A hosted, multi-tenant MCP server that exposes the Kitchen.co client-portal API to AI clients, enabling natural language interaction with tasks, documents, clients, invoices, and more.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
process.env. You'll be asked to provide them before it can run.ALLOWED_ORIGINS— e =https://claude.ai \HTTP_RATE_LIMIT_PER_MINUTEKITCHEN_API_KEY— Both Kitchen headers may instead be supplied via the / KITCHEN_WORKSPACE env vars for single-tenant deployments.KITCHEN_WEBHOOK_FORWARD_TOKEN— 3. (Optional) Set KITCHEN_WEBHOOK_FORWARD_URL if your actual handler lives elsewhere. The verifier POSTs the verified event JSON to that URL with an optional X-Forward-Token header ().KITCHEN_WEBHOOK_FORWARD_URL— 3. (Optional) Set if your actual handler lives elsewhere. The verifier POSTs the verified event JSON to that URL with an optional X-Forward-Token header (KITCHEN_WEBHOOK_FORWARD_TOKEN).KITCHEN_WEBHOOK_SECRETS— This server also runs a verified Kitchen-webhook ingress at POST /webhooks/kitchen. It is off by default — enable it by setting .KITCHEN_WORKSPACE— Both Kitchen headers may instead be supplied via the KITCHEN_API_KEY / env vars for single-tenant deployments.LOG_LEVELMCP_GATE_TOKEN— e =$(openssl rand -hex 32) \PORT— Standard Node web service — set , ALLOWED_ORIGINS, MCP_GATE_TOKEN, run npm start.TRUST_PROXY— set-env-vars==1 \[](https://m8ven.ai/mcp/horatio8-kitchenmcp-1dxcmg)