Mapbox DeveloperCAUTION
Developer-focused Mapbox MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides AI assistants with direct access to Mapbox developer APIs. This server enables AI models to interact with Mapbox services, helping developers build Mapbox applications more efficiently.
Looking for Mapbox documentation access? Use mcp-docs-server alongside this server — it provides AI assistants with access to Mapbox documentation, guides, and API references from docs.mapbox.com.
https://github.com/user-attachments/assets/8b1b8ef2-9fba-4951-bc9a-beaed4f6aff6
Table of Contents
- Mapbox Developer MCP Server
- Table of Contents
- Quick Start
- Integration with Developer Tools
- DXT Package Distribution
- Creating the DXT Package
- Hosted MCP Endpoint
- Getting Your Mapbox Access Token
- Tools
- Reference Tools
- Style Management Tools
- Token Management Tools
- create-token
- list-tokens
- Feedback Tools
- Local Processing Tools
- GeoJSON Preview tool (Beta)
- Coordinate Conversion tool
- Bounding Box tool
- comparestylestool
- Style Optimization tool
- Resources
- Observability \& Tracing
- Features
- Quick Start with Jaeger
- Supported Backends
- Documentation
- [Environment Varia
b4db17a2f76cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-devkit-server --env MAPBOX_ACCESS_TOKEN=${MAPBOX_ACCESS_TOKEN} -- npx -y @mapbox/[email protected]Exposed tools (29)
25 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
base_style | write | Optional base style to start from. Defaults to |
color_scheme | read | Color scheme: |
convert_coordinates | read | Whether to provide coordinate conversion examples for Web Mercator (true/false, default: false) |
create_style_tool | write | Create style |
data_description | read | Description of the data (e.g., |
delete_style_tool | destructive | Delete style |
emphasis | read | Optional features to emphasize (e.g., |
environment | read | Where the issue occurs: |
error_message | read | Exact error message from console or logs, if available |
geojson_data | read | GeoJSON object or string to analyze (Point, LineString, Polygon, Feature, FeatureCollection, etc.) |
issue_description | read | Description of the problem (e.g., |
list_styles_tool | read | List styles |
preview_location | read | Optional location to center the preview map (e.g., |
preview_style_tool | read | Preview style |
preview_zoom | read | Optional zoom level for the preview (0-22, default: 12) |
production_domain | read | Production domain for URL restrictions (e.g., |
project_name | read | Name of the project or application |
project_type | read | Type of project: |
property_name | read | Name of the data property to visualize (e.g., |
show_bounds | read | Whether to calculate and display the bounding box (true/false, default: true) |
skip_optimization | write | Set to |
style_description | read | Optional description of the style theme or purpose |
style_id | read | Mapbox style ID being used, if applicable |
style_id_or_json | read | Either a Mapbox style ID (e.g., |
style_name | read | Name for the new map style |
style_theme | read | Initial style theme: |
theme | read | Theme description for the map (e.g., |
visualization_type | read | How to visualize: |
wcag_level | read | WCAG compliance level to check: |
Trust audit
CAUTIONgrade C · trust 70/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (21)
token: 'pk.eyJ1IjoidGVzdHVzZXIiLCJhIjoiY2xwMTIzNDU2In0.test',
token: 'pk.eyJ1IjoidGVzdHVzZXIiLCJhIjoiY2xwMTIzNDU2In0.test',
token: 'pk.eyJ1IjoidGVzdHVzZXIiLCJhIjoiY2xwMTIzNDU2In0.test',
token: 'pk.eyJ1IjoidGVzdHVzZXIifQ.test123',
token: 'sk.eyJ1IjoidGVzdHVzZXIifQ.test456',
delete_style_tool
.cz.json
.prettierignore
const contentHash = createHash('md5')import { STREETS_V8_FIELDS } from '../../constants/mapboxStreetsV8Fields.trimmed.js';import { mintScopedPreviewToken } from '../../utils/mintScopedPreviewToken.js';import { BaseStylePropertiesSchema } from '../../schemas/style.js';import type { HttpRequest } from '../../utils/types.js';import type { ToolExecutionContext } from '../../utils/tracing.js';it('refuses cross-origin Link header to prevent token exfiltration', async () => {@mapbox/mapbox-gl-style-spec, @mcp-ui/server, @modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, @opentelemetry/api, @opentelemetry/auto-instrumentations-node, @opentelemetry/exporter-trace-ot
- **Both feedback tools**: Require `user-feedback:read` scope on the access token
- All tools require a valid Mapbox access token set in the `MAPBOX_ACCESS_TOKEN` environment variable
- **Access tokens**: Mapbox APIs take the access token as a URL query parameter, and HTTP
- **Reject cross-origin Link headers** (#103) — Pagination `next-page` URLs from `Link` response headers are now validated to share the same origin as the configured API endpoint; cross-origin URLs ar
assets/mcp_server_devkit.gif
Gates applied: no_behavioural_pass.
b4db17a2f76cfull audit observations/trust-audit/mcp-server/mapbox__mapbox-developer.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b4db17a2f76c | CAUTION | C | 70 | first audit |
Questions
What is the Mapbox Developer MCP server?
Developer-focused Mapbox MCP Server
What tools does Mapbox Developer expose?
29 in total: 25 read-only, 3 that write, and 1 that can delete or overwrite (delete_style_tool). Every one is listed on this page with its risk.
Is Mapbox Developer safe to connect to an agent?
With care. The audit graded it C (70/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Mapbox Developer need?
It reads MAPBOX_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mapbox Developer run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-package at 2.0.0.
How current is this page?
The grade is for one exact copy of the source (b4db17a2f76c), read on 2026-10-07. The repository is watched and re-audited when it changes.