A comprehensive MCP server covering the full GoHighLevel API surface with 651 tools, enabling management of contacts, opportunities, calendars, invoices, and more through natural language, with multi-tenant support and read-only safety defaults.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
ajv has ReDoS when using `$data` option
process.env. You'll be asked to provide them before it can run.GHL_API_KEY— "env": { "": "...", "GHL_ENABLE_WRITES": "false" }GHL_BASE_URLGHL_DEFAULT_LOCATION_IDGHL_ENABLED_DOMAINS— all Comma-separated spec basenames (e.g. contacts,opportunities,calendars) to expose a subset of the 651 tools — useful to keep client context small.GHL_ENABLE_WRITES— "env": { "GHL_API_KEY": "...", "": "false" }GHL_LOCATION_IDGHL_SPECS_DIR— (PPC corpus path) Only used by npm run extract to regenerate operations.json when GHL ships spec updates.GHL_TIMEOUT_MS— 30000 Request timeout.HD_GHL_API_KEY— GHL_API_KEY (fallback ) — Private-integration token / OAuth access token. Env-only, never hardcoded.HD_GHL_ENABLE_WRITES[](https://m8ven.ai/mcp/zackscriven-ghl-mcp-server-5lpk87)