Atlas / MCP servers / mhenry3164 / Twenty CRM

Twenty CRMSAFE

mcp/mhenry3164/twenty-crm

A Model Context Protocol (MCP) server for Twenty CRM integration. Enables natural language interactions with your CRM data through Claude and other AI assistants. Supports CRUD operations, dynamic schema discovery, and advanced search across people, companies, tasks, and notes.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
31 14r · 12w · 5d
Transport
stdio
License
MIT
Stars
107
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Transform your CRM into an AI-powered assistant

[](https://github.com/mhenry3164/twenty-crm-mcp-server/actions/workflows/ci.yml) [](https://opensource.org/licenses/MIT) [](https://nodejs.org/) [](https://twenty.com) [](https://modelcontextprotocol.io/)

A Model Context Protocol server that connects [Twenty CRM](https://twenty.com) with Claude and other AI assistants, enabling natural language interactions with your customer data.

🚀 Quick Start • 🛠️ Tools • 🔍 Search & Filtering • 🐳 Docker • 🤝 Contributing

✨ Features

  • Complete CRUD for people, companies, opportunities, notes and tasks
  • Working search — built on Twenty's real filter grammar (ilike matching), not the nonexistent search param
  • Correct composite-field mapping — flat inputs like firstName/email/amount are converted to Twenty's name/emails/amount composite shapes on write
  • Cursor pagination (startingAfter/endingBefore) plus raw filter, orderBy and depth passthrough on every list tool
  • Notes & tasks attach to records — pass personId/companyId/opportunityId when creating and the target links are created for you
  • Batch creates — up to 60 people or companies per call
  • Resilient client — 30s timeouts, automatic retry with backoff on 429/5xx (honors Retry-After), structured error messages
  • Schema discovery — metadata tools expose your workspace's objects, fields and enum options, including custom objects
Read from source at commit 7db168f9d528OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add twenty-crm-mcp-server --env TWENTY_API_KEY=${TWENTY_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "twenty-crm-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "TWENTY_API_KEY": "${TWENTY_API_KEY}"
      }
    }
  }
}
03

Exposed tools (31)

14 read · 12 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
batch_create_companieswriteCreate up to 60 companies in one call
batch_create_peoplewriteCreate up to 60 people in one call
create_companywriteCreate a new company in Twenty CRM
create_notewriteCreate a note, optionally attached to a person, company and/or opportunity
create_opportunitywriteCreate a new opportunity (deal) in Twenty CRM
create_personwriteCreate a new person in Twenty CRM
create_taskwriteCreate a task, optionally attached to a person, company and/or opportunity
delete_companydestructiveDelete a company from Twenty CRM
delete_notedestructiveDelete a note from Twenty CRM
delete_opportunitydestructiveDelete an opportunity from Twenty CRM
delete_persondestructiveDelete a person from Twenty CRM
delete_taskdestructiveDelete a task from Twenty CRM
get_companyreadGet details of a specific company by ID
get_metadata_objectsreadGet all object types and their metadata (includes custom objects)
get_notereadGet details of a specific note by ID
get_object_metadatareadGet metadata for a specific object type, including its fields and enum options
get_opportunityreadGet details of a specific opportunity by ID
get_personreadGet details of a specific person by ID
get_taskreadGet details of a specific task by ID
list_companiesreadList companies with search, filtering and cursor pagination
list_notesreadList notes with search, filtering and cursor pagination
list_opportunitiesreadList opportunities with search, filtering and cursor pagination
list_peoplereadList people with search, filtering and cursor pagination
list_tasksreadList tasks with search, filtering and cursor pagination
list_workspace_membersreadList workspace members (users) — needed for task assigneeId
search_recordsreadSearch across multiple object types at once (people, companies, opportunities, notes, tasks)
update_companywriteUpdate an existing company. Only provided fields are changed
update_notewriteUpdate an existing note. Only provided fields are changed
update_opportunitywriteUpdate an existing opportunity. Only provided fields are changed
update_personwriteUpdate an existing person. Only provided fields are changed
update_taskwriteUpdate an existing task. Only provided fields are changed
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_company, delete_note, delete_opportunity, delete_person, delete_task
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 7db168f9d528full audit observations/trust-audit/mcp-server/mhenry3164__twenty-crm.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-077db168f9d528SAFEB89first audit
06

Questions

What is the Twenty CRM MCP server?

A Model Context Protocol (MCP) server for Twenty CRM integration. Enables natural language interactions with your CRM data through Claude and other AI assistants. Supports CRUD operations, dynamic schema discovery, and advanced search across people, companies, tasks, and notes.

What tools does Twenty CRM expose?

31 in total: 14 read-only, 12 that write, and 5 that can delete or overwrite (delete_company, delete_note, delete_opportunity, delete_person, delete_task). Every one is listed on this page with its risk.

Is Twenty CRM safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Twenty CRM need?

It reads TWENTY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Twenty CRM run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as twenty-crm-mcp-server at 2.0.0.

How current is this page?

The grade is for one exact copy of the source (7db168f9d528), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement