An MCP server for interaction with the Boomi API.
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
Glebuar
Source: mcp.so
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
BOOMI_MCP_GET_MODEBOOMI_MCP_IDENTITY_SALTBOOMI_RT_GRACE_SECONDSdefault 60. Window during which a just-BOOMI_RT_GRACE_MAX_SIZEdefault 512. LRU capacity for the grace cache.BOOMI_RT_GRACE_LOCK_TTL_SECONDSdefault 30. Auto-release safety bound.BOOMI_RT_GRACE_LOCK_POLL_MSdefault 100. Follower poll interval.HOSTNAMEBOOMI_RT_SLIDING_REFRESH_EXPIRYdefault true. When upstream omitsBOOMI_RT_SLIDING_REFRESH_TTL_SECONDSdefault 2592000 (30d). Sliding lifetime.BOOMI_RT_RECOVERY_MAX_AGE_SECONDSdefault 2592000 (30d, matches the slidingBOOMI_RT_RECOVERY_MAX_HOPSdefault 64 (scaled with the 30d window).BOOMI_RT_REFRESH_JWT_LEEWAY_SECONDSdefault 60. Clock-skew tolerance on theBOOMI_LOCALBOOMI_RT_GRACE_SHAREDdefault true. Backs the refresh-tokenBOOMI_RT_GRACE_SHARED_COLLECTIONdefault mcp-rt-grace.BOOMI_RT_RECOVERY_ENABLEDdefault true. Durable recovery of staleBOOMI_RT_RECOVERY_COLLECTIONdefault mcp-rt-recovery.STORAGE_ENCRYPTION_KEYFernet key(s) for encrypting OAuth tokens at rest.BOOMI_DOCS_ENABLEDRegistered only when the server starts with =true and aSECRETS_BACKENDexport =gcpGCP_PROJECT_IDexport =boomimcpOIDC_CLIENT_IDGoogle OAuth client IDOIDC_CLIENT_SECRETGoogle OAuth client secretOIDC_BASE_URLexport ="http://localhost:8080"JWT_SIGNING_KEYStable key for signing MCP JWT tokensBOOMI_OAUTH_DIAGNOSTICS_DISABLEdefault off (diagnostics ON). Set true toBOOMI_OAUTH_DIAGNOSTICSpatches. =falseMCP_HOSTMCP_PORTSESSION_SECRETSession signing key for web UIAWS_REGIONAWS_SECRET_PREFIXGCP_SECRET_PREFIXAZURE_KEY_VAULT_URLAZURE_SECRET_PREFIXBOOMI_DOCS_DB_PATHpopulated KB at :BOOMI_DOCS_COLLECTIONBOOMI_TOKEN_CACHE_DISABLEdefault off (cache ON). Set true toBOOMI_TOKEN_CACHE_TTL_SECONDSdefault 300. Upper bound on per-entryBOOMI_TOKEN_CACHE_MAX_SIZEdefault 256. LRU capacity.BOOMI_TOKEN_CACHE_SWRdefault false. Opt-in stale-while-BOOMI_TOKEN_CACHE_SWR_WINDOWdefault 30. Seconds before expiry atBOOMI_TOKEN_CACHE_STALE_IF_ERROR_SECONDSdefault 0 (off); Cloud Run pins =0MONGODB_URIPORTTool annotations
21/36 tools have annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
36/36 tools missing one or more hints — list_boomi_profiles (missing: destructiveHint, idempotentHint); boomi_account_info (missing: destructiveHint, idempotentHint); manage_trading_partner (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +33 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
34/36 tool handlers declare input schemas (94%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool handlers catch errors
30/36 tool handlers wrap calls in try/catch (83%)
Wrap each tool handler body in try/catch and return a structured error response.
Tests exist
No test files found
Add tests that exercise each declared tool.
No access to sensitive paths
Reads sensitive paths: credentials.html
Remove reads of sensitive system paths. If you genuinely need them, document why in the README.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/glebuar-boomi-mcp-server-1qi8np)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check