PerplexitySAFE
The official MCP server implementation for the Perplexity API Platform
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://cursor.com/install-mcp?name=perplexity&config=eyJ1cmwiOiJodHRwczovL2FwaS5wZXJwbGV4aXR5LmFpL21jcCIsImhlYWRlcnMiOnsiQXV0aG9yaXphdGlvbiI6IkJlYXJlciBZT1VSX0FQSV9LRVkifX0%3D)
[](https://vscode.dev/redirect/mcp/install?name=perplexity&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fapi.perplexity.ai%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20%24%7Binput%3Aperplexity-api-key%7D%22%7D%7D&inputs=%5B%7B%22type%22%3A%22promptString%22%2C%22id%22%3A%22perplexity-api-key%22%2C%22description%22%3A%22Perplexity%20API%20Key%22%2C%22password%22%3Atrue%7D%5D)
[
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
perplexity_ask | read | |
perplexity_reason | read | |
perplexity_research | read | |
perplexity_search | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
baseUrl = `http://127.0.0.1:${port}`;baseUrl = `http://127.0.0.1:${port}`;[. Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Perplexity need?
It reads PERPLEXITY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Perplexity run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @perplexity-ai/mcp-server at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (0ed911c73ae0), read on 2026-09-22. The repository is watched and re-audited when it changes.