Vercel IntegrationSAFE
MCP server connecting Claude to Vercel
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) integration for Vercel's REST API, providing programmatic access to Vercel deployment management through AI Assistants like Claude and Cursor.
📋 Overview Last updated: May 2025
This MCP server implements Vercel's core API endpoints as tools, enabling:
- Deployment monitoring & management
- Environment variable retrieval
- Project deployment status tracking
- Team creation and management
- CI/CD pipeline integration
✨ Features
Current Tools
Deployment Management
vercel-list-all-deployments- List deployments with filteringvercel-get-deployment- Retrieve specific deployment detailsvercel-list-deployment-files- List files in a deploymentvercel-create-deployment- Create new deployments
Project Management
vercel-create-project- Create new Vercel projectsvercel-list-projects- List all projects with paginationvercel-find-project- Find a specific project by ID or namevercel-create-environment-variables- Create multiple environment variablesvercel-get-project-domain- Get information about a specific domain within a project
Environment Management
vercel-get-environments- Access project environment variablesvercel-create-custom-environment- Create custom environments for projects
Team Management
vercel-list-all-teams- List all accessible
e5fc577e449aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vercel --env VERCEL_API_TOKEN=${VERCEL_API_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"vercel": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"VERCEL_API_TOKEN": "${VERCEL_API_TOKEN}"
}
}
}
}Exposed tools (15)
8 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
vercel-create-custom-environment | write | Create a custom environment for a Vercel project. Note: Cannot be named |
vercel-create-deployment | write | Create a new Vercel deployment with the v13/deployments API |
vercel-create-environment-variables | write | Create environment variables for a Vercel project |
vercel-create-project | write | Create a new Vercel project |
vercel-create-team | write | Create a new Vercel team |
vercel-delete-project | destructive | Delete a Vercel project by its ID or name |
vercel-find-project | read | Find a Vercel project by its ID or name |
vercel-get-deployment | read | Get a deployment by its ID or URL |
vercel-get-environments | read | Retrieve environment variables for a project by ID or name |
vercel-get-project-domain | read | Get information about a specific domain within a Vercel project |
vercel-list-all-deployments | read | List deployments under the authenticated user or team. |
vercel-list-all-teams | read | List all teams under the authenticated account |
vercel-list-deployment-files | read | List all files of a Vercel deployment |
vercel-list-projects | read | List all projects under the authenticated user or team |
vercel-remove-environment-variable | destructive | Remove an environment variable from a Vercel project |
Trust audit
SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
vercel-delete-project, vercel-remove-environment-variable
import { vercelFetch } from "../../utils/api.js";import { vercelFetch } from "../../utils/api.js";import { vercelFetch } from "../../utils/api.js";import { VERCEL_API } from "../../utils/config.js";import { vercelFetch } from "../../utils/api.js";@modelcontextprotocol/sdk, dotenv, node-fetch, zod, @types/node, ts-node, typescript
- [`vercel-get-environments`](docs/environments.md#vercel-get-environments) - Access project environment variables
Gates applied: no_behavioural_pass, no_license.
e5fc577e449afull audit observations/trust-audit/mcp-server/nganiet__vercel-integration.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e5fc577e449a | SAFE | B | 87 | first audit |
Questions
What is the Vercel Integration MCP server?
MCP server connecting Claude to Vercel
What tools does Vercel Integration expose?
15 in total: 8 read-only, 5 that write, and 2 that can delete or overwrite (vercel-delete-project, vercel-remove-environment-variable). Every one is listed on this page with its risk.
Is Vercel Integration safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Vercel Integration need?
It reads VERCEL_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Vercel Integration run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as vercel at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (e5fc577e449a), read on 2026-10-07. The repository is watched and re-audited when it changes.