JustCallCAUTION
JustCall's Official MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The JustCall Model Context Protocol (MCP) Server lets Large Language Models (LLMs) and AI agents make real-world voice calls and send SMS directly through JustCall’s APIs — securely, contextually, and programmatically.
It provides a function-calling interface for conversational AI systems, enabling:
- 📞 AI-powered calling: Let your LLM initiate, manage, or transcribe calls using JustCall.
- 💬 Smart messaging: Allow your AI agent to send or respond to SMS within conversations.
- ⚙️ Seamless integration: Use the MCP standard to connect JustCall’s telephony capabilities with any LLM runtime or orchestration framework.
In short: It gives your LLMs a voice and a phone number — turning chatbots into truly conversational agents.
Claude Desktop Setup
- Open
Claude Desktopand pressCMD + ,to go toSettings. - Click on the
Connectorstab. - Click on the
Add Custom Connectorbutton. - Add name as
JustCalland Remote Server Url ashttps://mcp.justcall.host/mcp. - Now on
JustCallfrom the Connectors list click onConnectbutton for JustCall. - It will open a JustCall page requesting API key and secret.
- Get your JustCall API Key & Secret from the JustCall dashboard ().
- Enter the API key and Secret and press Continue, it should redirect back you to Claude.
Claude Web - https://claude.ai
- Open connectors url in your Browser - .
- Click on the
Connectorstab. - Click on the
Add Custom Connectorbutton. - Add name as
JustCalland Remote Server Url ashttps://mcp.justcall.host/mcp. - Now on
JustCallfrom the Connectors list click onConnectbutton for JustCall. - It will open a JustCall page requesting API key and secret.
- Get your JustCall API Key & Secret from the JustCall dashboard ().
- Enter the API key and Sec
69aca78ec6d0OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server --env JUSTCALL_API_KEY=${JUSTCALL_API_KEY} --env JUSTCALL_API_SECRET=${JUSTCALL_API_SECRET} -- npx -y @justcall/[email protected]{
"mcpServers": {
"mcp-server": {
"command": "npx",
"args": [
"-y",
"@justcall/[email protected]"
],
"env": {
"JUSTCALL_API_KEY": "${JUSTCALL_API_KEY}",
"JUSTCALL_API_SECRET": "${JUSTCALL_API_SECRET}"
}
}
}
}Exposed tools (66)
44 read · 20 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_contacts_blacklist | write | Add one or more contacts to the JustCall account |
add_salesdialer_campaign_contact | write | Add contact to a specific Sales Dialer campaign identified by Campaign ID |
add_salesdialer_contacts_dnca | write | Add one or more contacts to the Sales Dialer\ |
add_sms_thread_thread | write | Add tag to a sms thread/conversation identified by thread ID or combination of contact number and JustCall number |
check_sms_reply | read | Check for the most recent inbound sms/text message from a contact number |
check_whatsapp_message_reply | read | Check for the most recent inbound whatsapp message from a contact number |
create_appointment | write | Schedule a new appointment on a specific JustCall calendar |
create_contact | write | Create a new contact in the JustCall account |
create_salesdialer_campaign | write | Create a new Sales Dialer campaign in the JustCall account |
create_salesdialer_contact | write | Create a new contact in Sales Dialer |
create_sms_tag | write | Create a new sms tag in the JustCall account for tagging conversations |
create_voice_agent_call | write | Initiate an outbound call from a configured AI voice agent to a contact number |
create_webhook | write | Create a new webhook endpoint to receive real-time notifications |
delete_sms_tag | destructive | Delete a specific sms tag by ID |
get_account_analytics | read | Retrieve aggregated call analytics at the JustCall account level |
get_agent_analytics | read | Retrieve call performance analytics for a specific agent identified by Agent ID |
get_appointment | read | Retrieve details of a specific appointment by its ID |
get_call | read | |
get_call_ai_analysis | read | Retrieve AI-generated analysis for a specific call by Call ID associated with either JustCall or Sales Dialer |
get_call_journey | read | Fetch the sequence of events for a specific call identified by Call ID |
get_contact | read | Retrieve detailed information for a specific contact by ID |
get_meeting_ai_analysis | read | Retrieve AI-generated analysis for a specific meeting identified by Instance ID |
get_number | read | Retrieve detailed information for a specific phone number by ID |
get_number_analytics | read | Retrieve call analytics for a specific JustCall phone number |
get_salesdialer_agent_analytics | read | Retrieve call performance analytics of a specific agent for a Sales Dialer campaign |
get_salesdialer_call | read | Retrieve detailed information for a specific Sales Dialer call by Call ID |
get_salesdialer_campaign | read | Retrieve detailed information for a specific Sales Dialer campaign by ID |
get_salesdialer_contact | read | Retrieve detailed information for a specific contact in Sales Dialer by ID |
get_sms | read | Retrieve detailed information for a specific sms/text by ID |
get_sms_tag | read | Retrieve details of a specific sms tag by ID |
get_sms_thread | read | Retrieve a specific sms thread/conversation by ID |
get_user | read | Retrieve detailed information for a specific user by ID |
get_user_group | read | Retrieve detailed information for a specific user group by ID |
get_voice_agent_call | read | Retrieve voice agent related data for a specific call identified by Call ID |
get_whatsapp_message | read | Retrieve detailed information for a specific whatsapp message by ID |
import_salesdialer_contacts | write | Import multiple contacts into Sales Dialer or a campaign in bulk |
import_salesdialer_contacts_status | write | Check the status of a bulk import job/request by its batch ID |
list_appointment_slots | read | Retrieve all available time slots for appointments on a specific JustCall calendar |
list_blacklist_contacts | read | Retrieve all blacklist contacts from the JustCall account |
list_calls | read | |
list_calls_ai_analysis | read | Retrieve AI-generated analysis for all calls associated with either JustCall or Sales Dialer |
list_contacts | read | Retrieve all contacts associated with the JustCall account |
list_meetings_ai_analysis | read | Retrieve AI-generated analysis for recorded meetings |
list_numbers | read | Retrieve all phone numbers associated with the JustCall account |
list_salesdialer_calls | read | Retrieve all calls made via the Sales Dialer in JustCall |
list_salesdialer_campaign_contacts | read | Retrieve all contacts in a specific Sales Dialer campaign identified by Campaign ID |
list_salesdialer_campaigns | read | Retrieve all Sales Dialer campaigns in the JustCall account |
list_salesdialer_contacts | read | Retrieve all contacts from Sales Dialer in the JustCall account |
list_salesdialer_custom_fields | read | Fetch all custom contact fields defined in your Sales Dialer account and their details |
list_sms | read | Retrieve all sms/text messages associated with the JustCall account |
list_sms_tags | read | Retrieve the list of all sms tags defined in the JustCall account |
list_sms_threads | read | Retrieve all sms threads/conversations associated with a JustCall number |
list_user_groups | read | Retrieve all user groups defined in the JustCall account |
list_users | read | Retrieve all users associated with the JustCall account |
list_voice_agents | read | Retrieve all AI voice agents associated with the JustCall account |
list_webhooks | read | Retrieve all configured webhooks |
list_whatsapp_messages | read | Retrieve all whatsapp messages associated with the JustCall account |
list_whatsapp_templates | read | Retrieve all whatsapp message templates available in the JustCall account |
send_sms_mms | write | Send a new sms or text message or mms to a contact number |
send_whatsapp_message | write | Send a new whatsapp message to a contact number |
update_call | write | Update/modify details of an existing call record identified by Call ID |
update_contact | write | Update/modify details of an existing contact in the JustCall account |
update_contact_status | destructive | Add or remove a contact from DND/DNM/Blacklist lists in the JustCall account |
update_salesdialer_campaign | write | Update/modify details of an existing Sales Dialer campaign in the JustCall account |
update_salesdialer_contact | write | Update/modify details of an existing contact in Sales Dialer identified by ID |
update_user_availability | write | Update a user |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
callback_url?: string;
callback_url: z
delete_sms_tag, update_contact_status
.prettierignore
import * as packageJson from "../../package.json";
import { JustCallApiService } from "../../sdk/justcall.js";} from "../../schema/index.js";
import { JustCallApiService } from "../../sdk/justcall.js";} from "../../schema/index.js";
@modelcontextprotocol/sdk, agents, axios, dotenv, rxjs, zod, @changesets/cli, @modelcontextprotocol/inspector
src/ui/calls-list/index.html
6. It will open a JustCall page requesting API key and secret.
6. It will open a JustCall page requesting API key and secret.
6. It will open a JustCall page requesting API key and secret.
Gates applied: no_behavioural_pass.
69aca78ec6d0full audit observations/trust-audit/mcp-server/saaslabsco__justcall.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 69aca78ec6d0 | CAUTION | B | 89 | first audit |
Questions
What is the JustCall MCP server?
JustCall's Official MCP Server
What tools does JustCall expose?
66 in total: 44 read-only, 20 that write, and 2 that can delete or overwrite (delete_sms_tag, update_contact_status). Every one is listed on this page with its risk.
Is JustCall safe to connect to an agent?
With care. The audit graded it B (89/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does JustCall need?
It reads JUSTCALL_API_KEY and JUSTCALL_API_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does JustCall run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as @justcall/mcp-server at 1.2.3.
How current is this page?
The grade is for one exact copy of the source (69aca78ec6d0), read on 2026-10-09. The repository is watched and re-audited when it changes.