trafft-mcp-readonly
A read-only MCP server for auditing Trafft booking data with tools to list services, employees, appointments, and customers without mutation endpoints.
README
Trafft MCP Read-Only
A hardened, community-maintained, read-only Model Context Protocol server for auditing Trafft booking data without exposing mutation tools.
This repository is a clean derivative of mjmirza/trafft-mcp at commit c8793116e564a6c84d4e727ee0d4c7f24aef45ff. It retains the upstream MIT terms and documents all material changes in UPSTREAM.md and NOTICE.
Release status
Live-validated read-only candidate—not yet a tagged production release.
The committed lockfile, Node 20 build, MCP protocol smoke test, high-severity dependency audit, package inspection, authentication flow, core list/detail reads, and privacy-minimized audit checks have passed. The protected release workflow also performs a bounded one-day availability read using a service returned by Trafft.
Before the first tagged release, complete the account-specific service/capacity reconciliation, employee-assignment review, and pagination verification recorded in docs/RELEASE_CHECKLIST.md. Do not call this project affiliated with, endorsed by, or officially verified by Trafft.
Stable V1 tools
list_servicesget_servicefind_services_by_namelist_employeesget_employeelist_locationsget_locationlist_appointmentslist_customersget_customerfind_duplicate_customersget_available_timescompare_services_to_expected
Trafft's published collection documents appointment listing but not a read-by-ID appointment endpoint, so stable V1 deliberately exposes appointments as list-only.
get_available_times accepts one service and one date, then maps them to Trafft's documented calendar_start_date, calendar_end_date, and service query parameters. Optional employee, location, and additional-guest inputs are mapped to the published API names.
No create, update, cancel, reschedule, pricing-write, webhook-write, booking, coupon, or delete tool is compiled into stable V1.
Six experimental read-only probes—webhooks, notifications, working hours, Special Days, Days Off, and settings—remain disabled unless TRAFFT_ENABLE_EXPERIMENTAL_READS=true. Do not enable them until each path is verified.
Security architecture
- Local stdio MCP transport
- HTTPS-only Trafft origin
- Exact hostname allowlist
- API-path confinement and encoded-traversal rejection
- Redirect refusal
- GET-only REST policy, except the authentication POST
- In-memory Bearer token
- Sanitized errors and request identifiers
- Bounded safe-GET retries
- Streaming response-size enforcement
- Valid-JSON MCP response limits
- Privacy-minimized JSONL operation log
- No deep/write audit mode
See SECURITY.md for guarantees and limitations.
Development gate
npm ci --ignore-scripts
npm run check
npm audit --audit-level=high
npm pack --dry-run
The mock security suite does not call Trafft and does not require credentials.
Secret handling
Never commit credentials or paste them into chat, issues, screenshots, fixtures, or shell history. Use an OS secret store or approved private runtime injection.
Community
Contributions are welcome under CONTRIBUTING.md. V1 deliberately remains read-only. Security concerns should be reported privately through GitHub Security Advisories.
Independence
This project is not affiliated with, endorsed by, or sponsored by Trafft. Trafft is a trademark of its respective owner.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.