miro board |
delete-app-card-item | destructive | Delete a specific app card item from a Miro board |
delete-board | destructive | Delete a Miro board by its ID. Deleted boards go to Trash (on paid plans) and can be restored via UI within 90 days after deletion. |
delete-card-item | destructive | Delete a specific card item from a Miro board |
delete-connector | destructive | Delete a specific connector from a Miro board |
delete-document-item | destructive | Delete a specific document item from a Miro board |
delete-embed-item | destructive | Delete a specific embed item from a Miro board |
delete-frame-item | destructive | Delete a frame from a Miro board |
delete-group | destructive | Delete a specific group from a Miro board |
delete-image-item | destructive | Delete a specific image item from a Miro board |
delete-item | destructive | Delete a specific item from a Miro board |
delete-mindmap-node | destructive | Delete a mind map node from a Miro board |
delete-shape-item | destructive | Delete a specific shape item from a Miro board |
delete-sticky-note-item | destructive | Delete a specific sticky note item from a Miro board |
delete-tag | destructive | Delete a specific tag from a Miro board |
delete-text-item | destructive | Delete a specific text item from a Miro board |
detach-tag | read | Detach a tag from an item on a Miro board |
get-all-board-members | read | Retrieve all members of a specific Miro board |
get-all-cases | read | Retrieves the list of eDiscovery cases in an organization (Enterprise only) |
get-all-groups | read | Retrieve all groups on a Miro board |
get-all-legal-holds | read | Retrieves the list of all legal holds within a case (Enterprise only) |
get-all-tags | read | Retrieve all tags on a Miro board |
get-app-card-item | read | Retrieve information about a specific app card item on a Miro board |
get-audit-logs | read | Retrieves a page of audit events from the last 90 days (Enterprise only) |
get-board-classification | read | Retrieves board classification for a board (Enterprise only) |
get-board-content-logs | read | Retrieves content change logs of board items (Enterprise only) |
get-board-export-job-results | read | Retrieves the results of a board export job (Enterprise only) |
get-board-export-job-status | read | Retrieves the status of a board export job (Enterprise only) |
get-card-item | read | Retrieve information about a specific card item on a Miro board |
get-case | read | Retrieves information about a specific eDiscovery case (Enterprise only) |
get-connectors | read | Retrieve all connectors on a specific Miro board |
get-document-item | read | Retrieve information about a specific document item on a Miro board |
get-embed-item | read | Retrieve information about a specific embed item on a Miro board |
get-frame-item | read | Retrieve information for a specific frame on a Miro board |
get-group | read | Retrieve information about a specific group on a Miro board |
get-group-items | read | Retrieve all items in a specific group on a Miro board |
get-image-item | read | Retrieve information about a specific image item on a Miro board |
get-item-tags | read | Retrieve all tags attached to a specific item on a Miro board |
get-items-on-board | read | Retrieve all items on a specific Miro board |
get-legal-hold | read | Retrieves information about a specific legal hold (Enterprise only) |
get-legal-hold-content-items | read | Retrieves the list of content items under legal hold (Enterprise only) |
get-mindmap-node | read | Retrieve information about a specific mind map node on a Miro board |
get-mindmap-nodes | read | Retrieve a list of mind map nodes on a Miro board |
get-organization-info | read | Retrieves organization information (Enterprise only) |
get-organization-member | read | Retrieves information about a specific organization member (Enterprise only) |
get-organization-members | read | Retrieves a list of members for an organization (Enterprise only) |
get-project-member | read | Retrieves information about a specific project member (Enterprise only) |
get-shape-item | read | Retrieve information about a specific shape item on a Miro board |
get-specific-board | read | Retrieve information about a specific Miro board by its ID |
get-specific-board-member | read | Retrieve details of a specific member on a Miro board |
get-specific-connector | read | Retrieve information about a specific connector on a Miro board |
get-specific-item | read | Retrieve information about a specific item on a Miro board |
get-sticky-note-item | read | Retrieve information about a specific sticky note item on a Miro board |
get-tag | read | Retrieve information about a specific tag on a Miro board |
get-text-item | read | Retrieve information about a specific text item on a Miro board |
list-boards | read | List all available Miro boards |
remove-board-member | destructive | Remove a specific member from a Miro board |
remove-project-member | destructive | Removes a member from a project (Enterprise only) |
share-board | read | Share a Miro board with specific access level and optional team assignment |
ungroup-items | read | Ungroup a specific group on a Miro board |
update-app-card-item | write | Update an existing app card item on a Miro board |
update-board | write | Update an existing Miro board with new settings |
update-board-classification | write | Updates board classification for an existing board (Enterprise only) |
update-board-member | write | Update a specific member |
update-card-item | write | Update an existing card item on a Miro board |
update-connector | write | Update an existing connector on a Miro board |
update-document-item | write | Update an existing document item on a Miro board |
update-embed-item | write | Update an existing embed item on a Miro board |
update-frame-item | write | Update a frame on a Miro board based on the data, style, or geometry properties provided in the request body |
update-group | write | Update a specific group on a Miro board with new items |
update-image-item | write | Update an existing image item on a Miro board |
update-image-item-using-file | write | Update an existing image item on a Miro board using file from device |
update-item-position | write | Update the position or parent of a specific item on a Miro board |
update-shape-item | write | Update an existing shape item on a Miro board |
update-sticky-note-item | write | Update an existing sticky note item on a Miro board |
update-tag | write | Update an existing tag on a Miro board |
update-text-item | write | Update an existing text item on a Miro board |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
delete-app-card-item, delete-board, delete-card-item, delete-connector, delete-document-item, delete-embed-item, delete-frame-item, delete-group, delete-image-item, delete-item, delete-mindmap-node, d
.env.template
@mirohq/miro-api, @modelcontextprotocol/sdk, dotenv, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
5d20db981b17full audit observations/trust-audit/mcp-server/k-jarzyna__miro.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 5d20db981b17 | SAFE | B | 89 | first audit |
Questions
What is the Miro MCP server?
Miro integration for Model Context Protocol
What tools does Miro expose?
97 in total: 43 read-only, 37 that write, and 17 that can delete or overwrite (delete-app-card-item, delete-board, delete-card-item, delete-connector, delete-document-item). Every one is listed on this page with its risk.
Is Miro safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 17 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Miro need?
It reads MIRO_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Miro run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @k-jarzyna/mcp-miro at 1.0.11.
How current is this page?
The grade is for one exact copy of the source (5d20db981b17), read on 2026-10-07. The repository is watched and re-audited when it changes.