F
Warning
0/100
1 month ago

Boomi MCP Server

An MCP server for interaction with the Boomi API.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

Glebuar

Source: mcp.so

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Reads files from sensitive locations
Touches: credentials.html
🔐
You'll be asked for 4 credentials: STORAGE_ENCRYPTION_KEY, OIDC_CLIENT_SECRET, JWT_SIGNING_KEY, SESSION_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configBOOMI_MCP_GET_MODE
configBOOMI_MCP_IDENTITY_SALT
configBOOMI_RT_GRACE_SECONDSdefault 60. Window during which a just-
configBOOMI_RT_GRACE_MAX_SIZEdefault 512. LRU capacity for the grace cache.
configBOOMI_RT_GRACE_LOCK_TTL_SECONDSdefault 30. Auto-release safety bound.
configBOOMI_RT_GRACE_LOCK_POLL_MSdefault 100. Follower poll interval.
configHOSTNAME
configBOOMI_RT_SLIDING_REFRESH_EXPIRYdefault true. When upstream omits
configBOOMI_RT_SLIDING_REFRESH_TTL_SECONDSdefault 2592000 (30d). Sliding lifetime.
configBOOMI_RT_RECOVERY_MAX_AGE_SECONDSdefault 2592000 (30d, matches the sliding
configBOOMI_RT_RECOVERY_MAX_HOPSdefault 64 (scaled with the 30d window).
configBOOMI_RT_REFRESH_JWT_LEEWAY_SECONDSdefault 60. Clock-skew tolerance on the
configBOOMI_LOCAL
configBOOMI_RT_GRACE_SHAREDdefault true. Backs the refresh-token
configBOOMI_RT_GRACE_SHARED_COLLECTIONdefault mcp-rt-grace.
configBOOMI_RT_RECOVERY_ENABLEDdefault true. Durable recovery of stale
configBOOMI_RT_RECOVERY_COLLECTIONdefault mcp-rt-recovery.
🔐 secretSTORAGE_ENCRYPTION_KEYFernet key(s) for encrypting OAuth tokens at rest.
configBOOMI_DOCS_ENABLEDRegistered only when the server starts with =true and a
configSECRETS_BACKENDexport =gcp
configGCP_PROJECT_IDexport =boomimcp
configOIDC_CLIENT_IDGoogle OAuth client ID
🔐 secretOIDC_CLIENT_SECRETGoogle OAuth client secret
configOIDC_BASE_URLexport ="http://localhost:8080"
🔐 secretJWT_SIGNING_KEYStable key for signing MCP JWT tokens
configBOOMI_OAUTH_DIAGNOSTICS_DISABLEdefault off (diagnostics ON). Set true to
configBOOMI_OAUTH_DIAGNOSTICSpatches. =false
configMCP_HOST
configMCP_PORT
🔐 secretSESSION_SECRETSession signing key for web UI
configAWS_REGION
configAWS_SECRET_PREFIX
configGCP_SECRET_PREFIX
configAZURE_KEY_VAULT_URL
configAZURE_SECRET_PREFIX
configBOOMI_DOCS_DB_PATHpopulated KB at :
configBOOMI_DOCS_COLLECTION
configBOOMI_TOKEN_CACHE_DISABLEdefault off (cache ON). Set true to
configBOOMI_TOKEN_CACHE_TTL_SECONDSdefault 300. Upper bound on per-entry
configBOOMI_TOKEN_CACHE_MAX_SIZEdefault 256. LRU capacity.
configBOOMI_TOKEN_CACHE_SWRdefault false. Opt-in stale-while-
configBOOMI_TOKEN_CACHE_SWR_WINDOWdefault 30. Seconds before expiry at
configBOOMI_TOKEN_CACHE_STALE_IF_ERROR_SECONDSdefault 0 (off); Cloud Run pins =0
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployMONGODB_URI
deployPORT
// quality suggestions

Tool annotations

21/36 tools have annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

36/36 tools missing one or more hints — list_boomi_profiles (missing: destructiveHint, idempotentHint); boomi_account_info (missing: destructiveHint, idempotentHint); manage_trading_partner (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +33 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

34/36 tool handlers declare input schemas (94%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

30/36 tool handlers wrap calls in try/catch (83%)

Wrap each tool handler body in try/catch and return a structured error response.

Tests exist

No test files found

Add tests that exercise each declared tool.

No access to sensitive paths

Reads sensitive paths: credentials.html

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/glebuar-boomi-mcp-server-1qi8np?variant=verified)](https://m8ven.ai/mcp/glebuar-boomi-mcp-server-1qi8np)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: c2f088b6fbe993fec6f18fe410f7520aced9d41e
code hash: c6fa2b1743573b1bee73811a76cdf5b6a7669e0489f32f0192e46ec36090f20a
verified: 6/27/2026, 8:59:10 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client