Atlas / MCP servers / willdent / Pipedrive

PipedriveSAFE

mcp/willdent/pipedrive-3

Secure, self-hosted MCP server for Pipedrive CRM with v2 read tools, optional preview-first writes, stdio/HTTP transports, and Docker support.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
18 16r · 2w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
60
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A single-tenant, self-hosted Model Context Protocol server for Pipedrive. Version 2.x uses Pipedrive API v2 for deals, persons, organizations, pipelines, stages, leads, and item search. Notes and users remain isolated behind clearly scoped v1 adapters because Pipedrive has not moved those APIs to v2.

The server is read-only by default. Two narrowly scoped write tools can be enabled explicitly and remain preview-first.

Requirements

  • Node.js 22 or 24 (Node 24 recommended)
  • A Pipedrive API token

PIPEDRIVE_DOMAIN is not used. The official Pipedrive client supplies the API base URL.

Install and run with stdio

Install globally:

npm install --global pipedrive-mcp-server
PIPEDRIVE_API_TOKEN=your-token pipedrive-mcp-server

Or build this repository:

npm ci
npm run check
PIPEDRIVE_API_TOKEN=your-token npm start

Example desktop MCP configuration:

{
"mcpServers": {
"pipedrive": {
"command": "pipedrive-mcp-server",
"env": {
"PIPEDRIVE_API_TOKEN": "your-token"
}
}
}
}

Streamable HTTP

The modern HTTP endpoint defaults to http://127.0.0.1:3000/mcp:

PIPEDRIVE_API_TOKEN=your-token \
MCP_TRANSPORT=http \
pipedrive-mcp-server

GET /health is unauthenticated, host-validated, and returns only service status. The server creates an independent MCP server and transport for every session and closes active sessions during shutdown.

Binding to a non-loopback address requires both an HS256 JWT secret of at least 32 characters and an explicit hostname allowlist:

PIPEDRIVE_API_TOKEN=your-token \
MCP_TRANSPORT=http \
MCP_HOST=0.0.0.0 \
MCP_ALLOWED_HOSTS=mcp.example.com \
MCP_ALLOWED_ORIGINS=https://app.example.com \
MCP_JWT_SECRET='replace-with-at-least-32-random-characters' \
pipedrive-mcp-server

The built-in HTTP server does not terminate TLS. Never expose it directly on an untrusted network: place it behind a trusted HTTPS reverse proxy, keep

Read from source at commit dfc67b558e59OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add pipedrive-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "pipedrive-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (18)

16 read · 2 write · 0 destructive.

ToolRiskDescription
add-deal-notewrite
get-dealread
get-deal-notesread
get-dealsread
get-organizationread
get-organizationsread
get-personread
get-personsread
get-pipelineread
get-pipelinesread
get-stagesread
get-usersread
move-dealwrite
search-allread
search-dealsread
search-leadsread
search-organizationsread
search-personsread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:43
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 CMD ["node", "-e", "if(!['http','sse'].includes(process.env.MCP_TRANSPORT||'stdio'))process.exit(0);fetch('http://127.0.0.1:'+(pr
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
readme.md:48
The modern HTTP endpoint defaults to `http://127.0.0.1:3000/mcp`:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/transports.test.ts:30
const health = await fetch(`http://127.0.0.1:${running.port}/health`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/transports.test.ts:37
await client.connect(new StreamableHTTPClientTransport(new URL(`http://127.0.0.1:${running.port}/mcp`)));
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/transports.test.ts:51
const response = await fetch(`http://127.0.0.1:${running.port}/mcp`, {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, bottleneck, jsonwebtoken, pipedrive, zod, @types/jsonwebtoken, @types/node
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha dfc67b558e59full audit observations/trust-audit/mcp-server/willdent__pipedrive-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08dfc67b558e59SAFEB89first audit
06

Questions

What is the Pipedrive MCP server?

Secure, self-hosted MCP server for Pipedrive CRM with v2 read tools, optional preview-first writes, stdio/HTTP transports, and Docker support.

What tools does Pipedrive expose?

18 in total: 16 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pipedrive safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Pipedrive need?

No credential environment variables were found in its source, so it appears to need none.

How does Pipedrive run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as pipedrive-mcp-server at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (dfc67b558e59), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement