74
/ 100
4 days ago
glama

tldraw-mcp-app

Provides a standalone MCP server for tldraw diagrams, enabling clients to create, edit, and persist multiple canvases over Streamable HTTP with semantic protocol v2.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for the top badge — read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
21 tools verified — handlers match their declared behaviour
6 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// known CVEs in dependencies1 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

lowesbuild@0.28.0GHSA-g7r4-m6w7-qqqr

esbuild allows arbitrary file read when running the development server on Windows

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAPP_HTML_PATH
configHOST
configINTEROP_TLDRAW_HEALTH_URL
configINTEROP_TLDRAW_MCP_URL
configOPENCHAMBER_TLDRAW_HEALTH_URL
configOPENCHAMBER_TLDRAW_MCP_ALLOWED_HOSTS
configOPENCHAMBER_TLDRAW_MCP_ALLOWED_ORIGINS
configOPENCHAMBER_TLDRAW_MCP_ALLOW_HEAVY_BUILD
configOPENCHAMBER_TLDRAW_MCP_APP_HTML_PATH
configOPENCHAMBER_TLDRAW_MCP_ASSET_GC_MODE
configOPENCHAMBER_TLDRAW_MCP_CANVAS_ID
configOPENCHAMBER_TLDRAW_MCP_HOST
configOPENCHAMBER_TLDRAW_MCP_INSTALLATION_ID
configOPENCHAMBER_TLDRAW_MCP_PORT
configOPENCHAMBER_TLDRAW_MCP_PROVENANCE_PATH
configOPENCHAMBER_TLDRAW_MCP_REUSE_UPSTREAM
configOPENCHAMBER_TLDRAW_MCP_RUNTIME_DIR
configOPENCHAMBER_TLDRAW_MCP_SCOPE_ID
configOPENCHAMBER_TLDRAW_MCP_STATE_PATH
configOPENCHAMBER_TLDRAW_MCP_STORE_ROOT
configOPENCHAMBER_TLDRAW_MCP_URL
configOPENCHAMBER_TLDRAW_MCP_WORKSPACE_ID
configPORT
configTLDRAW_CANVAS_ID
configTLDRAW_MCP_ACCEPTANCE_REPORT_DIR
configTLDRAW_MCP_ALLOWED_HOSTSloopback hostnames HTTP Host allowlist; required for non-loopback bind
configTLDRAW_MCP_ALLOWED_ORIGINSloopback hostnames HTTP Origin-host allowlist; required for non-loopback bind
configTLDRAW_MCP_ALLOW_HEAVY_BUILD
configTLDRAW_MCP_APP_HTML_PATHsibling dist/app.html Verified App bundle
configTLDRAW_MCP_ASSET_GC_MODEdelete Startup-only revision-aware asset maintenance: delete, dry-run, or off
configTLDRAW_MCP_CANVAS_IDinterop-acceptance Initial/default canvas
configTLDRAW_MCP_HEALTH_URL
configTLDRAW_MCP_HOST127.0.0.1 Listen address
configTLDRAW_MCP_INSTALLATION_IDresolved store root Stable installation identity seed used to partition App caches
configTLDRAW_MCP_PORT39512 Listen port
configTLDRAW_MCP_PROBE_CANVAS_ID
configTLDRAW_MCP_PROVENANCE_PATHsibling provenance App integrity metadata
configTLDRAW_MCP_REUSE_UPSTREAM
configTLDRAW_MCP_RUNTIME_DIR/tmp/tldraw-mcp-test \
configTLDRAW_MCP_SCOPE_IDlocal-user Stable deployment/user namespace identity
configTLDRAW_MCP_STATE_PATHruntime state file Legacy monolithic state import source and rollback evidence
configTLDRAW_MCP_STORE_ROOTnext to state path Namespaced catalog, canvas records, history, recoverable trash, and content-addressed assets
configTLDRAW_MCP_TEST_FAIL_RENAME_AT
configTLDRAW_MCP_TEST_FAIL_WRITE_AT
configTLDRAW_MCP_URLloopback MCP URL Probe target
configTLDRAW_MCP_WORKSPACE_IDdefault-workspace Stable workspace namespace identity
configTLDRAW_PROVENANCE_PATH
configTLDRAW_STATE_PATH
configXDG_DATA_HOME
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/zunbaran-tldraw-mcp-app-qcgjd0)](https://m8ven.ai/mcp/zunbaran-tldraw-mcp-app-qcgjd0)
commit: f20d794adc38e11ab3ab267e98fed1521aa2a6c2
code hash: 8c546ac375e5050fa5b0a7e4b1e852c5cf01cb99013ea2470a016346b1ba0635
verified: 8/6/2026, 9:08:47 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client