Atlas / MCP servers / vapiai / Vapi

VapiSAFE

mcp/vapiai/vapi

Vapi MCP Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
14 9r · 5w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
57
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Build AI voice assistants and phone agents with Vapi using the Model Context Protocol.

Setup

The MCP server requires a Vapi API key. Get one from the Vapi dashboard.

Local Server (stdio)

Configure any MCP client that supports local stdio servers to run:

npx -y @vapi-ai/mcp-server

Set VAPI_TOKEN in the server environment. MCP client configuration formats vary, but the server definition generally looks like this:

{
"mcpServers": {
"vapi": {
"command": "npx",
"args": ["-y", "@vapi-ai/mcp-server"],
"env": {
"VAPI_TOKEN": ""
}
}
}
}

Remote Server (Streamable HTTP)

Clients that support remote MCP servers can connect directly:

  • URL: https://mcp.vapi.ai/mcp
  • Header: Authorization: Bearer your_vapi_api_key_here

Client-Specific Examples

Claude Code

claude mcp add -e VAPI_TOKEN=your_vapi_token vapi -- npx -y @vapi-ai/mcp-server

Claude Desktop

Use the local server configuration above in the Claude Desktop configuration file. To connect to the hosted server through an stdio bridge instead:

{
"mcpServers": {
"vapi": {
"command": "npx",
"args": [
"mcp-remote",
"https://mcp.vapi.ai/mcp",
"--header",
"Authorization: Bearer ${VAPI_TOKEN}"
],
"env": {
"VAPI_TOKEN": ""
}
}
}
}

Optional Agent Skill

The skill directory contains reusable instructions for AI coding agents that support Agent Skills. Install it using your host's skill installation process.

For Claude Code:

mkdir -p ~/.claude/skills/vapi
curl -o ~/.claude/skills/vapi/SKILL.md https://raw.githubusercontent.com/VapiAI/mcp-server/main/skill/SKILL.md

Example Usage

Create a Voice Assistant

Ask your MCP-enabled agent:

Read from source at commit 66ac59af48cbOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server --env VAPI_TOKEN=${VAPI_TOKEN} -- npx -y @vapi-ai/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@vapi-ai/[email protected]"
      ],
      "env": {
        "VAPI_TOKEN": "${VAPI_TOKEN}"
      }
    }
  }
}
03

Exposed tools (14)

9 read · 5 write · 0 destructive.

ToolRiskDescription
compatibility_toolreadCompatibility tool
create_assistantwriteCreates a new Vapi assistant
create_callwriteCreates a outbound call
create_toolwriteCreates a new Vapi tool
get_assistantreadGets a Vapi assistant by ID
get_callreadGets details of a specific call
get_phone_numberreadGets details of a specific phone number
get_toolreadGets details of a specific tool
list_assistantsread
list_callsread
list_phone_numbersread
list_toolsread
update_assistantwriteUpdates an existing Vapi assistant
update_toolwriteUpdates an existing Vapi tool
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/documentation-tools.test.ts:25
new URL(`../../${relativePath}`, import.meta.url),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/mcp-server-readonly-live.test.ts:13
readFileSync(new URL('../../package.json', import.meta.url), 'utf8')
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/mcp-stdio-compat.test.ts:9
readFileSync(new URL('../../package.json', import.meta.url), 'utf8')
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@vapi-ai/server-sdk, dotenv, zod, zod-to-json-schema, @types/jest, @types/node, jest, shx
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 66ac59af48cbfull audit observations/trust-audit/mcp-server/vapiai__vapi.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0866ac59af48cbSAFEB89first audit
06

Questions

What is the Vapi MCP server?

Vapi MCP Server

What tools does Vapi expose?

14 in total: 9 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Vapi safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Vapi need?

It reads VAPI_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Vapi run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @vapi-ai/mcp-server at 0.0.11.

How current is this page?

The grade is for one exact copy of the source (66ac59af48cb), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement