Converts PlantUML snippets into shareable diagrams with support for capability landscapes, business scenarios, and ArchiMate diagrams. Supports HTTP, SSE, and STDIO transports for integration with Claude Desktop, Flowise, and other MCP-compatible runtimes.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.GENERATED_FILES_DIR— 📁 Fallback shared-volume export ( + PUBLIC_FILE_BASE_URL)LOG_LEVEL— info emergency → debug supportedMCP_API_KEY— 🔒 Optional Bearer authentication viaMCP_HOST— / MCP_PORT 0.0.0.0 / 3000 Bind address + port (HTTP/SSE)MCP_HTTP_ENABLE_JSON_RESPONSES— false Return JSON body when true (for debugging)MCP_HTTP_PATH— /mcp HTTP JSON-RPC endpointMCP_PORT— MCP_HOST / 0.0.0.0 / 3000 Bind address + port (HTTP/SSE)MCP_SSE_MESSAGES_PATH— /messages \MCP_SSE_PATH— /sse SSE stream endpointMCP_TRANSPORT— HTTP (default) Direct REST-style integration, reverse proxies, health checks =http node dist/plantuml-mcp-server.jsOB_FILE_API_BASE_URL— ☁️ Optional ob-file export via signed download URLs ()OB_FILE_API_TOKEN— unset Bearer token used to call the ob-file management APIOB_FILE_OIDC_AUDIENCE— ob-file Audience requested during the client-credentials token requestOB_FILE_OIDC_CLIENT_ID— unset OIDC client identifier used by mcp-plantumlOB_FILE_OIDC_CLIENT_SECRET— unset OIDC client secret used by mcp-plantumlOB_FILE_OIDC_DISCOVERY_URL— unset Authelia OIDC discovery URL used to obtain a service access tokenOB_FILE_OIDC_FORWARDED_HOST— unset Optional X-Forwarded-Host header for internal Authelia callsOB_FILE_OIDC_FORWARDED_PROTO— unset Optional X-Forwarded-Proto header for internal Authelia callsOB_FILE_OIDC_SCOPE— groups Scope requested during the client-credentials token requestOB_FILE_OIDC_TOKEN_ENDPOINT— unset Optional direct token endpoint override (useful for internal service-to-service calls)PLANTUML_MCP_SKIP_AUTO_START— unset When true, skips auto-start so scripts can import the server class without launching transportsPLANTUML_SERVER_URL— Override environment variables (, MCP_API_KEY, etc.) as needed.PUBLIC_FILE_BASE_URL— 📁 Fallback shared-volume export (GENERATED_FILES_DIR + )[](https://m8ven.ai/mcp/sysam68-plantuml-mcp-server-1ea6cd)