SquareSAFE
A Model Context Protocol (MCP) server for square
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This project follows the Model Context Protocol standard, allowing AI assistants to interact with Square's connect API.
Quick Start
Get up and running with the Square MCP server using npx:
# Basic startup npx square-mcp-server start # With environment configuration ACCESS_TOKEN=YOUR_SQUARE_ACCESS_TOKEN SANDBOX=true npx square-mcp-server start # local runs npx /path/to/project/square-mcp-server
Replace YOUR_SQUARE_ACCESS_TOKEN with your actual Square access token. You can obtain your access token by following the guide at Square Access Tokens. You can also set environment variables before running the command.
Remote MCP Server
Square now offers a hosted remote MCP server at:
https://mcp.squareup.com/sse
The remote MCP is recommended as it uses OAuth authentication, allowing you to log in with your Square account directly without having to create or manage access tokens manually.
Configuration Options
Integration with AI Assistants
Goose Integration
To configure the Square MCP Server with Goose:
Remote MCP
To install the Square remote MCP in Goose,
be19424f2ba3OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add square-mcp-server --env ACCESS_TOKEN=${ACCESS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"square-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ACCESS_TOKEN": "${ACCESS_TOKEN}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_service_info | read | Get information about a Square API service. Call me before trying to get type info |
get_type_info | read | Get type information for a Square API method. You must call this before calling the make_api_request tool. |
make_api_request | read | Unified tool for all Square API operations. Be sure to get types before calling. Available services: ${Object.keys(serviceMethodsMap).map(name => name.toLowerCase()).join( |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@modelcontextprotocol/sdk, commander, cors, dotenv, escape-html, express, form-data, node-fetch
utils/type-map.ts
Gates applied: no_behavioural_pass.
be19424f2ba3full audit observations/trust-audit/mcp-server/square__square-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | be19424f2ba3 | SAFE | B | 89 | first audit |
Questions
What is the Square MCP server?
A Model Context Protocol (MCP) server for square
What tools does Square expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Square safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Square need?
It reads ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Square run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as square-mcp-server at 0.1.2.
How current is this page?
The grade is for one exact copy of the source (be19424f2ba3), read on 2026-10-07. The repository is watched and re-audited when it changes.