GoHighLevelCAUTION
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Instead of trying to tackle this ---- use our hosted version --- GHL Agent Framework, One Click to Sign in!
https://www.strategixagents.com/
🚨 IMPORTANT: FOUNDATIONAL PROJECT NOTICE
⚠️ This is a BASE-LEVEL foundational project designed to connect the GoHighLevel community with AI automation through MCP (Model Context Protocol).
🎯 What This Project Is:
- Foundation Layer: Provides access to ALL sub-account level GoHighLevel API endpoints via MCP
- Community Starter: Built to get the community moving forward together, faster
- Open Architecture: API client and types can be further modularized and segmented as needed
- Educational Resource: Learn how to integrate GoHighLevel with AI systems
⚠️ Critical AI Safety Considerations:
- Memory/Recall Systems: If you don't implement proper memory or recall mechanisms, AI may perform unintended actions
- Rate Limiting: Monitor API usage to avoid hitting GoHighLevel rate limits
- Permission Controls: Understand that this provides FULL access to your sub-account APIs
- Data Security: All actions are performed with your API credentials - ensure proper security practices
🎯 Intended Use:
- Personal/Business Use: Integrate your own GoHighLevel accounts with AI
- Development Base: Build upon this foundation for custom solutions
- Learning & Experimentation: Understand GoHighLevel API patterns
- Community Contribution: Help improve and extend this foundation
🚫 NOT Intended For:
- Direct Resale: This is freely available community software
- Production Without Testing: Always test thoroughly in development environments
- Unmonitored AI Usage: Implement proper safeguards and monitoring
🔑 CRITICAL: GoHighLevel API Setup
📋 Required: Private Integrations API Key
⚠️ This project requires a PRIVATE INTEGRATIONS API key, not a regular API key!
**How to get your Private I
2a45fb070facOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ghl-mcp-server --env GHL_API_KEY=${GHL_API_KEY} -- npx -y @mastanley13/[email protected]{
"mcpServers": {
"ghl-mcp-server": {
"command": "npx",
"args": [
"-y",
"@mastanley13/[email protected]"
],
"env": {
"GHL_API_KEY": "${GHL_API_KEY}"
}
}
}
}Exposed tools (200)
108 read · 106 write · 41 destructive. Blast radius: 41 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_contact_followers | write | Add followers to a contact |
add_contact_tags | write | Add tags to a contact |
add_contact_to_campaign | write | Add contact to a marketing campaign |
add_contact_to_workflow | write | Add contact to a workflow |
add_inbound_message | write | Manually add an inbound message to a conversation |
add_opportunity_followers | write | Add followers to an opportunity for notifications and tracking |
add_outbound_call | write | Manually add an outbound call record to a conversation |
bulk_delete_social_posts | destructive | Delete multiple social media posts at once (max 50) |
bulk_update_contact_business | write | Bulk update business association for multiple contacts |
bulk_update_contact_tags | destructive | Bulk add or remove tags from multiple contacts |
cancel_scheduled_email | read | Cancel a scheduled email before it is sent |
cancel_scheduled_message | read | Cancel a scheduled message before it is sent |
check_url_slug | read | Check if a URL slug is available for use. Use this before creating or updating blog posts to ensure unique URLs. |
create_appointment | write | Create a new appointment/booking in GoHighLevel |
create_appointment_note | write | Create a note for an appointment |
create_block_slot | write | Create a blocked time slot to prevent bookings during specific times |
create_blog_post | write | Create a new blog post in GoHighLevel. Requires blog ID, author ID, and category IDs which can be obtained from other blog tools. |
create_calendar | write | Create a new calendar in GoHighLevel |
create_calendar_group | write | Create a new calendar group |
create_calendar_notifications | write | Create calendar notifications |
create_calendar_resource_equipment | write | Create a calendar equipment resource |
create_calendar_resource_room | write | Create a calendar room resource |
create_contact | write | Create a new contact in GoHighLevel |
create_contact_note | write | Create a new note for a contact |
create_contact_task | write | Create a new task for a contact |
create_conversation | write | Create a new conversation with a contact |
create_coupon | write | Create a new promotional coupon |
create_custom_provider_config | write | Create new payment config for a location |
create_custom_provider_integration | write | Create a new custom payment provider integration |
create_email_template | write | Create a new email template in GoHighLevel. |
create_estimate | write | Create a new estimate |
create_invoice | write | Create a new invoice |
create_invoice_from_estimate | write | Create an invoice from an estimate |
create_invoice_schedule | write | Create a new invoice schedule |
create_invoice_template | write | Create a new invoice template |
create_location | write | Create a new sub-account/location in GoHighLevel (Agency Pro plan required) |
create_location_custom_field | write | Create a new custom field for a location |
create_location_custom_value | write | Create a new custom value for a location |
create_location_tag | write | Create a new tag for a location |
create_object_record | write | Create a new record in a custom or standard object with properties, owner, and followers |
create_object_schema | write | Create a new custom object schema with labels, key, and primary display property |
create_opportunity | write | Create a new opportunity in GoHighLevel CRM |
create_order_fulfillment | write | Create a fulfillment for an order |
create_social_post | write | Create a new social media post for multiple platforms |
create_whitelabel_integration_provider | write | Create a white-label integration provider for payments |
delete_appointment | destructive | Cancel/delete an appointment from GoHighLevel |
delete_appointment_note | destructive | Delete an appointment note |
delete_calendar | destructive | Delete a calendar from GoHighLevel |
delete_calendar_group | destructive | Delete a calendar group |
delete_calendar_notification | destructive | Delete calendar notification |
delete_calendar_resource_equipment | destructive | Delete an equipment resource |
delete_calendar_resource_room | destructive | Delete a room resource |
delete_contact | destructive | Delete a contact from GoHighLevel |
delete_contact_note | destructive | Delete a note for a contact |
delete_contact_task | destructive | Delete a task for a contact |
delete_conversation | destructive | Delete a conversation permanently |
delete_coupon | destructive | Delete a coupon permanently |
delete_custom_provider_integration | destructive | Delete an existing custom payment provider integration |
delete_email_template | destructive | Delete an email template from GoHighLevel. |
delete_invoice_template | destructive | Delete an invoice template |
delete_location | destructive | Delete a sub-account/location from GoHighLevel |
delete_location_custom_field | destructive | Delete a custom field from a location |
delete_location_custom_value | destructive | Delete a custom value from a location |
delete_location_tag | destructive | Delete a location tag |
delete_location_template | destructive | Delete a template from a location |
delete_media_file | destructive | Delete a specific file or folder from the media library |
delete_object_record | destructive | Delete a record from a custom or standard object |
delete_opportunity | destructive | Delete an opportunity from GoHighLevel CRM |
delete_social_account | destructive | Delete a social media account connection |
delete_social_post | destructive | Delete a social media post |
disable_calendar_group | write | Enable or disable a calendar group |
disconnect_custom_provider_config | read | Disconnect existing payment config for a location |
download_transcription | read | Download call transcription as a text file |
generate_estimate_number | read | Generate a unique estimate number |
generate_invoice_number | read | Generate a unique invoice number |
get_all_objects | read | Get all objects (custom and standard) for a location including contact, opportunity, business, and custom objects |
get_appointment | read | Get detailed information about a specific appointment by ID |
get_appointment_notes | read | Get notes for an appointment |
get_blocked_slots | read | Get blocked time slots for a location |
get_blog_authors | read | Get all available blog authors for the current location. Use this to find author IDs for creating blog posts. |
get_blog_categories | read | Get all available blog categories for the current location. Use this to find category IDs for creating blog posts. |
get_blog_posts | read | Get blog posts from a specific blog site. Use this to list and search existing blog posts. |
get_blog_sites | read | Get all blog sites for the current location. Use this to find available blogs before creating or managing posts. |
get_calendar | read | Get detailed information about a specific calendar by ID |
get_calendar_events | read | Get appointments/events from calendars within a date range |
get_calendar_groups | read | Get all calendar groups in the GoHighLevel location |
get_calendar_notification | read | Get specific calendar notification |
get_calendar_notifications | read | Get calendar notifications |
get_calendar_resource_equipment | read | Get specific equipment resource details |
get_calendar_resource_room | read | Get specific room resource details |
get_calendar_resources_equipments | read | Get calendar equipment resources |
get_calendar_resources_rooms | read | Get calendar room resources |
get_calendars | read | Get all calendars in the GoHighLevel location with optional filtering |
get_contact | read | Get detailed information about a specific contact |
get_contact_appointments | read | Get all appointments for a contact |
get_contact_note | read | Get a specific note for a contact |
get_contact_notes | read | Get all notes for a contact |
get_contact_task | read | Get a specific task for a contact |
get_contact_tasks | read | Get all tasks for a contact |
get_contacts_by_business | read | Get contacts associated with a specific business |
get_conversation | read | Get detailed conversation information including message history |
get_coupon | read | Get coupon details by ID or code |
get_csv_upload_status | write | Get status of CSV uploads |
get_custom_provider_config | read | Fetch existing payment config for a location |
get_duplicate_contact | read | Check for duplicate contacts by email or phone |
get_email_campaigns | read | Get a list of email campaigns from GoHighLevel. |
get_email_message | read | Get detailed email message information by email message ID |
get_email_templates | read | Get a list of email templates from GoHighLevel. |
get_free_slots | read | Get available time slots for booking appointments on a specific calendar |
get_invoice | read | Get invoice by ID |
get_invoice_schedule | write | Get invoice schedule by ID |
get_invoice_template | read | Get invoice template by ID |
get_location | read | Get detailed information about a specific location/sub-account by ID |
get_location_custom_field | read | Get a specific custom field by ID |
get_location_custom_fields | read | Get custom fields for a location, optionally filtered by model type |
get_location_custom_value | read | Get a specific custom value by ID |
get_location_custom_values | read | Get all custom values for a location |
get_location_tag | read | Get a specific location tag by ID |
get_location_tags | read | Get all tags for a specific location |
get_location_templates | read | Get SMS/Email templates for a location |
get_media_files | read | Get list of files and folders from the media library with filtering and search capabilities |
get_message | read | Get detailed message information by message ID |
get_message_recording | read | Get call recording audio for a message |
get_message_transcription | read | Get call transcription text for a message |
get_object_record | read | Get a specific record by ID from a custom or standard object |
get_object_schema | read | Get object schema details by key including all fields and properties for custom or standard objects |
get_opportunity | read | Get detailed information about a specific opportunity by ID |
get_order_by_id | write | Get a specific order by its ID |
get_pipelines | read | Get all sales pipelines configured in GoHighLevel |
get_platform_accounts | read | Get available accounts for a specific platform after OAuth |
get_recent_messages | read | Get recent messages across all conversations for monitoring |
get_social_accounts | read | Get all connected social media accounts and groups |
get_social_categories | write | Get social media post categories |
get_social_category | read | Get a specific social media category by ID |
get_social_post | write | Get details of a specific social media post |
get_social_tags | write | Get social media post tags |
get_social_tags_by_ids | read | Get specific social media tags by their IDs |
get_subscription_by_id | read | Get a specific subscription by its ID |
get_timezones | read | Get available timezones for location configuration |
get_transaction_by_id | read | Get a specific transaction by its ID |
ghl_create_association | write | Create a new association that defines relationship types between entities like contacts, custom objects, and opportunities. |
ghl_create_custom_field | write | Create a new custom field for custom objects or company (business). Supports various field types including text, number, options, date, file upload, etc. |
ghl_create_custom_field_folder | write | Create a new custom field folder for organizing fields within an object. |
ghl_create_price | write | Create a price for a product |
ghl_create_product | write | Create a new product in GoHighLevel |
ghl_create_product_collection | write | Create a new product collection |
ghl_create_relation | write | Create a relation between two entities using an existing association. Links specific records together. |
ghl_create_shipping_carrier | write | Create a new shipping carrier for dynamic rate calculation |
ghl_create_shipping_rate | write | Create a new shipping rate for a shipping zone |
ghl_create_shipping_zone | write | Create a new shipping zone with specific countries and states |
ghl_create_store_setting | write | Create or update store settings including shipping origin and notifications |
ghl_delete_association | destructive | Delete a user-defined association. This will also delete all relations created with this association. |
ghl_delete_custom_field | destructive | Delete a custom field by ID. This will permanently remove the field and its data. |
ghl_delete_custom_field_folder | destructive | Delete a custom field folder. This will also affect any fields within the folder. |
ghl_delete_product | destructive | Delete a product by ID |
ghl_delete_relation | destructive | Delete a specific relation between two entities. |
ghl_delete_shipping_carrier | destructive | Delete a shipping carrier |
ghl_delete_shipping_rate | destructive | Delete a shipping rate |
ghl_delete_shipping_zone | destructive | Delete a shipping zone and all its associated shipping rates |
ghl_get_all_associations | read | Get all associations for a sub-account/location with pagination. Returns system-defined and user-defined associations. |
ghl_get_association_by_id | read | Get a specific association by its ID. Works for both system-defined and user-defined associations. |
ghl_get_association_by_key | read | Get an association by its key name. Useful for finding both standard and user-defined associations. |
ghl_get_association_by_object_key | read | Get associations by object keys like contacts, custom objects, and opportunities. |
ghl_get_available_shipping_rates | write | Get available shipping rates for an order based on destination and order details |
ghl_get_custom_field_by_id | read | Get a custom field or folder by its ID. Supports custom objects and company (business) fields. |
ghl_get_custom_fields_by_object_key | read | Get all custom fields and folders for a specific object key (e.g., custom object or company). |
ghl_get_product | read | Get a specific product by ID |
ghl_get_relations_by_record | read | Get all relations for a specific record ID with pagination and optional filtering by association IDs. |
ghl_get_shipping_carrier | read | Get details of a specific shipping carrier |
ghl_get_shipping_rate | read | Get details of a specific shipping rate |
ghl_get_shipping_zone | read | Get details of a specific shipping zone |
ghl_get_store_setting | read | Get current store settings |
ghl_get_survey_submissions | read | Retrieve survey submissions with advanced filtering and pagination. Get responses from contacts who have completed surveys. |
ghl_get_surveys | read | Retrieve all surveys for a location. Surveys are used to collect information from contacts through forms and questionnaires. |
ghl_get_workflows | read | Retrieve all workflows for a location. Workflows represent automation sequences that can be triggered by various events in the system. |
ghl_list_inventory | read | List inventory items with stock levels |
ghl_list_prices | read | List prices for a product |
ghl_list_product_collections | read | List product collections |
ghl_list_products | read | List products with optional filtering |
ghl_list_shipping_carriers | read | List all shipping carriers for a location |
ghl_list_shipping_rates | read | List all shipping rates for a specific shipping zone |
ghl_list_shipping_zones | read | List all shipping zones for a location |
ghl_update_association | write | Update the labels of an existing association. Only user-defined associations can be updated. |
ghl_update_custom_field | write | Update an existing custom field by ID. Can modify name, description, options, and other properties. |
ghl_update_custom_field_folder | write | Update the name of an existing custom field folder. |
ghl_update_product | write | Update an existing product |
ghl_update_shipping_carrier | write | Update a shipping carrier\ |
ghl_update_shipping_rate | write | Update a shipping rate\ |
ghl_update_shipping_zone | write | Update a shipping zone\ |
list_coupons | read | List all coupons for a location with optional filtering |
list_estimates | read | List all estimates |
list_invoice_schedules | read | List all invoice schedules |
list_invoice_templates | read | List all invoice templates |
list_invoices | read | List all invoices |
list_order_fulfillments | write | List all fulfillments for an order |
list_orders | read | List orders with optional filtering and pagination |
list_subscriptions | read | List subscriptions with optional filtering and pagination |
list_transactions | read | List transactions with optional filtering and pagination |
list_whitelabel_integration_providers | read | List white-label integration providers with optional pagination |
live_chat_typing | write | Send typing indicator for live chat conversations |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
.env.example
console.log(`🌐 Server running on: http://0.0.0.0:${this.port}`);console.log(`🔗 SSE Endpoint: http://0.0.0.0:${this.port}/sse`);bulk_delete_social_posts, bulk_update_contact_tags, delete_appointment, delete_appointment_note, delete_calendar, delete_calendar_group, delete_calendar_notification, delete_calendar_resource_equipmen
import { GHLApiClient } from '../../src/clients/ghl-api-client.js';} from '../../src/types/ghl-types.js';
import { BlogTools } from '../../src/tools/blog-tools.js';import { ContactTools } from '../../src/tools/contact-tools.js';import { ConversationTools } from '../../src/tools/conversation-tools.js';@modelcontextprotocol/sdk, @types/cors, @types/express, axios, cors, dotenv, express, @types/jest
- **Permission Controls**: Understand that this provides FULL access to your sub-account APIs
cat > .env << EOF
Gates applied: no_behavioural_pass.
2a45fb070facfull audit observations/trust-audit/mcp-server/mastanley13__gohighlevel.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 2a45fb070fac | CAUTION | B | 85 | first audit |
Questions
What tools does GoHighLevel expose?
200 in total: 108 read-only, 106 that write, and 41 that can delete or overwrite (bulk_delete_social_posts, bulk_update_contact_tags, delete_appointment, delete_appointment_note, delete_calendar). Every one is listed on this page with its risk.
Is GoHighLevel safe to connect to an agent?
With care. The audit graded it B (85/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 41 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GoHighLevel need?
It reads GHL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does GoHighLevel run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @mastanley13/ghl-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (2a45fb070fac), read on 2026-10-06. The repository is watched and re-audited when it changes.