PipedriveSAFE
Secure, self-hosted MCP server for Pipedrive CRM with v2 read tools, optional preview-first writes, stdio/HTTP transports, and Docker support.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A single-tenant, self-hosted Model Context Protocol server for Pipedrive. Version 2.x uses Pipedrive API v2 for deals, persons, organizations, pipelines, stages, leads, and item search. Notes and users remain isolated behind clearly scoped v1 adapters because Pipedrive has not moved those APIs to v2.
The server is read-only by default. Two narrowly scoped write tools can be enabled explicitly and remain preview-first.
Requirements
- Node.js 22 or 24 (Node 24 recommended)
- A Pipedrive API token
PIPEDRIVE_DOMAIN is not used. The official Pipedrive client supplies the API base URL.
Install and run with stdio
Install globally:
npm install --global pipedrive-mcp-server PIPEDRIVE_API_TOKEN=your-token pipedrive-mcp-server
Or build this repository:
npm ci npm run check PIPEDRIVE_API_TOKEN=your-token npm start
Example desktop MCP configuration:
{
"mcpServers": {
"pipedrive": {
"command": "pipedrive-mcp-server",
"env": {
"PIPEDRIVE_API_TOKEN": "your-token"
}
}
}
}Streamable HTTP
The modern HTTP endpoint defaults to http://127.0.0.1:3000/mcp:
PIPEDRIVE_API_TOKEN=your-token \ MCP_TRANSPORT=http \ pipedrive-mcp-server
GET /health is unauthenticated, host-validated, and returns only service status. The server creates an independent MCP server and transport for every session and closes active sessions during shutdown.
Binding to a non-loopback address requires both an HS256 JWT secret of at least 32 characters and an explicit hostname allowlist:
PIPEDRIVE_API_TOKEN=your-token \ MCP_TRANSPORT=http \ MCP_HOST=0.0.0.0 \ MCP_ALLOWED_HOSTS=mcp.example.com \ MCP_ALLOWED_ORIGINS=https://app.example.com \ MCP_JWT_SECRET='replace-with-at-least-32-random-characters' \ pipedrive-mcp-server
The built-in HTTP server does not terminate TLS. Never expose it directly on an untrusted network: place it behind a trusted HTTPS reverse proxy, keep
dfc67b558e59OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add pipedrive-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"pipedrive-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (18)
16 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add-deal-note | write | |
get-deal | read | |
get-deal-notes | read | |
get-deals | read | |
get-organization | read | |
get-organizations | read | |
get-person | read | |
get-persons | read | |
get-pipeline | read | |
get-pipelines | read | |
get-stages | read | |
get-users | read | |
move-deal | write | |
search-all | read | |
search-deals | read | |
search-leads | read | |
search-organizations | read | |
search-persons | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 CMD ["node", "-e", "if(!['http','sse'].includes(process.env.MCP_TRANSPORT||'stdio'))process.exit(0);fetch('http://127.0.0.1:'+(prThe modern HTTP endpoint defaults to `http://127.0.0.1:3000/mcp`:
const health = await fetch(`http://127.0.0.1:${running.port}/health`);await client.connect(new StreamableHTTPClientTransport(new URL(`http://127.0.0.1:${running.port}/mcp`)));const response = await fetch(`http://127.0.0.1:${running.port}/mcp`, {@modelcontextprotocol/sdk, dotenv, bottleneck, jsonwebtoken, pipedrive, zod, @types/jsonwebtoken, @types/node
Gates applied: no_behavioural_pass.
dfc67b558e59full audit observations/trust-audit/mcp-server/willdent__pipedrive-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | dfc67b558e59 | SAFE | B | 89 | first audit |
Questions
What is the Pipedrive MCP server?
Secure, self-hosted MCP server for Pipedrive CRM with v2 read tools, optional preview-first writes, stdio/HTTP transports, and Docker support.
What tools does Pipedrive expose?
18 in total: 16 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pipedrive safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Pipedrive need?
No credential environment variables were found in its source, so it appears to need none.
How does Pipedrive run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as pipedrive-mcp-server at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (dfc67b558e59), read on 2026-10-08. The repository is watched and re-audited when it changes.