Atlas / MCP servers / marcelmarais / Spotify

SpotifyCAUTION

mcp/marcelmarais/spotify-5

Lightweight MCP server for Spotify

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
30 21r · 5w · 4d
Transport
streamable-http
License
—
Stars
468
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Spotify MCP Server

A lightweight Model Context Protocol (MCP) server that enables AI assistants like Cursor & Claude to control Spotify playback and manage playlists.

Contents

  • Example Interactions
  • Tools
  • Read Operations
  • Album Operations
  • Play / Create Operations
  • Playlist Operations
  • Setup
  • Prerequisites
  • Installation
  • Creating a Spotify Developer Application
  • Spotify API Configuration
  • Authentication Process
  • Integrating with Claude Desktop, Cursor, and VsCode (Cline)

Example Interactions

  • "Play Elvis's first song"
  • "Create a Taylor Swift / Slipknot fusion playlist"
  • "Copy all the techno tracks from my workout playlist to my work playlist"
  • "Turn the volume down a bit"

Tools

Read Operations

  1. searchSpotify
  • Description: Search for tracks, albums, artists, or playlists on Spotify
  • Parameters:
  • query (string): The search term
  • type (string): Type of item to search for (track, album, artist, playlist)
  • limit (number, optional): Maximum number of results to return (1-10, default: 10)
  • offset (number, optional): Index of the first result to return (default: 0)
  • Returns: List of matching items with their IDs, names, and additional details
  • Example: searchSpotify("bohemian rhapsody", "track", 10)
  1. getNowPlaying
  • **Descri
Read from source at commit 41e64b1dc363OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add spotify-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "spotify-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (30)

21 read · 5 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addToQueuereadAdds a track, album, artist or playlist to the playback queue
addTracksToPlaylistwriteAdd tracks or podcast episodes to a Spotify playlist.
adjustVolumereadAdjust the playback volume up or down by a relative amount. Use positive values to increase, negative to decrease. Requires Spotify Premium.
checkUsersSavedAlbumsreadCheck if albums are saved in the user\
createPlaylistwriteCreate a new playlist on Spotify
getAlbumTracksreadGet tracks from a specific album with pagination support
getAlbumsreadGet detailed information about one or more albums by their Spotify IDs
getAvailableDevicesreadGet information about the user
getMyPlaylistsreadGet a list of the current user
getNowPlayingreadGet information about the currently playing track on Spotify, including device and volume info
getPlaylistreadGet details of a specific Spotify playlist including tracks count, description and owner
getPlaylistTracksreadGet a list of tracks in a Spotify playlist
getQueuereadGet a list of the currently playing track and the next items in your Spotify queue
getRecentlyPlayedreadGet a list of recently played tracks on Spotify
getTopArtistsreadGet the current user
getTopTracksreadGet the current user
getUsersSavedTracksreadGet a list of tracks saved in the user\
pausePlaybackreadPause Spotify playback on the active device
playMusicwriteStart playing a Spotify track, album, artist, or playlist.
removeTracksFromPlaylistdestructiveRemove one or more tracks from a Spotify playlist (max 100 tracks per request)
removeUsersSavedTracksdestructiveRemove one or more tracks from the user\
reorderPlaylistItemsreadReorder a range of tracks within a Spotify playlist by moving them to a new position
resumePlaybackreadResume Spotify playback on the active device
saveOrRemoveAlbumForUserdestructiveSave or remove albums from the user\
searchSpotifyreadSearch for tracks, albums, artists, playlists, podcast episodes, or shows on Spotify.
setVolumewriteSet the playback volume to a specific percentage (0-100). Requires Spotify Premium.
skipToNextreadSkip to the next track in the current Spotify playback queue
skipToPreviousreadSkip to the previous track in the current Spotify playback queue
unfollowPlaylistdestructiveRemove a playlist from the current user
updatePlaylistwriteUpdate the details of a Spotify playlist (name, description, public/private, collaborative)
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils.ts:378
console.error('Example: http://127.0.0.1:8888/callback');
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
removeTracksFromPlaylist, removeUsersSavedTracks, saveOrRemoveAlbumForUser, unfollowPlaylist
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:320
8. Click "Edit Settings" and add a Redirect URI (e.g., `http://127.0.0.1:8888/callback`)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:338
"redirectUri": "http://127.0.0.1:8888/callback"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:422
Clients then connect to `http://127.0.0.1:3000/mcp`. `MCP_HTTP_PORT` defaults to `3000` and `MCP_HTTP_HOST` to `127.0.0.1`. On a loopback address, requests whose `Host` or `Origin` header names anythi
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
test/helpers.js:16
redirectUri: 'http://127.0.0.1:8888/callback',
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/node, @modelcontextprotocol/server, @spotify/web-api-ts-sdk, open, zod, @biomejs/biome, @modelcontextprotocol/client, @types/node
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-01 · audit v0.4.1 · source sha 41e64b1dc363full audit observations/trust-audit/mcp-server/marcelmarais__spotify-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0141e64b1dc363CAUTIONB86first audit
06

Questions

What is the Spotify MCP server?

Lightweight MCP server for Spotify

What tools does Spotify expose?

30 in total: 21 read-only, 5 that write, and 4 that can delete or overwrite (removeTracksFromPlaylist, removeUsersSavedTracks, saveOrRemoveAlbumForUser, unfollowPlaylist). Every one is listed on this page with its risk.

Is Spotify safe to connect to an agent?

With care. The audit graded it B (86/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Spotify need?

No credential environment variables were found in its source, so it appears to need none.

How does Spotify run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as spotify-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (41e64b1dc363), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement