MCP server for the Keka HRM API, enabling HR operations like employee management, leave, attendance, payroll, recruitment, and PSA.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
process.env. You'll be asked to provide them before it can run.KEKA_API_KEY— ✅ API key from Keka adminKEKA_BASE_URL— ✅ Your Keka tenant URL, e.g. https://yourcompany.keka.comKEKA_CLIENT_ID— ✅ OAuth2 Client ID from Keka adminKEKA_CLIENT_SECRET— ✅ OAuth2 Client SecretKEKA_EMPLOYEE_ID— Optional Your own Keka employee ID — used as requestedBy when applying leave on behalf of othersKEKA_SANDBOX— Optional Set to true to use kekademo.com sandbox authKEKA_TIMEZONEPORT— Optional HTTP port when TRANSPORT=http (default: 3000)TRANSPORT— Optional stdio (default) or http[](https://m8ven.ai/mcp/huebnermarketing-keka-mcp-172hph)