Atlas / MCP servers / team-telnyx / Telnyx

TelnyxCAUTION

mcp/team-telnyx/telnyx

Official Telnyx Local Model Context Protocol (MCP) Server that enables interaction with powerful telephony, messaging, and AI assistant APIs. This server allows MCP clients like Claude Desktop, Cursor, Windsurf, OpenAI Agents and others to manage phone numbers, send messages, make calls, and create

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
46 24r · 19w · 3d
Transport
—
License
—
Stars
25
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚠️ DEPRECATED: This Python-based MCP server is deprecated. Please migrate to the official TypeScript version: New Repository: https://github.com/team-telnyx/telnyx-node/tree/master/packages/mcp-server

Official Telnyx Local Model Context Protocol (MCP) Server that enables interaction with powerful telephony, messaging, and AI assistant APIs. This server allows MCP clients like Claude Desktop, Cursor, Windsurf, OpenAI Agents and others to manage phone numbers, send messages, make calls, and create AI assistants.

Quickstart with Claude Desktop

  1. Get your API key from the Telnyx Portal.
  2. Install uvx (Python package manager), install with curl -LsSf https://astral.sh/uv/install.sh | sh , brew install uv or see the uv repo for additional install methods.
  3. Go to Claude > Settings > Developer > Edit Config > claudedesktopconfig.json to include the following:
{
"mcpServers": {
"Telnyx": {
"command": "uvx",
"args": ["--from", "git+https://github.com/team-telnyx/telnyx-mcp-server.git", "telnyx-mcp-server"],
"env": {
"TELNYX_API_KEY": ""
}
}
}
}

If you're using Windows, you will have to enable "Developer Mode" in Claude Desktop to use the MCP server. Click "Help" in the hamburger menu at the top left and select "Enable Developer Mode".

Running After Download

  1. Get your API key from the Telnyx Portal.
  1. Install uvx (Python package manager), install with curl -LsSf https://astral.sh/uv/install.sh | sh , brew install uv or see the uv repo for additional install methods.
  1. Clone the Git Repository

Use Git to download the Telnyx MCP Server locally:

git clone https://github.com/team-telnyx/telnyx-mcp-server.git
cd telnyx-mcp-server
  1. Configure and Run with uvx

In your Claud

Read from source at commit 4ebe6df11cdcOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add telnyx-mcp-server --env NGROK_AUTHTOKEN=${NGROK_AUTHTOKEN} --env TELNYX_API_KEY=${TELNYX_API_KEY} -- uvx telnyx-mcp-server
claude-desktop
{
  "mcpServers": {
    "telnyx-mcp-server": {
      "command": "uvx",
      "args": [
        "telnyx-mcp-server"
      ],
      "env": {
        "NGROK_AUTHTOKEN": "${NGROK_AUTHTOKEN}",
        "TELNYX_API_KEY": "${TELNYX_API_KEY}"
      }
    }
  }
}
03

Exposed tools (46)

24 read · 19 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cloud_storage_create_bucketwriteCreate a new bucket.
cloud_storage_delete_objectdestructiveDelete an object from cloud storage.
cloud_storage_download_filereadDownload a file from cloud storage.
cloud_storage_get_bucket_locationreadGet the region where a bucket is located.
cloud_storage_list_bucketsreadList all buckets across all regions.
cloud_storage_list_objectsreadList objects in a bucket with optional prefix filtering.
cloud_storage_upload_filewriteUpload a file to cloud storage.
create_assistantwriteCreate a new AI Assistant. The user will provide some details (sometimes
create_call_control_applicationwriteCreate a call control application.
create_embeddingswriteEmbed a bucket that containe files.
create_integration_secretwriteCreate an integration secret.
create_messaging_profilewriteCreate a messaging profile.
delete_integration_secretdestructiveDelete an integration secret.
embed_urlreadScrape and embed a given URL. For a given website, this tool will scrape
get_assistantreadGet an AI Assistant by ID.
get_assistant_texmlreadGet an assistant
get_call_control_applicationreadRetrieve a specific call control application.
get_connectionreadGet a connection by ID.
get_messagereadRetrieve a message by ID.
get_messaging_profilereadRetrieve a messaging profile by ID.
get_phone_numberreadGet a phone number by ID.
get_webhook_eventsread
hangupreadHang up a call.
initiate_phone_number_orderwriteInitiate a phone number order.
list_assistantsreadList all AI Assistants.
list_available_phone_numbersreadList available phone numbers.
list_call_control_applicationsreadList call control applications.
list_connectionsreadList connections.
list_embedded_bucketsreadList user embedded buckets.
list_integration_secretsreadList integration secrets.
list_messaging_profilesreadList messaging profiles.
list_phone_numbersreadList phone numbers.
make_callreadMake a call.
mcp_telnyx_delete_assistantdestructiveDelete an AI Assistant.
playback_startwriteStart audio playback on a call.
playback_stopwriteStop audio playback on a call.
send_dtmfwriteSend DTMF tones on a call.
send_messagewriteSend a message.
speakreadSpeak text on a call using text-to-speech.
start_assistant_callwriteStart a call using an AI Assistant with a phone number.
transferwriteTransfer a call to a new destination.
update_assistantwriteUpdate an AI Assistant. Once there is an agent created, you can talk the
update_connectionwriteUpdate a connection.
update_messaging_profilewriteUpdate a messaging profile.
update_phone_numberwriteUpdate a phone number.
update_phone_number_messaging_settingswriteUpdate the messaging profile and/or messaging product of a phone number.
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
README.md:271
<img width="704" alt="Screenshot Webhook" src="https://github.com/user-attachments/assets/2e1f4a47-df24-4e35-acdf-765ef4a71578" />
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cloud_storage_delete_object, delete_integration_secret, mcp_telnyx_delete_assistant
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
fastapi, ngrok
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:14
2. Install `uvx` (Python package manager), install with `curl -LsSf https://astral.sh/uv/install.sh | sh` , `brew install uv` or see the `uv` repo for additional install methods.
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:37
2. Install `uvx` (Python package manager), install with `curl -LsSf https://astral.sh/uv/install.sh | sh` , `brew install uv` or see the `uv` repo for additional install methods.

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-09 · audit v0.4.1 · source sha 4ebe6df11cdcfull audit observations/trust-audit/mcp-server/team-telnyx__telnyx.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-094ebe6df11cdcCAUTIONB84first audit
06

Questions

What is the Telnyx MCP server?

Official Telnyx Local Model Context Protocol (MCP) Server that enables interaction with powerful telephony, messaging, and AI assistant APIs. This server allows MCP clients like Claude Desktop, Cursor, Windsurf, OpenAI Agents and others to manage phone numbers, send messages, make calls, and create

What tools does Telnyx expose?

46 in total: 24 read-only, 19 that write, and 3 that can delete or overwrite (cloud_storage_delete_object, delete_integration_secret, mcp_telnyx_delete_assistant). Every one is listed on this page with its risk.

Is Telnyx safe to connect to an agent?

With care. The audit graded it B (84/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Telnyx need?

It reads NGROK_AUTHTOKEN and TELNYX_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (4ebe6df11cdc), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement