Atlas / MCP servers / tomtom-international / TomTom

TomTomCAUTION

mcp/tomtom-international/tomtom

A Model Context Protocol (MCP) server providing TomTom's location services, search, routing, and traffic data to AI agents.

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
14 14r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
56
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@tomtom-org/tomtom-mcp) [](https://opensource.org/licenses/Apache-2.0)

The TomTom Maps MCP Server simplifies geospatial development by providing seamless access to TomTom’s location services, including search, routing, traffic and interactive maps. It enables easy integration of precise and accurate geolocation data into AI workflows and development environments.

Demo

Table of Contents

  • Demo
  • Security Notice
  • Remote MCP Server (No Installation Required)
  • Quick Start
  • Prerequisites
  • Installation
  • Configuration
  • Usage
  • Integration Guides
  • Available Tools
  • How dynamic map tool works
  • Getting geometry out of a tool response
  • Debug UI
  • Local Development
  • Setup
  • Testing
  • Testing Requirements
  • Project Structure
  • Troubleshooting
  • API Key Issues
  • Test Failures
  • Build Issues
  • Contributing \& Feedback
  • Security
  • License

Remote MCP Server (No Installation Required)

Public Preview — The TomTom Maps Remote MCP Server is currently in public preview.

The easiest way to get started is to connect directly to TomTom's hosted MCP Server — no Node.js, Docker, or local setup needed.

Endpoint:

https://mcp.tomtom.com/maps

Prerequisites:

  • A valid TomTo
Read from source at commit 5871729d4e11OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add tomtom-mcp-app-host --env AUTHORIZATION_SERVER_URL=${AUTHORIZATION_SERVER_URL} --env TOMTOM_API_KEY=${TOMTOM_API_KEY} --env ULS_TOKEN_ENDPOINT=${ULS_TOKEN_ENDPOINT} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "tomtom-mcp-app-host": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AUTHORIZATION_SERVER_URL": "${AUTHORIZATION_SERVER_URL}",
        "TOMTOM_API_KEY": "${TOMTOM_API_KEY}",
        "ULS_TOKEN_ENDPOINT": "${ULS_TOKEN_ENDPOINT}"
      }
    }
  }
}
03

Exposed tools (14)

14 read · 0 write · 0 destructive.

ToolRiskDescription
tomtom-area-searchreadarea-search: renders boundary polygon and pins, shows POI popup on click
tomtom-data-vizreaddata-viz: renders data visualization with title overlay
tomtom-dynamic-mapreaddynamic-map: renders marker at Amsterdam, shows popup on click
tomtom-ev-searchreadev-search: renders EV station markers, shows POI popup on click
tomtom-fuzzy-searchreadfuzzy-search: renders search results, shows POI popup on marker click
tomtom-geocodereadgeocode: renders map with pins, shows POI popup on marker click
tomtom-nearbyreadnearby: renders nearby places, shows POI popup on marker click
tomtom-poi-categoriesreadLook up POI category codes from natural language. The poiCategories parameter of the search tools accepts only codes returned by this tool.
tomtom-poi-searchreadpoi-search: renders POI markers, shows popup on click
tomtom-reachable-rangereadreachable-range: renders the requested range with budget controls
tomtom-reverse-geocodereadreverse-geocode: renders location pin, shows POI popup on click
tomtom-routingreadrouting: renders route on map with waypoint markers
tomtom-search-along-routereadsearch-along-route: renders route with POI markers, shows popup on click
tomtom-trafficreadtraffic: renders live traffic flow with auto-opened incident popup
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (24)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/coding-guidelines
.claude/skills/coding-guidelines
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/mcp-builder
.claude/skills/mcp-builder
Why it matters. link not followed
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/testClientMetadata.ts:47
"http://127.0.0.1:6274/oauth/callback",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/data-viz/byod/app.ts:27
import { createMapControls } from "../../shared/map-controls";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/data-viz/byod/app.ts:28
import { shouldShowUI, showMapUI, hideMapUI, showErrorUI } from "../../shared/ui-visibility";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/data-viz/byod/app.ts:29
import { extractFullData } from "../../shared/decompress";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/data-viz/byod/app.ts:30
import { ensureTomTomConfigured } from "../../shared/sdk-config";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/apps/data-viz/byod/app.ts:31
import { injectPoiPopupStyles } from "../../shared/poi-popup";
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/handlers/dataVizHandler.test.ts:749
["link-local / cloud metadata", "169.254.169.254"],
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/shared/scenarios.js:33
data_url: "https://169.254.169.254/latest/meta-data/",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
e2e/mapWorker.spec.ts:93
appUrl = `http://127.0.0.1:${(server.address() as AddressInfo).port}/app.html`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/testClientMetadata.test.ts:50
"http://127.0.0.1:6274/oauth/callback",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/testClientMetadata.test.ts:52
"http://127.0.0.1:6274/oauth/callback/debug",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/auth/testClientMetadata.test.ts:53
"http://127.0.0.1:8976/cb",
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
ui/src/implementation.ts:160
const html = "blob" in content ? atob(content.blob as string) : (content as any).text;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.agents/skills/mcp-builder/scripts/requirements.txt
anthropic, mcp
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, @turf/buffer, @types/geojson, axios, compression, cors, dotenv
Why it matters. 37 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
ui/package.json
@modelcontextprotocol/ext-apps, @modelcontextprotocol/sdk, dotenv, react, react-dom, @types/express, @types/node, @types/react
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/veracode-findings-triage.md:44
| 23 | Med | CWE-201 | `src/utils/http.ts`, `fetch()` | By design | The single `fetch` the three auth calls now share (PR #306). Supersedes #4 and the equivalent `tokenExchanger` / `mcpProjectResolver
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
images/claude_demo.gif
images/claude_demo.gif
Why it matters. 53452057 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:132
4. Select all available APIs to ensure full access, assign a name to your key, and click **Create**.
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:54
- A valid TomTom API key with MCP Server access enabled (see [API Key Management](https://developer.tomtom.com/platform/documentation/dashboard/api-key-management))
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:427
cat .env             # Check API key
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 5871729d4e11full audit observations/trust-audit/mcp-server/tomtom-international__tomtom.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-085871729d4e11CAUTIONB85first audit
06

Questions

What is the TomTom MCP server?

A Model Context Protocol (MCP) server providing TomTom's location services, search, routing, and traffic data to AI agents.

What tools does TomTom expose?

14 in total: 14 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is TomTom safe to connect to an agent?

With care. The audit graded it B (85/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does TomTom need?

It reads AUTHORIZATION_SERVER_URL, TOMTOM_API_KEY and ULS_TOKEN_ENDPOINT from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does TomTom run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as tomtom-mcp-app-host at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (5871729d4e11), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement