Atlas / MCP servers / mastanley13 / GoHighLevel

GoHighLevelCAUTION

mcp/mastanley13/gohighlevel
Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
200 108r · 106w · 41d
Transport
sse · stdio
License
NOASSERTION
Stars
194
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Instead of trying to tackle this ---- use our hosted version --- GHL Agent Framework, One Click to Sign in!

https://www.strategixagents.com/

🚨 IMPORTANT: FOUNDATIONAL PROJECT NOTICE

⚠️ This is a BASE-LEVEL foundational project designed to connect the GoHighLevel community with AI automation through MCP (Model Context Protocol).

🎯 What This Project Is:

  • Foundation Layer: Provides access to ALL sub-account level GoHighLevel API endpoints via MCP
  • Community Starter: Built to get the community moving forward together, faster
  • Open Architecture: API client and types can be further modularized and segmented as needed
  • Educational Resource: Learn how to integrate GoHighLevel with AI systems

⚠️ Critical AI Safety Considerations:

  • Memory/Recall Systems: If you don't implement proper memory or recall mechanisms, AI may perform unintended actions
  • Rate Limiting: Monitor API usage to avoid hitting GoHighLevel rate limits
  • Permission Controls: Understand that this provides FULL access to your sub-account APIs
  • Data Security: All actions are performed with your API credentials - ensure proper security practices

🎯 Intended Use:

  • Personal/Business Use: Integrate your own GoHighLevel accounts with AI
  • Development Base: Build upon this foundation for custom solutions
  • Learning & Experimentation: Understand GoHighLevel API patterns
  • Community Contribution: Help improve and extend this foundation

🚫 NOT Intended For:

  • Direct Resale: This is freely available community software
  • Production Without Testing: Always test thoroughly in development environments
  • Unmonitored AI Usage: Implement proper safeguards and monitoring

🔑 CRITICAL: GoHighLevel API Setup

📋 Required: Private Integrations API Key

⚠️ This project requires a PRIVATE INTEGRATIONS API key, not a regular API key!

**How to get your Private I

Read from source at commit 2a45fb070facOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ghl-mcp-server --env GHL_API_KEY=${GHL_API_KEY} -- npx -y @mastanley13/[email protected]
claude-desktop
{
  "mcpServers": {
    "ghl-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@mastanley13/[email protected]"
      ],
      "env": {
        "GHL_API_KEY": "${GHL_API_KEY}"
      }
    }
  }
}
03

Exposed tools (200)

108 read · 106 write · 41 destructive. Blast radius: 41 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_contact_followerswriteAdd followers to a contact
add_contact_tagswriteAdd tags to a contact
add_contact_to_campaignwriteAdd contact to a marketing campaign
add_contact_to_workflowwriteAdd contact to a workflow
add_inbound_messagewriteManually add an inbound message to a conversation
add_opportunity_followerswriteAdd followers to an opportunity for notifications and tracking
add_outbound_callwriteManually add an outbound call record to a conversation
bulk_delete_social_postsdestructiveDelete multiple social media posts at once (max 50)
bulk_update_contact_businesswriteBulk update business association for multiple contacts
bulk_update_contact_tagsdestructiveBulk add or remove tags from multiple contacts
cancel_scheduled_emailreadCancel a scheduled email before it is sent
cancel_scheduled_messagereadCancel a scheduled message before it is sent
check_url_slugreadCheck if a URL slug is available for use. Use this before creating or updating blog posts to ensure unique URLs.
create_appointmentwriteCreate a new appointment/booking in GoHighLevel
create_appointment_notewriteCreate a note for an appointment
create_block_slotwriteCreate a blocked time slot to prevent bookings during specific times
create_blog_postwriteCreate a new blog post in GoHighLevel. Requires blog ID, author ID, and category IDs which can be obtained from other blog tools.
create_calendarwriteCreate a new calendar in GoHighLevel
create_calendar_groupwriteCreate a new calendar group
create_calendar_notificationswriteCreate calendar notifications
create_calendar_resource_equipmentwriteCreate a calendar equipment resource
create_calendar_resource_roomwriteCreate a calendar room resource
create_contactwriteCreate a new contact in GoHighLevel
create_contact_notewriteCreate a new note for a contact
create_contact_taskwriteCreate a new task for a contact
create_conversationwriteCreate a new conversation with a contact
create_couponwriteCreate a new promotional coupon
create_custom_provider_configwriteCreate new payment config for a location
create_custom_provider_integrationwriteCreate a new custom payment provider integration
create_email_templatewriteCreate a new email template in GoHighLevel.
create_estimatewriteCreate a new estimate
create_invoicewriteCreate a new invoice
create_invoice_from_estimatewriteCreate an invoice from an estimate
create_invoice_schedulewriteCreate a new invoice schedule
create_invoice_templatewriteCreate a new invoice template
create_locationwriteCreate a new sub-account/location in GoHighLevel (Agency Pro plan required)
create_location_custom_fieldwriteCreate a new custom field for a location
create_location_custom_valuewriteCreate a new custom value for a location
create_location_tagwriteCreate a new tag for a location
create_object_recordwriteCreate a new record in a custom or standard object with properties, owner, and followers
create_object_schemawriteCreate a new custom object schema with labels, key, and primary display property
create_opportunitywriteCreate a new opportunity in GoHighLevel CRM
create_order_fulfillmentwriteCreate a fulfillment for an order
create_social_postwriteCreate a new social media post for multiple platforms
create_whitelabel_integration_providerwriteCreate a white-label integration provider for payments
delete_appointmentdestructiveCancel/delete an appointment from GoHighLevel
delete_appointment_notedestructiveDelete an appointment note
delete_calendardestructiveDelete a calendar from GoHighLevel
delete_calendar_groupdestructiveDelete a calendar group
delete_calendar_notificationdestructiveDelete calendar notification
delete_calendar_resource_equipmentdestructiveDelete an equipment resource
delete_calendar_resource_roomdestructiveDelete a room resource
delete_contactdestructiveDelete a contact from GoHighLevel
delete_contact_notedestructiveDelete a note for a contact
delete_contact_taskdestructiveDelete a task for a contact
delete_conversationdestructiveDelete a conversation permanently
delete_coupondestructiveDelete a coupon permanently
delete_custom_provider_integrationdestructiveDelete an existing custom payment provider integration
delete_email_templatedestructiveDelete an email template from GoHighLevel.
delete_invoice_templatedestructiveDelete an invoice template
delete_locationdestructiveDelete a sub-account/location from GoHighLevel
delete_location_custom_fielddestructiveDelete a custom field from a location
delete_location_custom_valuedestructiveDelete a custom value from a location
delete_location_tagdestructiveDelete a location tag
delete_location_templatedestructiveDelete a template from a location
delete_media_filedestructiveDelete a specific file or folder from the media library
delete_object_recorddestructiveDelete a record from a custom or standard object
delete_opportunitydestructiveDelete an opportunity from GoHighLevel CRM
delete_social_accountdestructiveDelete a social media account connection
delete_social_postdestructiveDelete a social media post
disable_calendar_groupwriteEnable or disable a calendar group
disconnect_custom_provider_configreadDisconnect existing payment config for a location
download_transcriptionreadDownload call transcription as a text file
generate_estimate_numberreadGenerate a unique estimate number
generate_invoice_numberreadGenerate a unique invoice number
get_all_objectsreadGet all objects (custom and standard) for a location including contact, opportunity, business, and custom objects
get_appointmentreadGet detailed information about a specific appointment by ID
get_appointment_notesreadGet notes for an appointment
get_blocked_slotsreadGet blocked time slots for a location
get_blog_authorsreadGet all available blog authors for the current location. Use this to find author IDs for creating blog posts.
get_blog_categoriesreadGet all available blog categories for the current location. Use this to find category IDs for creating blog posts.
get_blog_postsreadGet blog posts from a specific blog site. Use this to list and search existing blog posts.
get_blog_sitesreadGet all blog sites for the current location. Use this to find available blogs before creating or managing posts.
get_calendarreadGet detailed information about a specific calendar by ID
get_calendar_eventsreadGet appointments/events from calendars within a date range
get_calendar_groupsreadGet all calendar groups in the GoHighLevel location
get_calendar_notificationreadGet specific calendar notification
get_calendar_notificationsreadGet calendar notifications
get_calendar_resource_equipmentreadGet specific equipment resource details
get_calendar_resource_roomreadGet specific room resource details
get_calendar_resources_equipmentsreadGet calendar equipment resources
get_calendar_resources_roomsreadGet calendar room resources
get_calendarsreadGet all calendars in the GoHighLevel location with optional filtering
get_contactreadGet detailed information about a specific contact
get_contact_appointmentsreadGet all appointments for a contact
get_contact_notereadGet a specific note for a contact
get_contact_notesreadGet all notes for a contact
get_contact_taskreadGet a specific task for a contact
get_contact_tasksreadGet all tasks for a contact
get_contacts_by_businessreadGet contacts associated with a specific business
get_conversationreadGet detailed conversation information including message history
get_couponreadGet coupon details by ID or code
get_csv_upload_statuswriteGet status of CSV uploads
get_custom_provider_configreadFetch existing payment config for a location
get_duplicate_contactreadCheck for duplicate contacts by email or phone
get_email_campaignsreadGet a list of email campaigns from GoHighLevel.
get_email_messagereadGet detailed email message information by email message ID
get_email_templatesreadGet a list of email templates from GoHighLevel.
get_free_slotsreadGet available time slots for booking appointments on a specific calendar
get_invoicereadGet invoice by ID
get_invoice_schedulewriteGet invoice schedule by ID
get_invoice_templatereadGet invoice template by ID
get_locationreadGet detailed information about a specific location/sub-account by ID
get_location_custom_fieldreadGet a specific custom field by ID
get_location_custom_fieldsreadGet custom fields for a location, optionally filtered by model type
get_location_custom_valuereadGet a specific custom value by ID
get_location_custom_valuesreadGet all custom values for a location
get_location_tagreadGet a specific location tag by ID
get_location_tagsreadGet all tags for a specific location
get_location_templatesreadGet SMS/Email templates for a location
get_media_filesreadGet list of files and folders from the media library with filtering and search capabilities
get_messagereadGet detailed message information by message ID
get_message_recordingreadGet call recording audio for a message
get_message_transcriptionreadGet call transcription text for a message
get_object_recordreadGet a specific record by ID from a custom or standard object
get_object_schemareadGet object schema details by key including all fields and properties for custom or standard objects
get_opportunityreadGet detailed information about a specific opportunity by ID
get_order_by_idwriteGet a specific order by its ID
get_pipelinesreadGet all sales pipelines configured in GoHighLevel
get_platform_accountsreadGet available accounts for a specific platform after OAuth
get_recent_messagesreadGet recent messages across all conversations for monitoring
get_social_accountsreadGet all connected social media accounts and groups
get_social_categorieswriteGet social media post categories
get_social_categoryreadGet a specific social media category by ID
get_social_postwriteGet details of a specific social media post
get_social_tagswriteGet social media post tags
get_social_tags_by_idsreadGet specific social media tags by their IDs
get_subscription_by_idreadGet a specific subscription by its ID
get_timezonesreadGet available timezones for location configuration
get_transaction_by_idreadGet a specific transaction by its ID
ghl_create_associationwriteCreate a new association that defines relationship types between entities like contacts, custom objects, and opportunities.
ghl_create_custom_fieldwriteCreate a new custom field for custom objects or company (business). Supports various field types including text, number, options, date, file upload, etc.
ghl_create_custom_field_folderwriteCreate a new custom field folder for organizing fields within an object.
ghl_create_pricewriteCreate a price for a product
ghl_create_productwriteCreate a new product in GoHighLevel
ghl_create_product_collectionwriteCreate a new product collection
ghl_create_relationwriteCreate a relation between two entities using an existing association. Links specific records together.
ghl_create_shipping_carrierwriteCreate a new shipping carrier for dynamic rate calculation
ghl_create_shipping_ratewriteCreate a new shipping rate for a shipping zone
ghl_create_shipping_zonewriteCreate a new shipping zone with specific countries and states
ghl_create_store_settingwriteCreate or update store settings including shipping origin and notifications
ghl_delete_associationdestructiveDelete a user-defined association. This will also delete all relations created with this association.
ghl_delete_custom_fielddestructiveDelete a custom field by ID. This will permanently remove the field and its data.
ghl_delete_custom_field_folderdestructiveDelete a custom field folder. This will also affect any fields within the folder.
ghl_delete_productdestructiveDelete a product by ID
ghl_delete_relationdestructiveDelete a specific relation between two entities.
ghl_delete_shipping_carrierdestructiveDelete a shipping carrier
ghl_delete_shipping_ratedestructiveDelete a shipping rate
ghl_delete_shipping_zonedestructiveDelete a shipping zone and all its associated shipping rates
ghl_get_all_associationsreadGet all associations for a sub-account/location with pagination. Returns system-defined and user-defined associations.
ghl_get_association_by_idreadGet a specific association by its ID. Works for both system-defined and user-defined associations.
ghl_get_association_by_keyreadGet an association by its key name. Useful for finding both standard and user-defined associations.
ghl_get_association_by_object_keyreadGet associations by object keys like contacts, custom objects, and opportunities.
ghl_get_available_shipping_rateswriteGet available shipping rates for an order based on destination and order details
ghl_get_custom_field_by_idreadGet a custom field or folder by its ID. Supports custom objects and company (business) fields.
ghl_get_custom_fields_by_object_keyreadGet all custom fields and folders for a specific object key (e.g., custom object or company).
ghl_get_productreadGet a specific product by ID
ghl_get_relations_by_recordreadGet all relations for a specific record ID with pagination and optional filtering by association IDs.
ghl_get_shipping_carrierreadGet details of a specific shipping carrier
ghl_get_shipping_ratereadGet details of a specific shipping rate
ghl_get_shipping_zonereadGet details of a specific shipping zone
ghl_get_store_settingreadGet current store settings
ghl_get_survey_submissionsreadRetrieve survey submissions with advanced filtering and pagination. Get responses from contacts who have completed surveys.
ghl_get_surveysreadRetrieve all surveys for a location. Surveys are used to collect information from contacts through forms and questionnaires.
ghl_get_workflowsreadRetrieve all workflows for a location. Workflows represent automation sequences that can be triggered by various events in the system.
ghl_list_inventoryreadList inventory items with stock levels
ghl_list_pricesreadList prices for a product
ghl_list_product_collectionsreadList product collections
ghl_list_productsreadList products with optional filtering
ghl_list_shipping_carriersreadList all shipping carriers for a location
ghl_list_shipping_ratesreadList all shipping rates for a specific shipping zone
ghl_list_shipping_zonesreadList all shipping zones for a location
ghl_update_associationwriteUpdate the labels of an existing association. Only user-defined associations can be updated.
ghl_update_custom_fieldwriteUpdate an existing custom field by ID. Can modify name, description, options, and other properties.
ghl_update_custom_field_folderwriteUpdate the name of an existing custom field folder.
ghl_update_productwriteUpdate an existing product
ghl_update_shipping_carrierwriteUpdate a shipping carrier\
ghl_update_shipping_ratewriteUpdate a shipping rate\
ghl_update_shipping_zonewriteUpdate a shipping zone\
list_couponsreadList all coupons for a location with optional filtering
list_estimatesreadList all estimates
list_invoice_schedulesreadList all invoice schedules
list_invoice_templatesreadList all invoice templates
list_invoicesreadList all invoices
list_order_fulfillmentswriteList all fulfillments for an order
list_ordersreadList orders with optional filtering and pagination
list_subscriptionsreadList subscriptions with optional filtering and pagination
list_transactionsreadList transactions with optional filtering and pagination
list_whitelabel_integration_providersreadList white-label integration providers with optional pagination
live_chat_typingwriteSend typing indicator for live chat conversations
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.env.example
.env.example
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/http-server.ts:696
console.log(`🌐 Server running on: http://0.0.0.0:${this.port}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/http-server.ts:697
console.log(`🔗 SSE Endpoint: http://0.0.0.0:${this.port}/sse`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bulk_delete_social_posts, bulk_update_contact_tags, delete_appointment, delete_appointment_note, delete_calendar, delete_calendar_group, delete_calendar_notification, delete_calendar_resource_equipmen
Why it matters. 41 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/clients/ghl-api-client.test.ts:7
import { GHLApiClient } from '../../src/clients/ghl-api-client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/mocks/ghl-api-client.mock.ts:15
} from '../../src/types/ghl-types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/blog-tools.test.ts:7
import { BlogTools } from '../../src/tools/blog-tools.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/contact-tools.test.ts:7
import { ContactTools } from '../../src/tools/contact-tools.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/conversation-tools.test.ts:7
import { ConversationTools } from '../../src/tools/conversation-tools.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/cors, @types/express, axios, cors, dotenv, express, @types/jest
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:20
- **Permission Controls**: Understand that this provides FULL access to your sub-account APIs
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE-DESKTOP-DEPLOYMENT-PLAN.md:56
cat > .env << EOF
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 2a45fb070facfull audit observations/trust-audit/mcp-server/mastanley13__gohighlevel.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-062a45fb070facCAUTIONB85first audit
06

Questions

What tools does GoHighLevel expose?

200 in total: 108 read-only, 106 that write, and 41 that can delete or overwrite (bulk_delete_social_posts, bulk_update_contact_tags, delete_appointment, delete_appointment_note, delete_calendar). Every one is listed on this page with its risk.

Is GoHighLevel safe to connect to an agent?

With care. The audit graded it B (85/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 41 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does GoHighLevel need?

It reads GHL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does GoHighLevel run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @mastanley13/ghl-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (2a45fb070fac), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement