33
/ 100
1 month ago
glama

Nexian MCP Hub

A multi-tenant integration platform that connects MSP systems like HaloPSA, Microsoft 365, and HubSpot to a single remote MCP server. It provides normalized, AI-safe tools for managing third-party services with built-in security policies and audit logging.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: API_URL. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 7 credentials: ACTIONSTEP_CLIENT_SECRET, HALOPSA_CLIENT_SECRET, INTERNAL_MCP_SHARED_SECRET, MCP_OAUTH_CLIENT_SECRET, NINJAONE_CLIENT_SECRET, OAUTH_STATE_SIGNING_SECRET, SESSION_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 medium1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

mediumturbo@2.0.14GHSA-hcf7-66rw-9f5r

Trubo: Login callback CSRF/session fixation

lowturbo@2.0.14GHSA-3qcw-2rhx-2726

Turbo: Unexpected local code execution during Yarn Berry detection

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configACTIONSTEP_CLIENT_ID
🔐 secretACTIONSTEP_CLIENT_SECRET
configACTIONSTEP_ENV
configACTIONSTEP_REDIRECT_URI
configACTIONSTEP_SCOPES
configAPI_URLshould be your Railway API URL
configAPP_URLshould be your Vercel web URL
configDATABASE_URL
configHALOPSA_BASE_URL
configHALOPSA_CLIENT_ID
🔐 secretHALOPSA_CLIENT_SECRET
configHALOPSA_REDIRECT_URIshould point to the Railway API callback URL
configHALOPSA_SCOPES
configHALOPSA_URL
configHALO_DEBUG
configHALO_MAX_RETRIES
configHALO_TIMEOUT_MS
configHUBSPOT_CLIENT_ID
🔐 secretINTERNAL_MCP_SHARED_SECRET
configMCP_AUTH_MODE
configMCP_DEFAULT_ROLES
configMCP_DEFAULT_TENANT_ID
configMCP_DEFAULT_USER_ID
configMCP_OAUTH_CLIENT_ID
🔐 secretMCP_OAUTH_CLIENT_SECRET
configMCP_OAUTH_REDIRECT_URIS
configMCP_OAUTH_SCOPES
configMCP_PORT
configMCP_URLshould be your Railway MCP URL
configMS365_CLIENT_ID
configNEXT_PUBLIC_API_URLin Vercel should point to the Railway API URL
configNEXT_PUBLIC_MCP_URLin Vercel should point to the Railway MCP endpoint URL
configNINJAONE_AUTH_URL
configNINJAONE_BASE_URL
configNINJAONE_CLIENT_ID
🔐 secretNINJAONE_CLIENT_SECRET
configNINJAONE_REDIRECT_URI
configNINJAONE_SCOPES
configNINJAONE_URL
configNINJA_DEBUG
🔐 secretOAUTH_STATE_SIGNING_SECRET
configPORT
configREDIS_URL
🔐 secretSESSION_SECRETmust match between the API and MCP services
configTOKEN_ENCRYPTION_KEY_BASE64
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/nexiantechnology697531971-mcphub-1zu1kx)](https://m8ven.ai/mcp/nexiantechnology697531971-mcphub-1zu1kx)
commit: b5d91f3244156eb948187b94a51f126bad627516
code hash: d5e387c23d5db436fba994966442ae8f37cca46e6d0489d1c049b0a34de58803
verified: 6/11/2026, 11:16:21 AM
view raw JSON →