Atlas / MCP servers / k-jarzyna / Miro

MiroSAFE

mcp/k-jarzyna/miro

Miro integration for Model Context Protocol

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
97 43r · 37w · 17d
Transport
stdio
License
Apache-2.0
Stars
66
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://archestra.ai/mcp-catalog/k-jarzyna__mcp-miro) [](https://smithery.ai/server/@k-jarzyna/mcp-miro)

Model Context Protocol (MCP) server integrating with the Miro platform. It enables AI assistants (like Claude) to access Miro boards and manage their content through a standardized interface.

Requirements

  • Node.js v16 or newer installed
  • Miro account with API token

Generate Miro Access Token

  1. Go to the Miro Developer Portal
  2. Create a new app or use an existing one
  3. Make sure to create token with permission selected below
  4. Generate OAuth token by selecting Install app and get OAuth token

Connecting with Claude Desktop

  1. Install Claude Desktop
  2. Open or create the configuration file:
  3. macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  4. Windows: %APPDATA%\Claude\claude_desktop_config.json
  1. Update it to include this server:
{
"mcpServers":{
"miro":{
"command":"npx",
"args":[
"-y",
"@k-jarzyna/mcp-miro"
],
"env":{
"MIRO_ACCESS_TOKEN":"your_miro_access_token"
}
}
}
}
  1. Restart Claude Desktop

Available Tools and Resources

Tools

Read from source at commit 5d20db981b17OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-miro --env MIRO_ACCESS_TOKEN=${MIRO_ACCESS_TOKEN} -- npx -y @k-jarzyna/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-miro": {
      "command": "npx",
      "args": [
        "-y",
        "@k-jarzyna/[email protected]"
      ],
      "env": {
        "MIRO_ACCESS_TOKEN": "${MIRO_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (97)

43 read · 37 write · 17 destructive. Blast radius: 17 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add-project-memberwriteAdds a member to a project (Enterprise only)
attach-tagreadAttach a tag to an item on a Miro board
copy-boardwriteCreate a copy of an existing Miro board with optional new settings
create-app-card-itemwriteCreate a new app card item on a Miro board
create-boardwriteCreate a new Miro board with specified name and sharing policies
create-board-export-jobwriteCreates an export job for one or more boards (Enterprise only)
create-card-itemwriteCreate a new card item on a Miro board
create-connectorwriteCreate a new connector between items on a Miro board
create-document-itemwriteCreate a new document item on a Miro board
create-embed-itemwriteCreate a new embed item on a Miro board
create-framewriteCreate a new frame on a Miro board
create-groupwriteCreate a new group on a Miro board
create-image-item-using-filewriteCreate a new image item on a Miro board using file from device or from chat
create-image-item-using-urlwriteCreate a new image item on a Miro board using a URL
create-items-in-bulkwriteCreate multiple items on a Miro board in a single operation
create-items-in-bulk-using-filewriteCreate multiple items on a Miro board in a single operation using a JSON file from device
create-mindmap-nodewriteCreate a new mind map node on a Miro board
create-shape-itemwriteCreate a new shape item on a Miro board
create-sticky-note-itemwriteCreate a new sticky note item on a Miro board
create-tagwriteCreate a new tag on a Miro board
create-text-itemwriteCreate a new text item on a Miro board
delete-app-card-itemdestructiveDelete a specific app card item from a Miro board
delete-boarddestructiveDelete a Miro board by its ID. Deleted boards go to Trash (on paid plans) and can be restored via UI within 90 days after deletion.
delete-card-itemdestructiveDelete a specific card item from a Miro board
delete-connectordestructiveDelete a specific connector from a Miro board
delete-document-itemdestructiveDelete a specific document item from a Miro board
delete-embed-itemdestructiveDelete a specific embed item from a Miro board
delete-frame-itemdestructiveDelete a frame from a Miro board
delete-groupdestructiveDelete a specific group from a Miro board
delete-image-itemdestructiveDelete a specific image item from a Miro board
delete-itemdestructiveDelete a specific item from a Miro board
delete-mindmap-nodedestructiveDelete a mind map node from a Miro board
delete-shape-itemdestructiveDelete a specific shape item from a Miro board
delete-sticky-note-itemdestructiveDelete a specific sticky note item from a Miro board
delete-tagdestructiveDelete a specific tag from a Miro board
delete-text-itemdestructiveDelete a specific text item from a Miro board
detach-tagreadDetach a tag from an item on a Miro board
get-all-board-membersreadRetrieve all members of a specific Miro board
get-all-casesreadRetrieves the list of eDiscovery cases in an organization (Enterprise only)
get-all-groupsreadRetrieve all groups on a Miro board
get-all-legal-holdsreadRetrieves the list of all legal holds within a case (Enterprise only)
get-all-tagsreadRetrieve all tags on a Miro board
get-app-card-itemreadRetrieve information about a specific app card item on a Miro board
get-audit-logsreadRetrieves a page of audit events from the last 90 days (Enterprise only)
get-board-classificationreadRetrieves board classification for a board (Enterprise only)
get-board-content-logsreadRetrieves content change logs of board items (Enterprise only)
get-board-export-job-resultsreadRetrieves the results of a board export job (Enterprise only)
get-board-export-job-statusreadRetrieves the status of a board export job (Enterprise only)
get-card-itemreadRetrieve information about a specific card item on a Miro board
get-casereadRetrieves information about a specific eDiscovery case (Enterprise only)
get-connectorsreadRetrieve all connectors on a specific Miro board
get-document-itemreadRetrieve information about a specific document item on a Miro board
get-embed-itemreadRetrieve information about a specific embed item on a Miro board
get-frame-itemreadRetrieve information for a specific frame on a Miro board
get-groupreadRetrieve information about a specific group on a Miro board
get-group-itemsreadRetrieve all items in a specific group on a Miro board
get-image-itemreadRetrieve information about a specific image item on a Miro board
get-item-tagsreadRetrieve all tags attached to a specific item on a Miro board
get-items-on-boardreadRetrieve all items on a specific Miro board
get-legal-holdreadRetrieves information about a specific legal hold (Enterprise only)
get-legal-hold-content-itemsreadRetrieves the list of content items under legal hold (Enterprise only)
get-mindmap-nodereadRetrieve information about a specific mind map node on a Miro board
get-mindmap-nodesreadRetrieve a list of mind map nodes on a Miro board
get-organization-inforeadRetrieves organization information (Enterprise only)
get-organization-memberreadRetrieves information about a specific organization member (Enterprise only)
get-organization-membersreadRetrieves a list of members for an organization (Enterprise only)
get-project-memberreadRetrieves information about a specific project member (Enterprise only)
get-shape-itemreadRetrieve information about a specific shape item on a Miro board
get-specific-boardreadRetrieve information about a specific Miro board by its ID
get-specific-board-memberreadRetrieve details of a specific member on a Miro board
get-specific-connectorreadRetrieve information about a specific connector on a Miro board
get-specific-itemreadRetrieve information about a specific item on a Miro board
get-sticky-note-itemreadRetrieve information about a specific sticky note item on a Miro board
get-tagreadRetrieve information about a specific tag on a Miro board
get-text-itemreadRetrieve information about a specific text item on a Miro board
list-boardsreadList all available Miro boards
remove-board-memberdestructiveRemove a specific member from a Miro board
remove-project-memberdestructiveRemoves a member from a project (Enterprise only)
share-boardreadShare a Miro board with specific access level and optional team assignment
ungroup-itemsreadUngroup a specific group on a Miro board
update-app-card-itemwriteUpdate an existing app card item on a Miro board
update-boardwriteUpdate an existing Miro board with new settings
update-board-classificationwriteUpdates board classification for an existing board (Enterprise only)
update-board-memberwriteUpdate a specific member
update-card-itemwriteUpdate an existing card item on a Miro board
update-connectorwriteUpdate an existing connector on a Miro board
update-document-itemwriteUpdate an existing document item on a Miro board
update-embed-itemwriteUpdate an existing embed item on a Miro board
update-frame-itemwriteUpdate a frame on a Miro board based on the data, style, or geometry properties provided in the request body
update-groupwriteUpdate a specific group on a Miro board with new items
update-image-itemwriteUpdate an existing image item on a Miro board
update-image-item-using-filewriteUpdate an existing image item on a Miro board using file from device
update-item-positionwriteUpdate the position or parent of a specific item on a Miro board
update-shape-itemwriteUpdate an existing shape item on a Miro board
update-sticky-note-itemwriteUpdate an existing sticky note item on a Miro board
update-tagwriteUpdate an existing tag on a Miro board
update-text-itemwriteUpdate an existing text item on a Miro board
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-app-card-item, delete-board, delete-card-item, delete-connector, delete-document-item, delete-embed-item, delete-frame-item, delete-group, delete-image-item, delete-item, delete-mindmap-node, d
Why it matters. 17 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@mirohq/miro-api, @modelcontextprotocol/sdk, dotenv, zod, @types/node, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 5d20db981b17full audit observations/trust-audit/mcp-server/k-jarzyna__miro.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-075d20db981b17SAFEB89first audit
06

Questions

What is the Miro MCP server?

Miro integration for Model Context Protocol

What tools does Miro expose?

97 in total: 43 read-only, 37 that write, and 17 that can delete or overwrite (delete-app-card-item, delete-board, delete-card-item, delete-connector, delete-document-item). Every one is listed on this page with its risk.

Is Miro safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 17 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Miro need?

It reads MIRO_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Miro run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @k-jarzyna/mcp-miro at 1.0.11.

How current is this page?

The grade is for one exact copy of the source (5d20db981b17), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement