Atlas / MCP servers / mapbox / Mapbox Developer

Mapbox DeveloperCAUTION

mcp/mapbox/mapbox-developer

Developer-focused Mapbox MCP Server

Verdict
CAUTION
Grade
C
Trust score
70 /100
Exposed tools
29 25r · 3w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
61
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides AI assistants with direct access to Mapbox developer APIs. This server enables AI models to interact with Mapbox services, helping developers build Mapbox applications more efficiently.

Looking for Mapbox documentation access? Use mcp-docs-server alongside this server — it provides AI assistants with access to Mapbox documentation, guides, and API references from docs.mapbox.com.

https://github.com/user-attachments/assets/8b1b8ef2-9fba-4951-bc9a-beaed4f6aff6

Table of Contents

  • Mapbox Developer MCP Server
  • Table of Contents
  • Quick Start
  • Integration with Developer Tools
  • DXT Package Distribution
  • Creating the DXT Package
  • Hosted MCP Endpoint
  • Getting Your Mapbox Access Token
  • Tools
  • Reference Tools
  • Style Management Tools
  • Token Management Tools
  • create-token
  • list-tokens
  • Feedback Tools
  • Local Processing Tools
  • GeoJSON Preview tool (Beta)
  • Coordinate Conversion tool
  • Bounding Box tool
  • comparestylestool
  • Style Optimization tool
  • Resources
  • Observability \& Tracing
  • Features
  • Quick Start with Jaeger
  • Supported Backends
  • Documentation
  • [Environment Varia
Read from source at commit b4db17a2f76cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-devkit-server --env MAPBOX_ACCESS_TOKEN=${MAPBOX_ACCESS_TOKEN} -- npx -y @mapbox/[email protected]
03

Exposed tools (29)

25 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
base_stylewriteOptional base style to start from. Defaults to
color_schemereadColor scheme:
convert_coordinatesreadWhether to provide coordinate conversion examples for Web Mercator (true/false, default: false)
create_style_toolwriteCreate style
data_descriptionreadDescription of the data (e.g.,
delete_style_tooldestructiveDelete style
emphasisreadOptional features to emphasize (e.g.,
environmentreadWhere the issue occurs:
error_messagereadExact error message from console or logs, if available
geojson_datareadGeoJSON object or string to analyze (Point, LineString, Polygon, Feature, FeatureCollection, etc.)
issue_descriptionreadDescription of the problem (e.g.,
list_styles_toolreadList styles
preview_locationreadOptional location to center the preview map (e.g.,
preview_style_toolreadPreview style
preview_zoomreadOptional zoom level for the preview (0-22, default: 12)
production_domainreadProduction domain for URL restrictions (e.g.,
project_namereadName of the project or application
project_typereadType of project:
property_namereadName of the data property to visualize (e.g.,
show_boundsreadWhether to calculate and display the bounding box (true/false, default: true)
skip_optimizationwriteSet to
style_descriptionreadOptional description of the style theme or purpose
style_idreadMapbox style ID being used, if applicable
style_id_or_jsonreadEither a Mapbox style ID (e.g.,
style_namereadName for the new map style
style_themereadInitial style theme:
themereadTheme description for the map (e.g.,
visualization_typereadHow to visualize:
wcag_levelreadWCAG compliance level to check:
04

Trust audit

CAUTIONgrade C · trust 70/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (1 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (21)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/tools/create-token-tool/CreateTokenTool.test.ts:146
token: 'pk.eyJ1IjoidGVzdHVzZXIiLCJhIjoiY2xwMTIzNDU2In0.test',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/tools/create-token-tool/CreateTokenTool.test.ts:201
token: 'pk.eyJ1IjoidGVzdHVzZXIiLCJhIjoiY2xwMTIzNDU2In0.test',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/tools/create-token-tool/CreateTokenTool.test.ts:242
token: 'pk.eyJ1IjoidGVzdHVzZXIiLCJhIjoiY2xwMTIzNDU2In0.test',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/tools/list-tokens-tool/ListTokensTool.test.ts:135
token: 'pk.eyJ1IjoidGVzdHVzZXIifQ.test123',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
test/tools/list-tokens-tool/ListTokensTool.test.ts:146
token: 'sk.eyJ1IjoidGVzdHVzZXIifQ.test456',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_style_tool
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cz.json
.cz.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/tools/geojson-preview-tool/GeojsonPreviewTool.ts:101
const contentHash = createHash('md5')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/mapbox-streets-v8-fields-resource/MapboxStreetsV8FieldsResource.ts:5
import { STREETS_V8_FIELDS } from '../../constants/mapboxStreetsV8Fields.trimmed.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/ui-apps/MapPreviewUIResource.ts:12
import { mintScopedPreviewToken } from '../../utils/mintScopedPreviewToken.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/create-style-tool/CreateStyleTool.output.schema.ts:5
import { BaseStylePropertiesSchema } from '../../schemas/style.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/create-style-tool/CreateStyleTool.ts:5
import type { HttpRequest } from '../../utils/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/create-style-tool/CreateStyleTool.ts:6
import type { ToolExecutionContext } from '../../utils/tracing.js';
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
test/tools/list-tokens-tool/ListTokensTool.test.ts:430
it('refuses cross-origin Link header to prevent token exfiltration', async () => {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@mapbox/mapbox-gl-style-spec, @mcp-ui/server, @modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, @opentelemetry/api, @opentelemetry/auto-instrumentations-node, @opentelemetry/exporter-trace-ot
Why it matters. 35 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:317
- **Both feedback tools**: Require `user-feedback:read` scope on the access token
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
TOOL_CONFIGURATION.md:125
- All tools require a valid Mapbox access token set in the `MAPBOX_ACCESS_TOKEN` environment variable
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/tracing.md:372
- **Access tokens**: Mapbox APIs take the access token as a URL query parameter, and HTTP
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:93
- **Reject cross-origin Link headers** (#103) — Pagination `next-page` URLs from `Link` response headers are now validated to share the same origin as the configured API endpoint; cross-origin URLs ar
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
assets/mcp_server_devkit.gif
assets/mcp_server_devkit.gif
Why it matters. 1615896 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b4db17a2f76cfull audit observations/trust-audit/mcp-server/mapbox__mapbox-developer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b4db17a2f76cCAUTIONC70first audit
06

Questions

What is the Mapbox Developer MCP server?

Developer-focused Mapbox MCP Server

What tools does Mapbox Developer expose?

29 in total: 25 read-only, 3 that write, and 1 that can delete or overwrite (delete_style_tool). Every one is listed on this page with its risk.

Is Mapbox Developer safe to connect to an agent?

With care. The audit graded it C (70/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mapbox Developer need?

It reads MAPBOX_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mapbox Developer run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-package at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (b4db17a2f76c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement