MapboxCAUTION
Mapbox Model Context Protocol (MCP) server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@mapbox/mcp-server)
Node.js server implementing Model Context Protocol (MCP) for Mapbox APIs.
Unlock Geospatial Intelligence for Your AI Applications
The Mapbox MCP Server transforms any AI agent or application into a geospatially-aware system by providing seamless access to Mapbox's comprehensive location intelligence platform. With this server, your AI can understand and reason about places, navigate the physical world, and access rich geospatial data including:
- Global geocoding to convert addresses and place names to coordinates and vice versa
- Points of interest (POI) search across millions of businesses, landmarks, and places worldwide
- Multi-modal routing for driving, walking, and cycling with real-time traffic
- Travel time matrices to analyze accessibility and optimize logistics
- Route optimization to find the optimal visiting order for multiple stops (traveling salesman problem)
- Map matching to snap GPS traces to the road network for clean route visualization
- Isochrone generation to visualize areas reachable within specific time or distance constraints
- Live, interactive map rendering (
render_map_tool) to display routes, search results, and your own custom GeoJSON on a real Mapbox GL JS map directly inside the chat - Static map images to create visual representations of locations, routes, and geographic data
- Offline geospatial calculations for distance, area, bearing, buffers, and spatial analysis without requiring API calls
Whether you're building an AI travel assistant, logistics optimizer, location-based recommender, or any application that needs to understand "where", the Mapbox MCP Server provides the spatial intelligence to make it possible. You can also enable it on popular clients like Claude Desktop and VS Code. See below for details

18 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
arg1 | read | First |
arg2 | read | Second |
arg3 | read | Third |
buffer_meters | read | Search corridor width on each side of route in meters (default: 1000) |
category | read | Type of place to search for (e.g., |
directions_tool | read | Directions tool |
from | read | Starting location (address, place name, or coordinates) |
location | read | The location to search near (address, place name, or coordinates) |
matrix_tool | read | Matrix tool |
mode | read | Travel mode: driving, driving-traffic, walking, or cycling (default: driving) |
optional_arg | read | An optional argument |
radius | read | Search radius in meters (default: 1000) |
required_arg | read | A required argument |
search_for | read | Type of place to search for (e.g., |
static_map_image_tool | read | Static map tool |
time_minutes | read | Travel time in minutes (default: 15) |
to | read | Destination location (address, place name, or coordinates) |
version_tool | read | Version tool |
Trust audit
CAUTIONgrade C · trust 78/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
src: 'data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4KPCEtLSBHZW5lcmF0b3I6IEFkb2JlIElsbHVzdHJhdG9yIDIxLjAuMiwgU1ZHIEV4cG9ydCBQbHVnLUluIC4gU1ZHIFZlcnNpb246IDYuMDAgQnVpbGQg
src: 'data:image/svg+xml;base64,PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4KPCEtLSBHZW5lcmF0b3I6IEFkb2JlIElsbHVzdHJhdG9yIDIxLjAuMiwgU1ZHIEV4cG9ydCBQbHVnLUluIC4gU1ZHIFZlcnNpb246IDYuMDAgQnVpbGQg
token: 'pk.eyJ1IjoidGVzdHVzZXIifQ.fake-public-token',
const SECRET = 'sk.eyJ1IjoidGVzdHVzZXIifQ.signaturevalue';
.cz.json
import type { HttpRequest } from '../../utils/types.js';import { resolveComputeRef } from '../../utils/computeRef.js';import { resolveInlinePayloadRef } from '../../utils/inlinePayloadRef.js';import { temporaryResourceManager } from '../../utils/temporaryResourceManager.js';import { getUserNameFromToken } from '../../utils/jwtUtils.js';'https://169.254.169.254/latest/meta-data/', // cloud metadata
url: 'https://169.254.169.254/latest/meta-data/'
url: 'https://example.com\\@169.254.169.254/marker.png'
'https://example.com/@169.254.169.254/marker.png'
const rawUrl = 'https://example.com\\@169.254.169.254/marker.png';
'https://127.0.0.1/marker.png',
'https://10.0.0.5/marker.png',
'https://192.168.1.1/marker.png',
'https://169.254.169.254/latest/meta-data/', // cloud metadata
url: 'https://169.254.169.254/latest/meta-data/'
smolagents
@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, @opentelemetry/api, @opentelemetry/auto-instrumentations-node, @opentelemetry/exporter-trace-otlp-http, @opentelemetry/instrumentation, @open
For programmatic access, use your Mapbox access token directly in API calls (see Section 4).
- **Access tokens**: Mapbox APIs take the access token as a URL query parameter, and HTTP
- A Mapbox access token (set as an environment variable)
Gates applied: no_behavioural_pass.
2be750d3a5e0full audit observations/trust-audit/mcp-server/mapbox__mapbox-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 2be750d3a5e0 | CAUTION | C | 78 | first audit |
Questions
What is the Mapbox MCP server?
Mapbox Model Context Protocol (MCP) server
What tools does Mapbox expose?
18 in total: 18 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mapbox safe to connect to an agent?
With care. The audit graded it C (78/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Mapbox need?
It reads MAPBOX_ACCESS_TOKEN and MAPBOX_PUBLIC_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mapbox run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-package at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (2be750d3a5e0), read on 2026-10-02. The repository is watched and re-audited when it changes.