GoHighLevel MCP Server (REALSolutions605/Go-High-Level-MCP-2026-Complete) is an MCP server listed on the M8ven Trust Index. It scores 50 out of 100, grade D. It declares 192 tools. No publisher has claimed this listing.

D
Caution
50/100

GoHighLevel MCP Server

Enables AI assistants to directly interact with the entire GoHighLevel CRM via 563+ tools across 44 categories, allowing natural language control for contacts, messaging, opportunities, calendars, and more.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

REALSolutions605

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 12 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 3 credentials: ANTHROPIC_API_KEY, GHL_API_KEY, MCP_BEARER_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes192 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

search

Search for information in GoHighLevel CRM system

retrieve

Retrieve specific data from GoHighLevel

view_contact_grid

Display contact search results in a data grid. Accepts query (search string) or no args (shows recent contacts). Returns a visual UI component.

view_pipeline_board

Display a pipeline as an interactive Kanban board. Accepts pipelineId (direct), pipelineName (fuzzy match), or nothing (shows first pipeline). Returns a visual UI component.

view_quick_book

Display a quick booking interface for scheduling appointments. Accepts calendarId (direct), calendarName (fuzzy match), or nothing (shows first calendar). Returns a visual UI component.

view_opportunity_card

Display a single opportunity with details, value, and stage info. Accepts opportunityId (direct), opportunityName (fuzzy search), contactName (search by contact), or nothing (shows first opportunity). Returns a visual UI component.

view_calendar

Display a calendar with events and appointments. Accepts calendarId (direct), calendarName (fuzzy match), or nothing (shows first/default calendar). Returns a visual UI component.

view_invoice

Display an invoice preview with line items and payment status. Accepts invoiceId (direct), invoiceNumber (search by number), or nothing (shows most recent invoice). Returns a visual UI component.

view_campaign_stats

Display campaign statistics and performance metrics. Accepts campaignId (direct), campaignName (fuzzy match), or nothing (shows overview of all campaigns). Returns a visual UI component.

view_agent_stats

Display agent/user performance statistics and metrics. Returns a visual UI component.

view_contact_timeline

Display a contact's activity timeline with all interactions. Accepts contactId (direct), contactName (fuzzy search), or nothing (shows first recent contact). Returns a visual UI component.

view_workflow_status

Display workflow execution status and history. Accepts workflowId (direct), workflowName (fuzzy match), or nothing (shows overview of all workflows). Returns a visual UI component.

view_dashboard

Display the main GHL dashboard overview. Returns a visual UI component.

view_conversation_inbox

Display the conversation inbox with threaded messages and channel filters. Returns a visual UI component.

view_phone_log

Display phone call history with recordings, duration, and direction stats. Returns a visual UI component.

view_course_manager

Display courses with enrollment stats, lesson counts, and publish status. Returns a visual UI component.

view_store_front

Display the store with product catalog, inventory, and recent orders. Returns a visual UI component.

view_payment_dashboard

Display payment transactions, subscriptions, and revenue metrics. Returns a visual UI component.

view_social_media_hub

Display social media posts, scheduling, and engagement analytics. Returns a visual UI component.

view_reputation_monitor

Display reputation reviews, ratings, and response tracking. Returns a visual UI component.

view_funnel_builder

Display funnels with page counts, conversion rates, and funnel flow. Returns a visual UI component.

view_form_manager

Display forms and surveys with submission counts and field details. Returns a visual UI component.

view_email_center

Display email history, templates, and delivery statistics. Returns a visual UI component.

view_blog_manager

Display blog posts with categories, authors, and publish status. Returns a visual UI component.

view_affiliate_dashboard

Display affiliates, referral stats, commissions, and campaigns. Returns a visual UI component.

view_workflow_builder

Display workflows with trigger/action flow diagrams and execution stats. Returns a visual UI component.

view_reporting_hub

Display reports, widgets, and analytics charts. Returns a visual UI component.

view_smart_list_manager

Display smart lists with contact counts and filter conditions. Returns a visual UI component.

view_custom_fields_manager

Display custom fields with types, keys, and field hierarchy. Returns a visual UI component.

view_media_library

Display media files and folders with gallery view and file browser. Returns a visual UI component.

view_location_settings

Display location details, business hours, tags, and custom values. Returns a visual UI component.

view_user_manager

Display users with roles, permissions, and team overview. Returns a visual UI component.

view_voice_ai_console

Display Voice AI agents, call transcripts, and performance stats. Returns a visual UI component.

view_proposal_builder

Display proposals with status tracking, values, and conversion pipeline. Returns a visual UI component.

view_saas_admin

Display SaaS admin with sub-accounts, plans, snapshots, and MRR. Returns a visual UI component.

view_link_trigger_manager

Display trigger links, click stats, and trigger configurations. Returns a visual UI component.

generate_ghl_view

Generate a rich, AI-powered UI view on the fly from a natural language prompt. Optionally fetches real GHL data to populate the view. Requires ANTHROPIC_API_KEY. Returns a visual UI component rendered in the MCP App.

update_opportunity

Update an opportunity (move to stage, change value, status, etc.)

get_affiliate_campaigns

Get all affiliate campaigns

get_affiliate_campaign

Get a specific affiliate campaign

create_affiliate_campaign

Create a new affiliate campaign

update_affiliate_campaign

Update an affiliate campaign

delete_affiliate_campaign

Delete an affiliate campaign

get_affiliates

Get all affiliates

get_affiliate

Get a specific affiliate

create_affiliate

Create/add a new affiliate

update_affiliate

Update an affiliate

approve_affiliate

Approve a pending affiliate

reject_affiliate

Reject/deny a pending affiliate

delete_affiliate

Remove an affiliate

get_affiliate_commissions

Get commissions for an affiliate

get_affiliate_stats

Get affiliate performance statistics

create_payout

Create a payout for affiliate

get_payouts

Get affiliate payouts

get_referrals

Get referrals (leads/sales) from affiliates

ghl_create_agent
ghl_list_agents
ghl_get_agent

Get details for a specific AI agent by ID, including its current staging and production versions.

ghl_update_agent
ghl_delete_agent

Permanently delete an AI agent and all its versions. This action is irreversible.

ghl_list_agent_versions

List all versions (staging and production snapshots) for a given agent.

ghl_update_agent_version
ghl_deploy_agent
ghl_get_all_associations

Get all associations for a sub-account/location with pagination. Returns system-defined and user-defined associations.

ghl_create_association

Create a new association that defines relationship types between entities like contacts, custom objects, and opportunities.

ghl_get_association_by_id

Get a specific association by its ID. Works for both system-defined and user-defined associations.

ghl_update_association

Update the labels of an existing association. Only user-defined associations can be updated.

ghl_delete_association

Delete a user-defined association. This will also delete all relations created with this association.

ghl_get_association_by_key

Get an association by its key name. Useful for finding both standard and user-defined associations.

ghl_get_association_by_object_key

Get associations by object keys like contacts, custom objects, and opportunities.

ghl_create_relation

Create a relation between two entities using an existing association. Links specific records together.

ghl_get_relations_by_record

Get all relations for a specific record ID with pagination and optional filtering by association IDs.

ghl_delete_relation

Delete a specific relation between two entities.

create_blog_post

Create a new blog post in GoHighLevel. Requires blog ID, author ID, and category IDs which can be obtained from other blog tools.

update_blog_post

Update an existing blog post in GoHighLevel. All fields except postId and blogId are optional.

get_blog_posts

Get blog posts from a specific blog site. Use this to list and search existing blog posts.

get_blog_sites

Get all blog sites for the current location. Use this to find available blogs before creating or managing posts.

get_blog_authors

Get all available blog authors for the current location. Use this to find author IDs for creating blog posts.

get_blog_categories

Get all available blog categories for the current location. Use this to find category IDs for creating blog posts.

check_url_slug

Check if a URL slug is available for use. Use this before creating or updating blog posts to ensure unique URLs.

get_businesses

Get all businesses for a location. Businesses represent different entities within a sub-account.

get_business

Get a specific business by ID

create_business

Create a new business for a location

update_business

Update an existing business

delete_business

Delete a business from a location

get_calendar_groups

Get all calendar groups in the GoHighLevel location

get_calendars

Get all calendars in the GoHighLevel location with optional filtering

create_calendar

Create a new calendar in GoHighLevel

get_calendar

Get detailed information about a specific calendar by ID

update_calendar

Update an existing calendar in GoHighLevel

delete_calendar

Delete a calendar from GoHighLevel

get_calendar_events

Get appointments/events from calendars within a date range

get_free_slots

Get available time slots for booking appointments on a specific calendar

create_appointment

Create a new appointment/booking in GoHighLevel

get_appointment

Get detailed information about a specific appointment by ID

update_appointment

Update an existing appointment in GoHighLevel

delete_appointment

Cancel/delete an appointment from GoHighLevel

create_block_slot

Create a blocked time slot to prevent bookings during specific times

update_block_slot

Update an existing blocked time slot

create_calendar_group

Create a new calendar group

92 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies12 high5 medium12 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highaxios@1.9.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.9.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.9.0GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

highaxios@1.9.0GHSA-4hjh-wcwx-xvwj

Axios is vulnerable to DoS attack through lack of data size check

highaxios@1.9.0GHSA-6chq-wfr3-2hj9

Axios: Header Injection via Prototype Pollution

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretANTHROPIC_API_KEY
🔐 secretGHL_API_KEYyour_private_integrations_api_key_here # From Private Integrations, NOT regular API key
configGHL_BASE_URLAdd: GHL_API_KEY, , GHL_LOCATION_ID, NODE_ENV
configGHL_LOCATION_IDyour_location_id_here # From Settings → Company → Locations
configLOG_LEVEL
🔐 secretMCP_BEARER_TOKEN
configMCP_SERVER_PORT
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

192/192 tools missing one or more hints — search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); retrieve (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); view_contact_grid (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +189 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

Only 22/192 tools referenced in tests (11%)

Write tests that reference each tool by name so every tool has at least one test.

Secrets not logged

1 secret value sent to console.log

Redact or omit secret values from log output.

Production dependencies are patched

0 critical, 12 high severity in production deps — axios@1.9.0 (high), axios@1.9.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Domain consistency

npm scope @mastanley13 doesn't match GitHub owner realsolutions605

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/realsolutions605/go-high-level-mcp-2026-complete?variant=verified)](https://m8ven.ai/mcp/realsolutions605/go-high-level-mcp-2026-complete)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 6f28546cf92f3db002e9b4ff45caffc0f5908fa9
code hash: 76127acc1a012e05ad66b16ac39a5e51cb27fe044bf96eae55bae6903799de23
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client