GoHighLevel MCP Server (ThinkBeDo/gohighlevel_mcp) is an MCP server listed on the M8ven Trust Index. It scores 50 out of 100, grade D. It declares 255 tools. No publisher has claimed this listing.

D
Caution
50/100

GoHighLevel MCP Server

Connects GoHighLevel sub-accounts to AI models with over 260 tools for managing contacts, messaging, sales pipelines, and marketing automation. It enables users to automate complex CRM operations and business tasks through natural language interfaces like Claude Desktop.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

ThinkBeDo

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 15 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: GHL_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes255 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

search

Search for information in GoHighLevel CRM system

retrieve

Retrieve specific data from GoHighLevel

ghl_get_all_associations

Get all associations for a sub-account/location with pagination. Returns system-defined and user-defined associations.

ghl_create_association

Create a new association that defines relationship types between entities like contacts, custom objects, and opportunities.

ghl_get_association_by_id

Get a specific association by its ID. Works for both system-defined and user-defined associations.

ghl_update_association

Update the labels of an existing association. Only user-defined associations can be updated.

ghl_delete_association

Delete a user-defined association. This will also delete all relations created with this association.

ghl_get_association_by_key

Get an association by its key name. Useful for finding both standard and user-defined associations.

ghl_get_association_by_object_key

Get associations by object keys like contacts, custom objects, and opportunities.

ghl_create_relation

Create a relation between two entities using an existing association. Links specific records together.

ghl_get_relations_by_record

Get all relations for a specific record ID with pagination and optional filtering by association IDs.

ghl_delete_relation

Delete a specific relation between two entities.

create_blog_post

Create a new blog post in GoHighLevel. Requires blog ID, author ID, and category IDs which can be obtained from other blog tools.

update_blog_post

Update an existing blog post in GoHighLevel. All fields except postId and blogId are optional.

get_blog_posts

Get blog posts from a specific blog site. Use this to list and search existing blog posts.

get_blog_sites

Get all blog sites for the current location. Use this to find available blogs before creating or managing posts.

get_blog_authors

Get all available blog authors for the current location. Use this to find author IDs for creating blog posts.

get_blog_categories

Get all available blog categories for the current location. Use this to find category IDs for creating blog posts.

check_url_slug

Check if a URL slug is available for use. Use this before creating or updating blog posts to ensure unique URLs.

get_calendar_groups

Get all calendar groups in the GoHighLevel location

get_calendars

Get all calendars in the GoHighLevel location with optional filtering

create_calendar

Create a new calendar in GoHighLevel

get_calendar

Get detailed information about a specific calendar by ID

update_calendar

Update an existing calendar in GoHighLevel

delete_calendar

Delete a calendar from GoHighLevel

get_calendar_events

Get appointments/events from calendars within a date range

get_free_slots

Get available time slots for booking appointments on a specific calendar

create_appointment

Create a new appointment/booking in GoHighLevel

get_appointment

Get detailed information about a specific appointment by ID

update_appointment

Update an existing appointment in GoHighLevel

delete_appointment

Cancel/delete an appointment from GoHighLevel

create_block_slot

Create a blocked time slot to prevent bookings during specific times

update_block_slot

Update an existing blocked time slot

create_calendar_group

Create a new calendar group

validate_group_slug

Validate if a calendar group slug is available

update_calendar_group

Update calendar group details

delete_calendar_group

Delete a calendar group

disable_calendar_group

Enable or disable a calendar group

get_appointment_notes

Get notes for an appointment

create_appointment_note

Create a note for an appointment

update_appointment_note

Update an appointment note

delete_appointment_note

Delete an appointment note

get_calendar_resources_equipments

Get calendar equipment resources

create_calendar_resource_equipment

Create a calendar equipment resource

get_calendar_resource_equipment

Get specific equipment resource details

update_calendar_resource_equipment

Update equipment resource details

delete_calendar_resource_equipment

Delete an equipment resource

get_calendar_resources_rooms

Get calendar room resources

create_calendar_resource_room

Create a calendar room resource

get_calendar_resource_room

Get specific room resource details

update_calendar_resource_room

Update room resource details

delete_calendar_resource_room

Delete a room resource

get_calendar_notifications

Get calendar notifications

create_calendar_notifications

Create calendar notifications

get_calendar_notification

Get specific calendar notification

update_calendar_notification

Update calendar notification

delete_calendar_notification

Delete calendar notification

get_blocked_slots

Get blocked time slots for a location

create_contact

Create a new contact in GoHighLevel

search_contacts

Search for contacts with advanced filtering options

get_contact

Get detailed information about a specific contact

update_contact

Update contact information

delete_contact

Delete a contact from GoHighLevel

add_contact_tags

Add tags to a contact

remove_contact_tags

Remove tags from a contact

get_contact_tasks

Get all tasks for a contact

create_contact_task

Create a new task for a contact

get_contact_task

Get a specific task for a contact

update_contact_task

Update a task for a contact

delete_contact_task

Delete a task for a contact

update_task_completion

Update task completion status

get_contact_notes

Get all notes for a contact

create_contact_note

Create a new note for a contact

get_contact_note

Get a specific note for a contact

update_contact_note

Update a note for a contact

delete_contact_note

Delete a note for a contact

upsert_contact

Create or update contact based on email/phone (smart merge)

get_duplicate_contact

Check for duplicate contacts by email or phone

get_contacts_by_business

Get contacts associated with a specific business

get_contact_appointments

Get all appointments for a contact

bulk_update_contact_tags

Bulk add or remove tags from multiple contacts

bulk_update_contact_business

Bulk update business association for multiple contacts

add_contact_followers

Add followers to a contact

remove_contact_followers

Remove followers from a contact

add_contact_to_campaign

Add contact to a marketing campaign

remove_contact_from_campaign

Remove contact from a specific campaign

remove_contact_from_all_campaigns

Remove contact from all campaigns

add_contact_to_workflow

Add contact to a workflow

remove_contact_from_workflow

Remove contact from a workflow

send_sms

Send an SMS message to a contact in GoHighLevel

send_email

Send an email message to a contact in GoHighLevel

search_conversations

Search conversations in GoHighLevel with various filters

get_conversation

Get detailed conversation information including message history

create_conversation

Create a new conversation with a contact

update_conversation

Update conversation properties (star, mark read, etc.)

get_recent_messages

Get recent messages across all conversations for monitoring

delete_conversation

Delete a conversation permanently

get_email_message

Get detailed email message information by email message ID

get_message

Get detailed message information by message ID

upload_message_attachments

Upload file attachments for use in messages

155 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies15 high5 medium10 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.9.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.9.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretGHL_API_KEYyour_private_integrations_api_key_here # From Private Integrations, NOT regular API key
configGHL_BASE_URLAdd: GHL_API_KEY, , GHL_LOCATION_ID, NODE_ENV
configGHL_LOCATION_IDyour_location_id_here # From Settings → Company → Locations
configMCP_SERVER_PORT
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deployPORT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

255/255 tools missing one or more hints — search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); retrieve (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); ghl_get_all_associations (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +252 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

Only 23/255 tools referenced in tests (9%)

Write tests that reference each tool by name so every tool has at least one test.

Secrets not logged

3 secret values sent to console.log

Redact or omit secret values from log output.

Production dependencies are patched

0 critical, 15 high severity in production deps — @modelcontextprotocol/sdk@1.12.1 (high), @modelcontextprotocol/sdk@1.12.1 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Domain consistency

npm scope @mastanley13 doesn't match GitHub owner thinkbedo

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/thinkbedo/gohighlevel_mcp?variant=verified)](https://m8ven.ai/mcp/thinkbedo/gohighlevel_mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 599a5ff713bb011607960c2792f43e63939493ab
code hash: bbd6ba5e02fdb253db45f82be363b331ee30d76a0dbcd55c055a8474247e4246
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client