Enables MCP-compatible agents to authenticate to a Kanka account and interact with campaigns, entities (CRUD on all 18 entity types, posts, relations), and full-text search.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.KANKA_BASE_URL— no https://api.kanka.io/1.0 Override the API base (for testing)KANKA_LOG_LEVEL— no info trace, debug, info, warn, error, fatalKANKA_OAUTH_BASE_URL— no https://app.kanka.io Override the OAuth host (for testing)KANKA_OAUTH_CLIENT_ID— OAuth — OAuth app client id (register at app.kanka.io/settings/api-apps)KANKA_OAUTH_CLIENT_SECRET— OAuth — OAuth app client secretKANKA_OAUTH_TOKEN_FILE— no ~/.config/kanka-mcp/oauth.json Where access + refresh tokens are persistedKANKA_RATE_LIMIT_PER_MIN— no auto-tuned via /profile Hard override on the rate-limit bucket capacity. Setting this disables /profile-based auto-tuning so a deliberately conservative value won't be silently raised.KANKA_TIER— claude mcp add kanka-mcp --env =subscriber \KANKA_TOKEN— ## Set theKANKA_TOKEN_FILE— no ~/.config/kanka-mcp/token Fallback token location if KANKA_TOKEN is unset[](https://m8ven.ai/mcp/torinvdb-kanka-mcp-1uvukd)