Atlas / MCP servers / saaslabsco / JustCall

JustCallCAUTION

mcp/saaslabsco/justcall

JustCall's Official MCP Server

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
66 44r · 20w · 2d
Transport
sse · streamable-http
License
MIT
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The JustCall Model Context Protocol (MCP) Server lets Large Language Models (LLMs) and AI agents make real-world voice calls and send SMS directly through JustCall’s APIs — securely, contextually, and programmatically.

It provides a function-calling interface for conversational AI systems, enabling:

  • 📞 AI-powered calling: Let your LLM initiate, manage, or transcribe calls using JustCall.
  • 💬 Smart messaging: Allow your AI agent to send or respond to SMS within conversations.
  • ⚙️ Seamless integration: Use the MCP standard to connect JustCall’s telephony capabilities with any LLM runtime or orchestration framework.

In short: It gives your LLMs a voice and a phone number — turning chatbots into truly conversational agents.

Claude Desktop Setup

  1. Open Claude Desktop and press CMD + , to go to Settings.
  2. Click on the Connectors tab.
  3. Click on the Add Custom Connector button.
  4. Add name as JustCall and Remote Server Url as https://mcp.justcall.host/mcp.
  5. Now on JustCall from the Connectors list click on Connect button for JustCall.
  6. It will open a JustCall page requesting API key and secret.
  7. Get your JustCall API Key & Secret from the JustCall dashboard ().
  8. Enter the API key and Secret and press Continue, it should redirect back you to Claude.

Claude Web - https://claude.ai

  1. Open connectors url in your Browser - .
  2. Click on the Connectors tab.
  3. Click on the Add Custom Connector button.
  4. Add name as JustCall and Remote Server Url as https://mcp.justcall.host/mcp.
  5. Now on JustCall from the Connectors list click on Connect button for JustCall.
  6. It will open a JustCall page requesting API key and secret.
  7. Get your JustCall API Key & Secret from the JustCall dashboard ().
  8. Enter the API key and Sec
Read from source at commit 69aca78ec6d0OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server --env JUSTCALL_API_KEY=${JUSTCALL_API_KEY} --env JUSTCALL_API_SECRET=${JUSTCALL_API_SECRET} -- npx -y @justcall/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@justcall/[email protected]"
      ],
      "env": {
        "JUSTCALL_API_KEY": "${JUSTCALL_API_KEY}",
        "JUSTCALL_API_SECRET": "${JUSTCALL_API_SECRET}"
      }
    }
  }
}
03

Exposed tools (66)

44 read · 20 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_contacts_blacklistwriteAdd one or more contacts to the JustCall account
add_salesdialer_campaign_contactwriteAdd contact to a specific Sales Dialer campaign identified by Campaign ID
add_salesdialer_contacts_dncawriteAdd one or more contacts to the Sales Dialer\
add_sms_thread_threadwriteAdd tag to a sms thread/conversation identified by thread ID or combination of contact number and JustCall number
check_sms_replyreadCheck for the most recent inbound sms/text message from a contact number
check_whatsapp_message_replyreadCheck for the most recent inbound whatsapp message from a contact number
create_appointmentwriteSchedule a new appointment on a specific JustCall calendar
create_contactwriteCreate a new contact in the JustCall account
create_salesdialer_campaignwriteCreate a new Sales Dialer campaign in the JustCall account
create_salesdialer_contactwriteCreate a new contact in Sales Dialer
create_sms_tagwriteCreate a new sms tag in the JustCall account for tagging conversations
create_voice_agent_callwriteInitiate an outbound call from a configured AI voice agent to a contact number
create_webhookwriteCreate a new webhook endpoint to receive real-time notifications
delete_sms_tagdestructiveDelete a specific sms tag by ID
get_account_analyticsreadRetrieve aggregated call analytics at the JustCall account level
get_agent_analyticsreadRetrieve call performance analytics for a specific agent identified by Agent ID
get_appointmentreadRetrieve details of a specific appointment by its ID
get_callread
get_call_ai_analysisreadRetrieve AI-generated analysis for a specific call by Call ID associated with either JustCall or Sales Dialer
get_call_journeyreadFetch the sequence of events for a specific call identified by Call ID
get_contactreadRetrieve detailed information for a specific contact by ID
get_meeting_ai_analysisreadRetrieve AI-generated analysis for a specific meeting identified by Instance ID
get_numberreadRetrieve detailed information for a specific phone number by ID
get_number_analyticsreadRetrieve call analytics for a specific JustCall phone number
get_salesdialer_agent_analyticsreadRetrieve call performance analytics of a specific agent for a Sales Dialer campaign
get_salesdialer_callreadRetrieve detailed information for a specific Sales Dialer call by Call ID
get_salesdialer_campaignreadRetrieve detailed information for a specific Sales Dialer campaign by ID
get_salesdialer_contactreadRetrieve detailed information for a specific contact in Sales Dialer by ID
get_smsreadRetrieve detailed information for a specific sms/text by ID
get_sms_tagreadRetrieve details of a specific sms tag by ID
get_sms_threadreadRetrieve a specific sms thread/conversation by ID
get_userreadRetrieve detailed information for a specific user by ID
get_user_groupreadRetrieve detailed information for a specific user group by ID
get_voice_agent_callreadRetrieve voice agent related data for a specific call identified by Call ID
get_whatsapp_messagereadRetrieve detailed information for a specific whatsapp message by ID
import_salesdialer_contactswriteImport multiple contacts into Sales Dialer or a campaign in bulk
import_salesdialer_contacts_statuswriteCheck the status of a bulk import job/request by its batch ID
list_appointment_slotsreadRetrieve all available time slots for appointments on a specific JustCall calendar
list_blacklist_contactsreadRetrieve all blacklist contacts from the JustCall account
list_callsread
list_calls_ai_analysisreadRetrieve AI-generated analysis for all calls associated with either JustCall or Sales Dialer
list_contactsreadRetrieve all contacts associated with the JustCall account
list_meetings_ai_analysisreadRetrieve AI-generated analysis for recorded meetings
list_numbersreadRetrieve all phone numbers associated with the JustCall account
list_salesdialer_callsreadRetrieve all calls made via the Sales Dialer in JustCall
list_salesdialer_campaign_contactsreadRetrieve all contacts in a specific Sales Dialer campaign identified by Campaign ID
list_salesdialer_campaignsreadRetrieve all Sales Dialer campaigns in the JustCall account
list_salesdialer_contactsreadRetrieve all contacts from Sales Dialer in the JustCall account
list_salesdialer_custom_fieldsreadFetch all custom contact fields defined in your Sales Dialer account and their details
list_smsreadRetrieve all sms/text messages associated with the JustCall account
list_sms_tagsreadRetrieve the list of all sms tags defined in the JustCall account
list_sms_threadsreadRetrieve all sms threads/conversations associated with a JustCall number
list_user_groupsreadRetrieve all user groups defined in the JustCall account
list_usersreadRetrieve all users associated with the JustCall account
list_voice_agentsreadRetrieve all AI voice agents associated with the JustCall account
list_webhooksreadRetrieve all configured webhooks
list_whatsapp_messagesreadRetrieve all whatsapp messages associated with the JustCall account
list_whatsapp_templatesreadRetrieve all whatsapp message templates available in the JustCall account
send_sms_mmswriteSend a new sms or text message or mms to a contact number
send_whatsapp_messagewriteSend a new whatsapp message to a contact number
update_callwriteUpdate/modify details of an existing call record identified by Call ID
update_contactwriteUpdate/modify details of an existing contact in the JustCall account
update_contact_statusdestructiveAdd or remove a contact from DND/DNM/Blacklist lists in the JustCall account
update_salesdialer_campaignwriteUpdate/modify details of an existing Sales Dialer campaign in the JustCall account
update_salesdialer_contactwriteUpdate/modify details of an existing contact in Sales Dialer identified by ID
update_user_availabilitywriteUpdate a user
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/dto/salesdialer/contacts.ts:57
callback_url?: string;
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/schema/salesdialer/contacts.ts:108
callback_url: z
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_sms_tag, update_contact_status
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/sdk/base-api.ts:2
import * as packageJson from "../../package.json";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/justcall/ai.ts:4
import { JustCallApiService } from "../../sdk/justcall.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/justcall/ai.ts:10
} from "../../schema/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/justcall/analytics.ts:4
import { JustCallApiService } from "../../sdk/justcall.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/justcall/analytics.ts:9
} from "../../schema/index.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, agents, axios, dotenv, rxjs, zod, @changesets/cli, @modelcontextprotocol/inspector
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
src/ui/calls-list/index.html
src/ui/calls-list/index.html
Why it matters. 1014833 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:20
6. It will open a JustCall page requesting API key and secret.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:31
6. It will open a JustCall page requesting API key and secret.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:43
6. It will open a JustCall page requesting API key and secret.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 69aca78ec6d0full audit observations/trust-audit/mcp-server/saaslabsco__justcall.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0969aca78ec6d0CAUTIONB89first audit
06

Questions

What is the JustCall MCP server?

JustCall's Official MCP Server

What tools does JustCall expose?

66 in total: 44 read-only, 20 that write, and 2 that can delete or overwrite (delete_sms_tag, update_contact_status). Every one is listed on this page with its risk.

Is JustCall safe to connect to an agent?

With care. The audit graded it B (89/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does JustCall need?

It reads JUSTCALL_API_KEY and JUSTCALL_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does JustCall run?

It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as @justcall/mcp-server at 1.2.3.

How current is this page?

The grade is for one exact copy of the source (69aca78ec6d0), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement