ripper-mcp
Exposes Ripper CRM tools (contacts, listings, tasks, notes, timeline, search) to any MCP client via a dynamic tool catalog.
README
ripper-mcp
A lightweight, local MCP server for Ripper. It exposes everything the in-app assistant can do — contacts, listings, tasks, notes, timeline, and cross-CRM search — to any MCP client (Claude Desktop, Claude Code, Cursor, …), authenticated as your own Ripper account.
It's a thin, generic shell: it knows no individual tool. It reads the tool catalog from the deployed Ripper backend at runtime and dispatches every call through a single gateway. So:
- Tool changes are live. It polls the backend's manifest; when the catalog
changes it swaps its tool list and emits
notifications/tools/list_changed— no reinstall, no restart. - The client stays current on its own. Launched via
npx ripper-mcp@latest, every start fetches the newest version. A rare backendshellVersionbump just prints an update notice.
The backend half of this (the
mcp.*gateway) lives in the private Ripper app. This repo is only the local client.
Quick start
# 1. Log in once (browser SSO — your normal Google sign-in). Caches a personal
# token at ~/.ripper/credentials.json (chmod 0600).
npx ripper-mcp@latest login
# 2. Check state
npx ripper-mcp@latest status
login starts a loopback listener and opens the /mcp/connect consent page.
Sign in, click Approve, and the authorization code is redirected straight
back to the CLI on 127.0.0.1 and exchanged for your token (PKCE — see below).
Wire it into a client
Claude Desktop — claude_desktop_config.json:
{
"mcpServers": {
"ripper": {
"command": "npx",
"args": ["-y", "ripper-mcp@latest"]
}
}
}
Claude Code — .mcp.json (or claude mcp add):
{
"mcpServers": {
"ripper": { "command": "npx", "args": ["-y", "ripper-mcp@latest"] }
}
}
Prefer a global install? npm i -g ripper-mcp then use "command": "ripper-mcp".
How it fits together
Claude Desktop / Cursor ──stdio──▶ ripper-mcp (local) ──HTTPS──▶ Ripper backend (Convex)
│ ├─ mcp.getManifest (tool catalog + versions)
│ ├─ mcp.callTool (runs a tool as you)
└─ ~/.ripper/credentials.json ├─ mcp.authorize (browser consent → code)
└─ mcp.token (PKCE exchange → token)
Login uses OAuth 2.0 Authorization Code + PKCE with a loopback redirect
(RFC 8252 — the same native-app flow as gh / gcloud): login starts a
listener on 127.0.0.1, opens the consent page, and after you approve, the
authorization code is redirected to your own loopback and exchanged (with the
PKCE verifier that never leaves this machine) for a 90-day access token. Only the
token's SHA-256 hash is stored on the backend; no password is ever handled here.
Commands
ripper-mcp # start the stdio server (default)
ripper-mcp serve # explicit
ripper-mcp login # browser-SSO login, cache token
ripper-mcp logout # clear cached token
ripper-mcp status # show config + login state
Configuration
Resolution order for every setting: CLI flag → env var → ~/.ripper/credentials.json → default.
| Setting | Flag | Env var | Default |
|---|---|---|---|
| Backend URL | --convex-url |
RIPPER_CONVEX_URL |
reliable-bullfrog-975 (production) |
| App URL | --app-url |
RIPPER_APP_URL |
https://rippr.dev (production) |
| Token | — | RIPPER_MCP_TOKEN |
cached after login |
| Poll period | — | RIPPER_MCP_POLL_MS |
60000 (min 10000) |
Update controls:
| Env var | Effect |
|---|---|
RIPPER_MCP_NO_SELFUPDATE=1 |
Suppress the "newer version available" notice. |
RIPPER_MCP_AUTO_UPDATE=1 |
Also run npm i -g ripper-mcp@latest in the background when behind. |
Security notes
- PKCE + loopback means an authorization code is only ever delivered to
your
127.0.0.1, and can't be exchanged for a token without the verifier that never leaves this machine — so a phished or intercepted code is useless to anyone else. The listener binds to loopback only and checks thestate. - Tokens expire after 90 days and are revocable. Only their SHA-256 hash is
stored server-side; the plaintext is returned to the CLI once and cached at
~/.ripper/credentials.json(chmod 0600). - Rotate/revoke by running
ripper-mcp logoutthenloginagain (or revoking the token from the Ripper app). Treat the credentials file like any credential.
Development
npm install
npm run check # syntax-check all sources
node bin.mjs status
Run against a non-default deployment with --convex-url / RIPPER_CONVEX_URL.
License
MIT
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.