Lark OpenAPICAUTION
飞书/Lark官方 OpenAPI MCP
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@larksuiteoapi/lark-mcp) [](https://www.npmjs.com/package/@larksuiteoapi/lark-mcp) [](https://nodejs.org/)
English | 中文
Developer Documentation Retrieval MCP
⚠️ Beta Version Notice: This tool is currently in Beta stage. Features and APIs may change, so please stay updated with version releases.
This is the Feishu/Lark official OpenAPI MCP (Model Context Protocol) tool designed to help users quickly connect to the Feishu/Lark platform and enable efficient collaboration between AI Agents and Feishu/Lark. The tool encapsulates Feishu/Lark Open Platform API interfaces as MCP tools, allowing AI assistants to directly call these interfaces and implement various automation scenarios such as document processing, conversation management, calendar scheduling, and more.
Preparation
Creating a Feishu/Lark Application
Before using the lark-mcp tool, you need to create a Feishu/Lark application:
- Visit the Feishu Open Platform or Lark Open Platform and log in
- Click "Console" and create a new application
- Obtain the App ID and App Secret, which will be used for API authentication
- Add the necessary permissions for your application based on your usage scenario
- If you need to call APIs as a user, set the OAuth 2.0 redirect URL to http://localhost:3000/callback
For detailed application creation and configuration guidelines, please refer to the [Feishu Open Plat
dc92d0e5a0c5OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add lark-mcp --env APP_SECRET=${APP_SECRET} --env LARK_TOKEN_MODE=${LARK_TOKEN_MODE} --env USER_ACCESS_TOKEN=${USER_ACCESS_TOKEN} -- npx -y @larksuiteoapi/[email protected]{
"mcpServers": {
"lark-mcp": {
"command": "npx",
"args": [
"-y",
"@larksuiteoapi/[email protected]"
],
"env": {
"APP_SECRET": "${APP_SECRET}",
"LARK_TOKEN_MODE": "${LARK_TOKEN_MODE}",
"USER_ACCESS_TOKEN": "${USER_ACCESS_TOKEN}"
}
}
}
}Exposed tools (17)
15 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
RecallTool | read | RecallTool description |
async-tool | read | Async tool |
custom.handler.tool | read | 自定义处理程序工具 |
docx.v1.document.rawContent | read | 获取文档内容 |
im.v1.chat.create | write | 创建群 |
im.v1.message.create | write | 发送消息 |
im.v1.message.nonFunction | read | 测试非函数路径 |
image-tool | read | Image tool |
multi-tool | read | Multi tool |
openplatform_developer_document_recall | read | Recall for relevant documents in all of the Feishu/Lark Open Platform Developer Documents based on user input. |
refined-tool | read | Refined tool |
string-tool | read | String tool |
test-recall-tool | read | A test recall tool |
test.tool | read | 测试工具 |
text-tool | read | Text tool |
validation-tool | read | Validation tool |
wiki.v1.node.search | read | 搜索知识库节点 |
Trust audit
CAUTIONgrade C · trust 72/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
logger.error(`[LarkAuthHandler] refreshToken: No local access token found`);
logger.error(`[LarkAuthHandler] refreshToken: No refresh token found`);
logger.info(`[LarkAuthHandler] refreshToken: Successfully refreshed token`);
logger.error(`[LarkAuthHandler] reAuthorize: Invalid access token, please reconnect the mcp server`);
logger.error(`[LarkAuthHandler] reAuthorize: Invalid access token, please reconnect the mcp server`);
"Key:Value of the text. The key needs to start with @i18n@ and the value must be passed in according to the requirements of each parameter.**Description**: This field is mainly used for internationali
'The department ID type in this call. For a detailed description of department IDs, see [Department ID Description]. Options:department_id(DepartmentId Supports user-defined department ID. When custom
'Approval instance extension parameter, JSON format, needs to be compressed and escaped into a string when passing the value. The document number is realized by passing the business_key parameter.**No
'A readable view collection. This is only meaningful when view_perm is 1. If it is not set, all views are readable. If it is set, it means that only views in the collection are readable, and views out
'base role`base_complex_edit`: Set whether you can create copies, download, and print multidimensional tables`copy`: Set whether you can copy the contents of multidimensional tablesThe parameter type
.prettierignore
import { logger } from '../../utils/logger';import { logger } from '../../utils/logger';import { commonHttpInstance } from '../../utils/http-instance';import { logger } from '../../utils/logger';import { commonHttpInstance } from '../../utils/http-instance';@larksuiteoapi/node-sdk, @modelcontextprotocol/sdk, axios, commander, dotenv, env-paths, express, keytar
| `--user-access-token` | `-u` | User access token for calling APIs as a user | `-u u-xxxx` |
| drive.v1.permissionPublicPassword.create | [Open password](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/reference/drive-v1/permission-public-password/create) | This interface is used to ena
> 💡 **Tip**: The system will automatically read `APP_ID` and `APP_SECRET` environment variables, no need to specify them again in args.
| `USER_ACCESS_TOKEN` | `-u, --user-access-token` | User access token | `u-zzzzz` |
| admin.v1.password.reset | [Reset user enterprise email password](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/reference/admin-v1/password/reset) | Admin-Login password management-Reset user
| aily.v1.ailySessionAilyMessage.create | [Send aily message](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/aily-v1/aily_session-aily_message/create) | The API is used to send a message to a F
| aily.v1.ailySession.create | [Create session](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/aily-v1/aily_session/create) | This API is used to create a session with a Feishu smart partner ap
| hire.v1.ecoExam.loginInfo | [Post exam login info](https://open.feishu.cn/document/ukTMukTMukTM/uMzM1YjLzMTN24yMzUjN/hire-v1/eco_exam/login_info) | The written test service provider of Feishu Hire,
Gates applied: no_behavioural_pass.
dc92d0e5a0c5full audit observations/trust-audit/mcp-server/larksuite__lark-openapi.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | dc92d0e5a0c5 | CAUTION | C | 72 | first audit |
Questions
What is the Lark OpenAPI MCP server?
飞书/Lark官方 OpenAPI MCP
What tools does Lark OpenAPI expose?
17 in total: 15 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Lark OpenAPI safe to connect to an agent?
With care. The audit graded it C (72/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Lark OpenAPI need?
It reads APP_SECRET, LARK_TOKEN_MODE and USER_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Lark OpenAPI run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @larksuiteoapi/lark-mcp at 0.5.1.
How current is this page?
The grade is for one exact copy of the source (dc92d0e5a0c5), read on 2026-09-27. The repository is watched and re-audited when it changes.