Run a live Excalidraw canvas and control it from AI agents.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
ws affected by a DoS when handling a request with many HTTP headers
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
Mermaid: Improper sanitization of configuration leads to CSS injection
Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection
process.env. You'll be asked to provide them before it can run.ADMIN_API_KEYAUTO_SNAPSHOT_INTERVAL_MSAUTO_SNAPSHOT_KEEPCANVAS_PROXY_TIMEOUT_MSCANVAS_RUNTIMECANVAS_URLDATA_DIRENABLE_CANVAS_SYNC— Enable real-time canvas sync trueEXCALIDRAW_EXPORT_DIREXPRESS_SERVER_URL— MCP server: exposes MCP tools over stdio; syncs to the canvas viaHOSTINTERNAL_CANVAS_URLLOG_FILE_PATHLOG_LEVELMCP_AGENT_COLOR— Cursor color, either a stroke hex color or JSON with background/stroke #1971c2 strokeMCP_AGENT_CURSOR— Show MCP tool activity as a collaborator cursor when canvas sync is enabled trueMCP_AGENT_NAME— Collaborator label for MCP agent cursor presence MCP AgentMCP_REQUIRE_AUTHNO_COLORPERSIST_DEBOUNCE_MSPORT— 3000 npm run canvasPUBLIC_BASE_URLROOT_REDIRECT_URLSYNC_DEBUG[](https://m8ven.ai/mcp/val4evr-excalidraw-zephy-2j8t6j)